# CRM

Part of AppEngine API Documentation. Full index: https://appengine.appmint.io/documentation.md
## GET /crm/flexdata/get/{id}

**Get flex data**

`operationId: CRMController_getFlexData`

Reads flexible, schema-less records scoped to the caller. Supply `id` for one, or a `query` to filter.

#### Signature

```http
GET /crm/flexdata/get/{id} (id: string, query?: string) -> The matching flex data
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Errors

| Status | Code | Message | When | What to do |
| --- | --- | --- | --- | --- |
| `401` | CUSTOMER_REQUIRED | customer is required | No signed-in customer or user could be resolved. | Sign in — these routes are scoped to the caller. |

Plus the standard platform errors: `403`, `429`, `500`.

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `query` | query | string | — | Filter expression. |
| `id` | path | string | yes | Record id. Omit to query. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | The matching flex data |
| `401` | customer is required — No signed-in customer or user could be resolved. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## GET /crm/place/near-by

**Find nearby places**

`operationId: CRMController_getNearbyPlaces`

Looks up places near a point, backed by a maps provider.

**This route reads no `orgid` header** and is not scoped to an organization — it is a plain proxy to the places lookup.

#### Signature

```http
GET /crm/place/near-by (lat?: number, lng?: number, radius?: number, type?: string) -> Nearby places
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`).

#### Notes

- Backed by a billable maps provider — do not call it per keystroke.

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `lat` | query | number | yes | Latitude. |
| `lng` | query | number | yes | Longitude. |
| `radius` | query | number | yes | Search radius in metres. |
| `type` | query | string | yes | Place type to search for. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | Nearby places |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

