API v4, webhooks and MCP

Your systems work here too

API v4, two-way webhooks, and MCP as both server and client. Each key performs only the operations you allow: if it leaks, the possible damage is what you decided.

  • Browsable OpenAPI schema
  • Allowlist per key
  • MCP writes off by default

Data and integrations

API v4, webhooks and MCP: what it does

API v4, REST and documented

Documents, customers and contacts, assets, projects with their line items, checklists and attachments. The OpenAPI schema is browsable and lets you try the calls before writing any code.

Permissions per key

One key per integration, with permissions by area and by operation. Operations are grouped in bundles: read-only, field, sales, ERP and AI assistant. Expiry, rate limits and revocation.

System accounts

Your integrations sign in with system accounts, which do not use a license. Each one has only the permissions it needs, and the allowlist is checked on every request.

Two-way webhooks

Outgoing, to notify your systems when something happens, with history and resend. Incoming, so an external system can trigger a flow. And a flow step calls any API without code.

MCP server

Connect your assistant, such as Claude or ChatGPT, and ask about documents, customers or assets. It answers with what that person is allowed to see and cites where it got it. Writes come turned off.

MCP client

attendo also connects to third-party MCP servers. From a flow or from the record, an agent asks your ERP whether a part is in stock. The answer goes into their reply.

How it works

Step by step

This is how it is used day to day, on the same document as the rest of the modules.

  1. Step 1

    You create the key

    With the operation bundle the integration needs, its expiry and its limit.

  2. Step 2

    You test in staging

    With the OpenAPI schema and a staging instance, before touching real data.

  3. Step 3

    You connect your systems

    Via API, via webhook or with a flow step that calls their API.

  4. Step 4

    You monitor it

    Every outgoing webhook keeps its history, and it can be resent if needed.

marIA in API v4, webhooks and MCP

With the MCP server, your AI assistant queries attendo with each person’s permissions. And as an MCP client, marIA asks your ERP or other MCP servers from the record. Every marIA operation is logged with who ran it, the model and its cost.

Honesty

Where it fits (and where it does not)

  • Instance configuration is not done via API: document types, fields, permissions and flows are configured in the interface.

  • There is no published rate limit, but there is abuse control. If you plan to move a lot of volume, we size it with you.

Glossary

Glossary terms

Processes and automation

Webhook

HTTP callback · reverse API

A webhook is an automatic notice that one system sends to another, at a web address, as soon as something happens: a new order, a payment or an approved document.

Maintenance

Predictive maintenance

PdM

Predictive maintenance decides when to intervene based on the real condition of the equipment, measured through vibration, temperature, power draw or oil analysis, not by calendar.

Maintenance

Critical spare part

Critical spare

A critical spare part is one whose absence holds up the repair and drags out the equipment’s downtime. It is not the most expensive part or the most used one: it is the one you cannot get quickly.

See all 53 glossary terms

Frequently asked questions

Frequently asked questions

Is the API documented?

Yes. API v4 has a browsable OpenAPI schema where you can try the calls.

What happens if a key leaks?

It can only perform the operations on its allowlist, and you revoke it without touching the others. The possible damage is what you decided when you created it.

What is the difference between the MCP server and the MCP client?

The server lets your assistant query attendo. The client does the opposite: attendo connects to third-party MCP servers and queries them from a flow or from the record.

Can my AI assistant change data over MCP?

Not by default. Writes come turned off, and turning them on requires a double lock.

Can I test before connecting production?

Yes. We set up a staging instance so you can test your integration.

Request a demo

Try it with your processes

We will show it to you with your own document types and the way you work. If it is not a fit, we will tell you.

  • With your operation, not a generic demo
  • A real person from our team replies
  • No cold calls afterwards

Would you rather talk first?

Which area do you want to see in the demo?

With your work email we prepare the demo around your case.

In one or two sentences.

If you chose Maintenance (CMMS)

If you chose Field work (Field Service)

If you chose Facility Management

If you chose any other area

Only if you would rather we call you.

Data protection. Controller: AxisOne Group SL. Purpose: preparing the demo you request and replying to you. Legal basis: your consent and the request you make. Recipients: we do not disclose your data; Cloudflare (website) and Brevo (email notices and confirmation) process it on our behalf. Rights: access, rectification, erasure, objection, restriction and portability, at privacy@attendo.me. More information in the privacy policy.

What happens when you send it. Someone from our team reads what you tell us and writes to you to agree on a time for the demo. Our hours: Monday to Thursday 9:30 AM to 6:30 PM and Friday 9:30 AM to 2:30 PM, Spain time.