Developer & API documentation

API Integration Overview

CardIQ currently exposes a small company-scoped server API, selected public profile helpers, an app-specific mobile API, and signed outbound lead webhooks. This is not a claim of a broad, general-purpose public API.

Supported integration surfaces

Company API

Enterprise-authorized API keys can read the authenticated company record and list or create employees within that same company.

Public profile helpers

Read-only public profile and vCard-link responses accept a public slug or opaque public profile identifier. Internal numeric employee IDs are intentionally rejected.

Lead delivery

A configured paid-plan company can send the outbound lead_created event to one HTTPS receiver. webhook_test is available from the administration screen.

Mobile API boundary

Bearer tokens serve the CardIQ employee/mobile application. They are not general integration credentials and those app routes are not documented here as a public provisioning API.

Tenant and lifecycle boundary

Company isolation

The server resolves company ownership from the authenticated key; callers do not select another tenant in the documented company API.

Operational state

Active workspaces may operate subject to plan access. Suspended, frozen, and deactivated workspaces can receive HTTP 403 with COMPANY_SUSPENDED, COMPANY_FROZEN, or COMPANY_DEACTIVATED. Private lifecycle reasons and notes are not returned.

Explicit limits

No public scopes, pagination contract for the company employee list, SDK, client library, API version guarantee, inbound webhook API, or general provisioning standard is evidenced. Confirm any broader enterprise requirement before implementation.

Continue reading

Control how employees represent your company externally

Explore the CardIQ platform or review the workflow from verification through identity deactivation.

See how CardIQ works View pricing