public

POST /v1/public/quotes

Ask us to price a project — no account.

All public endpoints

All developer docs

Authentication

This endpoint is public. It takes no credential and no organisation — it is what our own marketing site and AI answer engines read.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/public/quotes \
  -H "Content-Type: application/json" \
  -d '{ "name": <string>, "email": <string>, "description": <string>, "project_type": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Anonymous — no credential, no tenant, and the only route into paid development work (development services are quote-only, owner ruling 2026-09-11). Three spam controls fire in order: a fail-closed per-IP and global budget charged before the body is parsed, a honeypot field, then Cloudflare Turnstile. The cheapest first, and the one that makes a vendor call last — so a flood cannot turn our anti-abuse check into an outbound traffic amplifier. ⛔ multipart/form-data accepts attachments (a brief, a spec, a screenshot of the error). They are magic-byte verified against an allow-list and are not servable to anybody until a malware scan returns clean. ⛔⛔ An attachment refused after the enquiry is written does not fail the request. The reply is still 201 with attachments_refused set: throwing away a description somebody spent ten minutes on because a file was the wrong type loses the customer and reads, to them, as the form being broken.

Request body

NameTypeRequiredWhat it is
namestringYes
emailstringYes
descriptionstringYesWhat they need doing — the thing we actually price. ⛔ Bounded here as well as in the engine: a TextField has no length, and an operator has to READ this.
project_typestringYesThe shape of the work, from project_types. Deliberately not the technology — a WordPress build and a bespoke application are quoted by different people on different lead times;…
companystringNo
phonestringNo
countrystringNoISO 3166-1 alpha-2.
stackstringNo
budget_bandstringNoA RANGE, never a figure. Somebody who has not been quoted does not have a number, and storing one invents a precision they never gave — which an operator then anchors their quote…
timelinestringNo
website_urlstringNoThe site the job is about. ⛔ Optional and may be blank: a broken site is one of the commonest reasons to be here, and refusing the enquiry over a URL loses exactly the customer in…
localestringNoThe language the form was filled in. ⛔ The confirmation is sent in it — without this a platform sold in 58 languages answers every enquiry in English, and nothing looks broken.
source_pagestringNoWhich page the form was submitted from — how we learn what converts.
turnstile_tokenstringNoCloudflare's token. ⛔ Not marked required: whether it is needed is the engine's answer (is a secret configured?), not the schema's — hard-coding required would make an…
website_confirmstringNo⛔ Leave this empty. It is a honeypot, and it is documented rather than hidden because an SDK consumer that populated every string field would otherwise be refused with no way to…

Response

NameTypeRequiredWhat it is
referencestringYesThe short handle a human quotes back at us, e.g. QR-2609-K7M3PX. ⛔ Not sequential: a running number published to strangers leaks how much work we are winning, and nothing here…
statusstringYes
attachments_storedintegerYes
attachments_refusedstringYesCopy for the visitor when a file could not be attached, or null. ⛔ The enquiry was still accepted — see the endpoint description.

Errors this endpoint can return

422 · 429