canonical: https://jentic.com/apis/zenoti.com/zenoti

# Zenoti API

Zenoti spa/salon management API. The API exposes 15 endpoints secured with bearer authentication.

## For AI agents

Programmatically generate access token, revoke access token. Covers 15 operations with bearer authentication.

## Scope

Does not handle payments, communications, or crm - use for developer tools only.

## Capabilities

- Generate access token
- Revoke access token
- List all centers
- Get center details
- Create guest

## Use cases

### Developer Tools Operations

Use the Zenoti API to perform developer tools operations programmatically. The API provides 15 endpoints covering core functionality including generate access token, revoke access token, list all centers.

Example prompt: Call POST /tokens to generate access token

### Automated Auth Management

Automate auth operations by combining multiple Zenoti API endpoints. Agents can revoke access token and then list all centers in a single workflow.

Example prompt: Call DELETE `/tokens/sessions/revoke` to revoke access token, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Zenoti API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle bearer tokens manually.

Example prompt: Search Jentic for 'generate access token', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| POST | `/tokens` | Generate access token |
| DELETE | `/tokens/sessions/revoke` | Revoke access token |
| GET | `/centers` | List all centers |
| GET | `/centers/{center_id}` | Get center details |
| POST | `/guests` | Create guest |
| GET | `/guests` | List guests |
| GET | `/guests/{guest_id}` | Get guest |
| PUT | `/guests/{guest_id}` | Update guest |

## Key resources

- **Auth** — Operations related to Auth
- **Bookings** — Operations related to Bookings
- **Centers** — Operations related to Centers
- **Employees** — Operations related to Employees
- **Guests** — Operations related to Guests

## AI readiness

This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.

- **Score:** 70 / 100
- **Maturity:** AI-Aware
- **Dimensions:**
  - Foundational Compliance: 100 / 100
  - Developer Experience & Jentic Compatibility: 63 / 100
  - AI-Readiness & Agent Experience: 51 / 100
  - Agent Usability: 94 / 100
  - Security: 60 / 100
  - AI Discoverability: 100 / 100
- **View full report:** https://jentic.com/apis/zenoti.com/zenoti/scorecard
- **How the score is calculated:** https://docs.jentic.com/reference/api-readiness-framework/overview/
- **More about the dimensions:** https://docs.jentic.com/reference/api-readiness-framework/specification/#dimensional-model-overview

### Score it yourself

Every API in the directory is allowlisted, so you can re-score it with no key required.

- **Score your own API:** https://jentic.com/scorecard.md
- **Scoring CLI agent skill:** https://github.com/jentic/jentic-api-scorecard/blob/main/skills/jentic-api-scorecard/SKILL.md

```sh
npx @jentic/api-scorecard-cli score <openapi-url>
```

## Why Jentic

- **Setup:** Wiring the Zenoti API by hand means minting its bearer token from the tokens endpoint, working through center and guest paths on api.zenoti.com/v1, and coding request handling yourself. Through Jentic you install once, import Zenoti from the API Directory, store the token once, and your agent calls it.
- **Permission scoping:** Zenoti puts the center and guest ids in the URL path (`/centers/{center_id}` and `/guests/{guest_id}`), so a rule can pin your agent to one center or guest. You choose the operations it may call, so revoking token sessions is not included unless you add it.
- **Credential handling:** Your Zenoti token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'list centers' or 'look up a guest', and Jentic returns the matching Zenoti operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Github** — Alternative developer tools API
- **Gitlab** — Alternative developer tools API

## FAQ

### What authentication does the Zenoti API use?

The Zenoti API uses a Bearer token in the Authorization header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I generate access token with the Zenoti API?

Yes. Use the POST /tokens endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Zenoti API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I generate access token through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'generate access token'. Jentic returns the matching Zenoti API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Zenoti API have?

The Zenoti API exposes 15 endpoints covering auth, bookings, centers operations.

### Can I limit what my agent is allowed to do with the Zenoti API?

Yes. Because Jentic One is self-hosted, your own rules decide which Zenoti operations and credentials the agent may use. Since Zenoti carries the center and guest ids in the URL path (`/centers/{center_id}` and `/guests/{guest_id}`), you can pin the agent to a single center or a single guest, and you choose the exact operations it may call, so something like revoking token sessions stays off unless you add it. The token is injected only for the calls you have approved.
