public
POST /v1/public/quotes
Ask us to price a project — no account.
Authentication
This endpoint is public. It takes no credential and no organisation — it is what our own marketing site and AI answer engines read.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/public/quotes \
-H "Content-Type: application/json" \
-d '{ "name": <string>, "email": <string>, "description": <string>, "project_type": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Anonymous — no credential, no tenant, and the only route into paid development work (development services are quote-only, owner ruling 2026-09-11). Three spam controls fire in order: a fail-closed per-IP and global budget charged before the body is parsed, a honeypot field, then Cloudflare Turnstile. The cheapest first, and the one that makes a vendor call last — so a flood cannot turn our anti-abuse check into an outbound traffic amplifier. ⛔ multipart/form-data accepts attachments (a brief, a spec, a screenshot of the error). They are magic-byte verified against an allow-list and are not servable to anybody until a malware scan returns clean. ⛔⛔ An attachment refused after the enquiry is written does not fail the request. The reply is still 201 with attachments_refused set: throwing away a description somebody spent ten minutes on because a file was the wrong type loses the customer and reads, to them, as the form being broken.
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
name | string | Yes | — |
email | string | Yes | — |
description | string | Yes | What they need doing — the thing we actually price. ⛔ Bounded here as well as in the engine: a TextField has no length, and an operator has to READ this. |
project_type | string | Yes | The shape of the work, from project_types. Deliberately not the technology — a WordPress build and a bespoke application are quoted by different people on different lead times;… |
company | string | No | — |
phone | string | No | — |
country | string | No | ISO 3166-1 alpha-2. |
stack | string | No | — |
budget_band | string | No | A RANGE, never a figure. Somebody who has not been quoted does not have a number, and storing one invents a precision they never gave — which an operator then anchors their quote… |
timeline | string | No | — |
website_url | string | No | The site the job is about. ⛔ Optional and may be blank: a broken site is one of the commonest reasons to be here, and refusing the enquiry over a URL loses exactly the customer in… |
locale | string | No | The language the form was filled in. ⛔ The confirmation is sent in it — without this a platform sold in 58 languages answers every enquiry in English, and nothing looks broken. |
source_page | string | No | Which page the form was submitted from — how we learn what converts. |
turnstile_token | string | No | Cloudflare's token. ⛔ Not marked required: whether it is needed is the engine's answer (is a secret configured?), not the schema's — hard-coding required would make an… |
website_confirm | string | No | ⛔ Leave this empty. It is a honeypot, and it is documented rather than hidden because an SDK consumer that populated every string field would otherwise be refused with no way to… |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
reference | string | Yes | The short handle a human quotes back at us, e.g. QR-2609-K7M3PX. ⛔ Not sequential: a running number published to strangers leaks how much work we are winning, and nothing here… |
status | string | Yes | — |
attachments_stored | integer | Yes | — |
attachments_refused | string | Yes | Copy for the visitor when a file could not be attached, or null. ⛔ The enquiry was still accepted — see the endpoint description. |
Errors this endpoint can return
422 · 429