Overview
WinAI builds custom integrations for businesses that need their systems to communicate automatically.
Our integration services may support use cases such as:
- Sending data between business applications
- Connecting CRM systems
- Triggering workflow automations
- Creating or updating records
- Processing lead information
- Scheduling workflows
- Connecting AI agents to business systems
- Receiving real-time webhook events
- Synchronizing data between platforms
API availability depends on the systems involved and the requirements of each project.
API Access
WinAI APIs are not currently provided as an unrestricted public API.
API access may be made available to:
- WinAI clients
- Approved integration partners
- Custom application projects
- AI Agent implementations
- Workflow automation projects
- Authorized internal systems
Access credentials and technical documentation are provided only when required for an approved project.
Authentication
Depending on the integration, WinAI may use secure authentication methods such as:
- API keys
- Bearer tokens
- OAuth
- Signed webhook requests
- Secret-based authentication
- Provider-specific authentication
Authentication requirements vary by implementation.
Base URLs
API base URLs may differ depending on:
- Production environment
- Development environment
- Client project
- Integration type
The appropriate API URL will be provided with your project documentation. Do not use undocumented WinAI endpoints.
Requests
Unless otherwise specified, API requests typically use:
Content-Type: application/jsonExample request structure:
{
"customerId": "example_customer_id",
"event": "example_event",
"data": {
"key": "value"
}
}Actual request fields depend on the specific integration.
Responses
Successful API responses generally return structured JSON. Example:
{
"success": true,
"data": {
"id": "example_id",
"status": "completed"
}
}An unsuccessful request may return:
{
"success": false,
"error": {
"code": "invalid_request",
"message": "The request could not be processed."
}
}Response formats may vary by integration.
HTTP Status Codes
WinAI integrations may use standard HTTP status codes.
| Status | Meaning |
|---|---|
| 200 | Request completed successfully |
| 201 | Resource created successfully |
| 400 | Invalid request |
| 401 | Authentication required or invalid |
| 403 | Access is not permitted |
| 404 | Resource not found |
| 409 | Request conflicts with an existing resource |
| 422 | Request could not be processed |
| 429 | Too many requests |
| 500 | Unexpected server error |
Specific APIs may use additional status codes.
Webhooks
WinAI may use webhooks to send real-time events between systems.
Common webhook use cases may include:
- New lead received
- Appointment created
- Appointment updated
- Appointment cancelled
- Workflow completed
- AI Agent interaction completed
- CRM record updated
- Form submitted
Example webhook payload:
{
"event": "workflow.completed",
"timestamp": "2026-09-29T12:00:00Z",
"data": {
"id": "example_id"
}
}Available webhook events depend on the project.
Webhook Security
Webhook endpoints should be protected against unauthorized requests.
Depending on the implementation, WinAI may use:
- Authorization headers
- Shared secrets
- Request signatures
- Timestamp validation
- Replay protection
- IP or network restrictions
- Request validation
Idempotency
Some integrations may support idempotency to prevent duplicate actions when requests are retried.
This is especially useful for operations such as:
- Creating records
- Sending notifications
- Processing payments
- Creating appointments
- Triggering workflows
Where supported, idempotency requirements will be documented for the specific API.
Rate Limits
Rate limits may apply to protect system reliability and prevent abuse.
Limits may vary based on:
- API
- Client
- Project
- Integration
- Infrastructure provider
If a rate limit is exceeded, the API may respond with:
429 Too Many RequestsClient applications should implement appropriate retry and backoff behavior where necessary.
Error Handling
Applications integrating with WinAI should handle failures gracefully.
Recommended practices include:
- Checking HTTP status codes
- Validating response bodies
- Logging failed requests
- Using retry logic where appropriate
- Avoiding unlimited retries
- Preventing duplicate operations
- Handling timeouts
- Monitoring integration failures
Do not assume that every API request will succeed.
Data Formats
Unless otherwise specified:
- API requests use JSON
- Dates should use ISO 8601 where possible
- Time zones should be explicitly defined when relevant
- Identifiers should be treated as opaque values
- Clients should not infer information from internal identifiers
Example timestamp:
2026-09-29T14:30:00ZTime Zones
Scheduling integrations should always include explicit time zone information.
Where applicable, WinAI may use standard IANA time zone identifiers such as:
America/New_York
America/Los_Angeles
Asia/Ho_Chi_MinhDo not assume the server time zone is the same as the customer's time zone.
Security
Clients integrating with WinAI should follow secure development practices.
Never:
- Expose API keys publicly
- Commit secrets to Git repositories
- Store credentials directly in frontend code
- Send credentials in URLs
- Log passwords or private authentication tokens
- Share production credentials through unsecured channels
Use server-side environment variables or an appropriate secrets-management system.
For more information, see our Security page.
Personal Data
API integrations may process personal or business information.
Customers are responsible for ensuring that they have appropriate rights and permissions to provide data through an integration.
Do not send regulated or highly sensitive information unless the project has been specifically reviewed and approved for that type of data.
See our Privacy Policy for more information.
Third-Party APIs
Many WinAI projects integrate with third-party platforms.
Third-party APIs are subject to their own:
- Availability
- Authentication requirements
- Pricing
- Rate limits
- Terms
- Privacy policies
- Technical restrictions
Changes made by third-party providers may affect existing integrations. WinAI cannot guarantee the continued availability of a third-party API.
API Versioning
WinAI may introduce new API versions as integrations evolve.
When versioning is used, changes may include:
- New fields
- New endpoints
- Updated authentication
- Deprecated functionality
- Security improvements
Clients should use the API version specified in their project documentation.
Deprecation
WinAI may occasionally retire outdated APIs or integration methods.
Where practical, affected clients will receive reasonable notice and migration guidance.
SDKs
WinAI does not currently guarantee official public SDKs for every programming language.
Custom integrations can generally be implemented using standard HTTPS requests from technologies such as:
- JavaScript / TypeScript
- Node.js
- Python
- PHP
- Java
- C#
- Other server-side environments
Actual compatibility depends on the integration.
Example Integration Flow
Integration architecture varies depending on your existing systems and business workflow.
API Support
If you are already working with WinAI and need help with an integration, contact your WinAI project representative.
For new API or integration projects: Contact WinAI.
Please include:
- Your company name
- The system you want to connect
- The API or platform involved
- The workflow you want to automate
- Expected usage or volume
- Any relevant technical documentation
Our team will review the requirements and determine an appropriate integration approach.
Contact WinAI