Tickets-API
Endpoints
All REST endpoints of the Tickets API.
Endpoints
All paths are relative to the base URL https://www.theredstonee.de/api/tickets/v1. The addresses have no file extension.
Older integrations still calling
…/create.php are redirected automatically to the address without the extension — using HTTP 308, so the method and the request body are preserved. New code should still target the addresses below.| Method | Path | Description |
|---|---|---|
POST | /create | Create a ticket (pk or sk). Fields: name, email, subject, message (required); category, fields, page_url (optional). Attachments via multipart attachments[]. |
GET | /list | List tickets (sk only). Query: status, category, limit (default 50), offset. |
GET | /ticket?id=tkt_xxx | A single ticket. With pk also pass email. |
POST | /reply | Add a reply. pk = customer, sk = support. Body: ticket_id, message, optional from_customer, author. |
POST | /status | Change the status (sk only). Body: ticket_id, status. |
POST | /priority | Set the priority (sk only). Body: ticket_id, priority (low, normal, high, urgent). |
POST | /assign | Assign to an agent (sk only). Body: ticket_id, agent_id (empty removes the assignment). |
DELETE | /delete | Delete a ticket (sk only). Body or query: ticket_id. |
GET | /meta | Categories including custom fields, statuses and priorities (pk or sk). |
GET | /kb | Knowledge base (pk or sk). Without ?id= the overview, with ?id= the full article. pk sees published articles only, sk also drafts. |
POST | /close-request | Request closing (pk or sk). Body: ticket_id, optional by (agent/customer). |
POST | /close-resolve | Answer a close request (sk only). Body: ticket_id, accept. |
POST | /upload | File upload (multipart): ticket_id, file, optional reply_id, email. Max 5 MB. jpg, png, gif, webp, pdf, txt, log, json, csv, zip. |
GET | /file?ticket_id=X&file_id=Y | Download an attachment. With pk also pass email. Always served as a download, never rendered in the browser. |
POST | /rate | Rate a ticket (pk or sk). Body: ticket_id, score (1–5), optional comment. |
GET / POST | /settings | Read and write mail settings (sk only). Fields: email_notify, smtp, autoreply, business_hours. |
GET | /me | Portal info for the API key, for verification (pk or sk). |
GET | /widget-config | Widget design and public keys (pk or sk). Used by the JS widget itself. |
Example: create a ticket
curl -X POST -H "Authorization: Bearer sk_live_KEY" \
-F "name=Max" -F "email=max@example.com" \
-F "subject=Help" -F "message=My problem ..." \
"https://www.theredstonee.de/api/tickets/v1/create"
Management API
Reads and writes the portal settings through one endpoint — for your own tools, setup scripts or a backup of the configuration. sk_live_ only.
Secrets never leave the server: the SMTP password, Turnstile secret, agent passwords, 2FA secrets and passkeys are stripped when reading. For SMTP you only see
pass_set, whether a password is stored at all.# Read the full configuration
curl -H "Authorization: Bearer sk_live_KEY" \
"https://www.theredstonee.de/api/tickets/v1/admin?r=all"
# Replace a list — always send it complete
curl -X POST -H "Authorization: Bearer sk_live_KEY" -H "Content-Type: application/json" \
-d '{"tags":[{"name":"VIP","color":"#ff0000"}]}' \
"https://www.theredstonee.de/api/tickets/v1/admin?r=tags"
# Create or update a single entry (agents, kb)
curl -X POST -H "Authorization: Bearer sk_live_KEY" -H "Content-Type: application/json" \
-d '{"title":"Forgot password","body":"...","published":true}' \
"https://www.theredstonee.de/api/tickets/v1/admin?r=kb"
# Delete a single entry
curl -X DELETE -H "Authorization: Bearer sk_live_KEY" \
"https://www.theredstonee.de/api/tickets/v1/admin?r=agents&id=agt_123"
| Kind | Resources |
|---|---|
| Replace the whole list | categories, statuses, macros, rules, tags, escalation, modules |
| Single object | design, sla, autoreply, autoclose, blocklists, business_hours, form, mail, turnstile |
Individually by id | agents, kb — POST creates or updates, DELETE ?id= removes |
| Read-only | priorities; the logs audit and webhook_log (with &limit=, default 100, at most 500) |
List resources are fully replaced on
POST — always send the complete list. A partial update would have to guess which entry you meant. r=all returns all settings at once, but without the two logs.