Perfex CRM Module
REST API Pro
A complete REST API for Perfex CRM: 30 CRUD resources, hashed keys with scopes, 57 webhook events, OpenAPI 3.1 and an interactive playground.
- Perfex CRM 3.0+
- PHP 7.4+
- 30 resources
- Webhooks
- OpenAPI 3.1
- 30 resources Full CRUD across all CRM entities
- Secure keys SHA-256, scopes, expiry & IP whitelist
- 57 webhook events HMAC-signed with retry logic
- OpenAPI & playground Try-it tester and code samples
An API you can actually build on
The standard Perfex API quickly hits limits for serious integrations. REST API Pro delivers a modern, developer-friendly platform: production-grade security, complete documentation, webhooks and request logs. It's ready for Zapier/Make, custom apps and automation without custom code.
“Production-ready. Developer-friendly.”
Documentation & playground
An auto-generated OpenAPI 3.1 spec with an interactive Try-it tester and code samples in cURL, PHP, JavaScript and Python, right in the admin.
Everything for serious integrations
30 full-CRUD resources
Full create/read/update/delete across all major CRM entities with unified JSON responses.
Hashed keys with scopes
SHA-256 keys, shown only once, with read/write permissions per resource and a role matrix.
Advanced key management
Expiry dates, IP whitelisting (CIDR), individual rate limits and JWT token exchange.
Powerful queries
Pagination, multi-field filtering, sorting, full-text search, sparse fields, relationship embedding and sync windows.
57 webhook events
HMAC-signed delivery for invoices, leads, tickets & tasks, with exponential retry.
OpenAPI 3.1 & playground
Auto-generated spec, Try-it tester and code samples (cURL, PHP, JS, Python).
Logs & analytics
A full audit log of every call with traffic charts, error rates and latency tracking.
Batch operations
Up to 25 operations in a single request, for fewer round-trips.
Action endpoints
PDF download, email delivery, quote→invoice, lead→customer, task timers and attachments.
Security hardening
SSRF protection for webhooks, CSRF-safe writes, rate-limit headers and per-install JWT secrets.
Compatibility mode
Legacy mapping for migrating from older Perfex REST APIs.
Global search & stats
Cross-resource search over 12 entities plus CRM-wide metrics.
All included
One module — from keys and webhooks to the playground.
- 30 resources
- API keys
- Scopes
- JWT
- IP whitelist
- Rate limits
- 57 webhooks
- HMAC signature
- OpenAPI 3.1
- Playground
- Request logs
- Analytics
- Batch
- Action endpoints
- Global search
- Compatibility mode
See the API platform in action
From key management and webhooks to the request logs.
Three ways to authenticate
REST API Pro supports modern and legacy auth, secured server-side.
API key
Hashed keys (SHA-256), shown only once, with scopes and rate limits.
JWT
Token exchange via /v1/auth/token with a per-install secret.
Legacy mode
Compatible headers (authtoken, X-API-KEY) for migrating existing setups.
Security is built in: hashed keys (SHA-256), per-resource scopes, SSRF protection for webhooks, CSRF-safe writes, rate-limit headers and per-install JWT secrets.
Requirements
- Perfex CRM 3.0 or newer
- PHP 7.4+ (8.x recommended)
- PHP cURL extension enabled
- HTTPS endpoint for webhook delivery
In the download
- The module as a ZIP (upload & activate)
- German & English documentation
- Access to the public bug tracker & roadmap
- 12 months of updates, 6 months of support
API scope
- 30 CRUD resources
- Action & helper endpoints
- 57 webhook events
OpenAPI 3.1, playground and code samples included.
Get REST API Pro
Secure payment & instant download via perfexcrm-module.com.
- The module as a ZIP (upload & activate)
- German & English documentation
- Access to the public bug tracker & roadmap
- 12 months of updates, 6 months of support
Frequently asked questions
Which entities does the API cover?
Full CRUD across 30 resources — customers, contacts, leads, invoices, quotes, projects, tasks, tickets and more.
How is authentication secured?
Hashed API keys (SHA-256) with scopes, optional JWT, plus IP whitelist, expiry dates and per-key rate limits.
Are there webhooks?
Yes. 57 events, HMAC-signed, with exponential retry and SSRF protection.
Is there documentation to test against?
Yes. An auto-generated OpenAPI 3.1 spec with a Try-it playground and samples in cURL, PHP, JS and Python.
Can I migrate from an older Perfex API?
Yes. A compatibility mode maps legacy requests and responses transparently.
Do I get updates?
Yes. 12 months of updates and 6 months of support via perfexcrm-module.com.
Want your own Perfex module?
We build tailor-made extensions for Perfex CRM. Tell us about your workflow.