Skip to content

Authentication

Evorest creates API keys for a property-management organization and sends them to you over a channel you both trust. A key is a secret. Do not put it in a mobile app, a browser page, or a git repository. See Getting access for how to ask for keys.

Each call below has its own key. A key for opening deposits does not work for reading contract status.

Send both headers:

HeaderRequiredMeaning
x-api-keyYesThe key Evorest issued for opening deposits.
x-external-org-idYesThe organization id agreed for this integration.

The external organization id is matched to an Evorest organization that has this integration turned on. A wrong key or an unknown organization id rejects the request with HTTP 500 and result: errored. This call never returns 401. See Open a deposit.

Contract status uses a different organization header and its own key:

HeaderRequiredMeaning
x-api-keyYesThe key Evorest issued for contract status.
x-org-idYesThe Evorest organization id.

x-external-org-id is not accepted on this call. A wrong key is HTTP 401. An organization that is unknown, or does not have contract status turned on, is HTTP 500. See Contract status.

The 365immo opening signal uses the same two headers as contract status, x-api-key and x-org-id, with the key issued for 365immo. A failed authentication is HTTP 500, as for opening a deposit.

Evorest also calls you, to hand over PDFs (see Document callback) or status changes (365immo). Those calls authenticate to your server:

IntegrationHow Evorest authenticates to you
Propbase, Emonitorx-api-key with the same key you use to call Evorest, plus x-external-org-id.
Flatfoxx-api-key, and a Flatfox user agent.
365immox-api-key.
CustomHTTP Basic authentication. Evorest agrees the username and password with you when the integration is set up.

Check these on your side before you trust a call. Use HTTPS URLs only.