What the API cannot do

The things that stay in the WoodSystems web app and are not available through the API or the MCP server.

Some things are done only in the WoodSystems web app, by a person who is signed in. They are not in the API and not in the MCP server.

  • Money movement: taking payments, charging cards, payment links and refunds. Payments can be read, never created or changed.
  • Payroll and time: payroll, approving or locking timesheets, and writing time entries. Time entries can be read.
  • People: adding or removing users and changing roles.
  • Billing: the account's subscription and billing.
  • Deleting records: jobs, contacts, estimates, invoices, payments, files and products are never deleted through the API.
  • Signatures: sending documents for signature.
  • Account setup: account settings, statuses, custom field definitions, workflows and timeline templates.
  • QuickBooks: running the QuickBooks sync.
  • Phone and text: phone numbers and text messages.
  • Production: releasing work orders to the shop.

Connected apps that sign in through OAuth, including MCP clients, are held to a shorter list still: they can never delete anything, manage webhooks or read usage, whatever their scopes. See scopes.