API & Integrations BUSINESS

Features

Connect OrgCanvas to Zapier, your HRIS, custom scripts, or any tool that supports REST APIs. Use the API to keep your org chart automatically in sync with the systems where your team data lives.

Generating an API key

  1. Open OrgCanvas and make sure you're in a Business workspace (API access is a Business-tier feature)
  2. Click your avatar in the top-right and choose Settings
  3. In the settings sidebar, choose API & Integrations
  4. Click Generate New API Key, give it a descriptive name (e.g., "Zapier production"), and optionally set an expiration
  5. Copy the key immediately — for security reasons, we don't show it again after you close the dialog
Heads up: Treat API keys like passwords. If a key is leaked, revoke it immediately in Settings → API & Integrations.

Making your first request

All API requests go to https://api.orgcanvas.app/api/v1/ and must include your API key as a Bearer token:

curl https://api.orgcanvas.app/api/v1/me \ -H "Authorization: Bearer oc_live_..."

A successful response looks like:

{ "workspace": { "id": "ws_abc123", "name": "Acme Corp", "plan": "business" }, "user": { "email": "[email protected]", "name": "Your Name" } }

Available endpoints

Read data

MethodEndpointDescription
GET/v1/meReturn workspace and user info for this key
GET/v1/canvasesList all canvases in the workspace (newest first)
GET/v1/canvases/:idGet a single canvas with full org data
GET/v1/peopleList all people across all canvases

Modify data

MethodEndpointDescription
POST/v1/canvasesCreate a new canvas
POST/v1/canvases/:id/peopleAdd a person to a canvas
PUT/v1/canvases/:id/people/:keyUpdate a person's name, title, department, or manager
DELETE/v1/canvases/:id/people/:keyRemove a person from a canvas

Authentication

Every request must include your API key. Two methods are supported:

The Bearer header is preferred because it keeps the key out of URLs, server logs, and browser history.

Rate limits

Each API key is limited to 1,000 requests per hour. Every response includes headers showing your current usage:

X-RateLimit-Limit: 1000 X-RateLimit-Remaining: 847 X-RateLimit-Reset: 1776487200

If you exceed the limit, you'll get a 429 Too Many Requests response with a Retry-After header telling you how many seconds to wait.

Zapier integration

The OrgCanvas Zapier integration is the fastest way to connect OrgCanvas to tools you already use without writing any code. It's currently in private beta — available to all Business customers on request.

What's included:

Want early access? Email [email protected].

Error codes

CodeMeaning
200Success
201Resource created (for POST endpoints)
400Invalid or missing required fields in your request
401Missing, invalid, or expired API key
403Plan doesn't allow API access (upgrade to Business+)
404Canvas or person not found
429Rate limit exceeded — check Retry-After header
500Server error — retry with exponential backoff

Example: Add a person from a script

curl -X POST \ https://api.orgcanvas.app/api/v1/canvases/YOUR_CANVAS_ID/people \ -H "Authorization: Bearer oc_live_..." \ -H "Content-Type: application/json" \ -d '{ "name": "Jane Doe", "title": "Senior Engineer", "dept": "Engineering", "parent": "manager_key_here" }'
Business feature: API access is available on the Business plan. View plans
Back to Features