Aller au contenu principal
FIG 0.0 · DEVELOPERS

Wire your AI into your CRMin 30 seconds.

A single MCP URL wires Claude, ChatGPT, Cursor or n8n into your CRM. ~200 tools through a universal endpoint, rotatable keys, signed webhooks, OAuth 2.0 — plus a dual Law 25 audit log.

Free 14-day trial

No credit card required.

toncrm.io developer space: API, keys and webhooks
FIG 0.1 · CONNECTION

Three steps. Not a single line of code.

MCP is hosted by URL — zero npm, zero local server. It works even from an iPad or a Chromebook. One URL, and your CRM becomes a tool for any AI.

MCP client
# just 1 URL — no npm, no local server
https://app.toncrm.io/api/mcp/sse?key=tcrm_live_•••••

# → ~200 CRM tools show up in the agent
FIG 0.2 · CLIENTS COVERED

Your CRM talks to all your agents.

Hosted MCP, plain REST, Custom GPT manifest, no-code n8n. You don't have to pick your agent — the same key connects them all.

Claude
MCP
Cursor
MCP
ChatGPT
Custom GPT
Gemini
MCP / REST
n8n
REST
Zed
MCP
Postman
Collection
Your code
REST + OpenAPI
FIG 0.3 · UNIVERSAL ENDPOINT

~200 tools, a single key.

A single endpoint /api/v1/tools/call exposes the same tool registry as the internal AI agent — with a scope per tool and a log of every call. Your CRM lends its own tool brain to any external agent.

Rare among SMB CRMs: exposing the internal tool registry to third-party agents, scoped and audited — that's platform-grade.
List my 5 latest contacts
Connected agent
Here are your 5 latest contacts: Réno Bouchard, Garage Néon, Clinique Lavoie, Plomberie Rivard, Marie-Claude Roy.
Create a $5,000 deal for Jean Tremblay
Connected agent
Deal created — 5 000 $ · « Jean Tremblay » · New stage. Call logged in your audit log (top tools 24 h).
tcrm_live_•••••••••••
sha256-hashed · secret shown once
24 granular scopes (FR)
Zero-downtime rotation · grace window
IP allowlist (CIDR) per key
FIG 0.4 · API KEYS

Keys at Stripe level.

The tcrm_live_ prefix is picked up by GitHub secret scanners. The key is hashed, the secret shows only once, and you choose exactly which scopes it can touch. You rotate without breaking anything thanks to a grace window — the old and new key run in parallel while you migrate.

FIG 0.5 · WEBHOOKS

Signed webhooks, built-in leak protection.

Every outbound webhook is signed HMAC-SHA256, with a one-time secret, a manual test, delivery history and replay. An SSRF guard blocks internal targets (cloud IMDS, private IPs, loopback…) before every send. Deterministic retry, and auto-disable after repeated failures.

vs the rest: HubSpot often pushes you to Operations Hub for this level. Here it's native — enterprise security on an SMB CRM.
deal.won → POST delivered · 200 OK
# verify the signature
X-TonCRM-Signature: sha256=a3f1•••
X-Webhook-Event: deal.won
X-Delivery-Id: whd_8c2•••
SSRF guard · 14 cases blocked
.well-known/oauth-authorization-server
RFC 8414 discovery
authorization_code + refresh_token
standard grants
PKCE S256 / plain
anti-interception
apps confidential / public
third-party registration
FIG 0.6 · OAUTH 2.0

A full OAuth server to connect other apps.

Full OAuth 2.0 server: .well-known discovery (RFC 8414), authorization_code + refresh_token grants, PKCE, third-party app registration. A dev can build on top of it, cleanly.

FIG 0.7 · LAW 25 AUDIT

Your API access, traceable to Law 25.

Two distinct audit logs — a native API access registry SMB competitors don't have.

Lifecycle of sensitive actions
Creation, rotation, revocation, scope or IP-allowlist change — every action leaves a timestamped trail.
Log of every call
Every tool invocation is logged. Arguments are kept only as a sha256 fingerprint — privacy by default.
Enterprise bonus: a native JSONL audit stream for your SIEM (Splunk / Datadog / Sentinel), gated by admin scope. Plus a Law 25-oriented DPA served from a public endpoint.
FIG 0.8 · THE DETAILS THAT MATTER

The kind of thing an integrator notices.

Zero-downtime rotation
Stripe-style: a grace window accepts the old and new key in parallel while you migrate your services.
IP allowlist per key
Restrict a key to a CIDR block. If the call comes from elsewhere, hard refusal.
Idempotency-Key
Stripe-style anti-duplicate on actions: you replay a call, it doesn't create the same thing twice.
Dynamic OpenAPI 3.1
The spec is generated from the tool registry — each new tool shows up without re-publishing. Postman collection included.
Bulk create (100/call)
Import up to 100 contacts in one call, with dry_run to validate before writing.
ETag + cursor pagination
If-None-Match, sparse fieldset ?fields= and cursor pagination — light on your lists.
Semantic search
Search by embeddings (cosine, min_similarity) directly through the API.
Right to be forgotten in the API
Per-contact forget endpoint (Law 25 / GDPR Art.17) + per-contact export and summary.
Custom GPT manifest
Auto-generated, ready to paste: publish your own TonCRM GPT in a few clicks.
FIG 0.9 · ALL IN ONE PLACE

API, webhooks, OAuth — on a single page.

Rotatable keys, signed webhooks, OAuth server, OpenAPI spec, audit log. Not three separate portals — a single developer hub, built for an entrepreneur, not just for a dev.

API keys
Webhooks
OAuth 2.0
OpenAPI
Law 25 audit
FIG 1.0 · FAQ

Everything about the API.

You paste a single MCP URL (SSE transport) into Claude, Cursor, Zed or your MCP client — zero npm, zero local server. Your CRM tools show up and the agent drives your CRM in plain language.

Nothing to install server-side. The MCP is hosted by URL, so it works even from an iPad or a Chromebook. You generate a key, copy the URL, and it's connected.

Keys are sha256-hashed, the secret is shown only once, and each key has its own granular scopes plus an optional IP allowlist. You can rotate a key without downtime using a grace window.

Yes — two audit logs: a lifecycle of sensitive actions (creation, rotation, revocation, scope change) and a log of every tool call. It's an access registry compliant with Law 25.

Every webhook is signed HMAC-SHA256, protected by an SSRF guard, with deterministic retry and auto-disable after repeated failures.
L'entrepreneur d'aujourd'hui
FIG 1.1 · GET STARTED

Generate your first key.

14 days free, no card. Wire Claude into your CRM, or book a demo and we'll show you live.

Free 14-day trial

We'll wire your AI into your CRM in a 45-sec demo.

Essai gratuit 14 joursAppeler Clodyne

Ready to see toncrm.io for real? We show it to you set up for your trade.

Book a 15-minute demo — or start your free trial right away.

Free 14-day trial

No credit card · Setup done for you · French-language support

Features