TowAgent Partner API
Get your data in, get release facts back
Push impounds from your dispatch or impound system, read the balance TowAgent computes today, place and release holds, and record releases made at the counter. Subscribe to webhooks for payments and releases so your books stay right without polling.
Spec: /openapi.json (OpenAPI 3.0). Keys and webhook endpoints live in Admin → Settings → Integrations.
Authentication
Bearer token. Keys are scoped; ask for the least you need.
curl https://towagent.io/api/v1/vehicles?status=impounded \
-H "Authorization: Bearer ta_live_3f9c1a2b7e4d_..."Push an impound
Upsert by plate. Include the tow fee and daily storage rate and TowAgent computes the balance every day on its own.
curl -X POST https://towagent.io/api/v1/vehicles \
-H "Authorization: Bearer ta_live_..." \
-H "Idempotency-Key: inv-48213" \
-H "Content-Type: application/json" \
-d '{
"licensePlate": "ABC1234", "vin": "1HGCM82633A004352",
"make": "Honda", "model": "Accord", "year": 2019, "color": "Silver",
"towDate": "2026-09-08", "towReason": "Private property",
"towFee": 185, "dailyStorageRate": 45,
"locationId": "loc_main", "lotLocation": "B-12",
"ownerName": "J. Rivera", "ownerPhone": "+15125550123",
"towCompanyReference": "INV-48213"
}'Read the balance today
GET /api/v1/vehicles/{id}
→ { "data": { ..., "balance": { "total": 320.00, "storageDays": 3, "lines": [...] } } }Webhooks
Register an https endpoint and pick events. Every delivery is signed. Verify before trusting the body.
X-TowAgent-Event: payment.completed
X-TowAgent-Signature: t=1725900000,v1=5f1c…
expected = HMAC_SHA256(secret, t + "." + rawBody)
accept if hex(expected) == v1 and |now - t| <= 300sEvents: vehicle.created, vehicle.updated, vehicle.released, payment.completed, payment.refunded, hold.placed, hold.released, call.ended. Retries: 8 attempts over roughly 48 hours; return 2xx to acknowledge.
Conflict rule
Your system is the source of truth for vehicle facts (make, model, tow details, owner). TowAgent is the source of truth for payment and release facts. PATCH cannot mark a vehicle paid; releases go through the release endpoint or the kiosk, and you hear about both by webhook.
Rate limit: 120 requests per minute per key. Questions: support@towagent.io