Business Box API
A REST API over your bookings, with webhooks for anything that changes. 12 operations, 4 events, and an OpenAPI document you can hand to a code generator.
https://api.marubox.jp/v1. Authenticate with Authorization: Bearer <your API key>, created under Settings → Integrations in the app. It is available on every plan, including free.What it is for#
Two kinds of thing connect to this API, and both are supported the same way.
Automation platforms. Zapier, Make, n8n, Power Automate and the rest. You paste an API key into their connection screen and build steps: when a booking is created, add a row to a spreadsheet; when a form is submitted, create a booking. You write no code.
Your own software. A CRM, an internal dashboard, a website that books on a customer's behalf. You call the endpoints directly.
If you only want your bookings in another calendar, you do not need any of this — connect Google or Microsoft in the app and it happens by itself. The user guide covers that.
The shape of it#
- Base URL
https://api.marubox.jp/v1. It will not move: it is in other people's configuration files. - Authentication is a bearer token. See Authentication.
- JSON only, in and out. Send
Content-Type: application/jsonon writes. - Times are ISO 8601 in UTC, always with a
Z. Timezones are IANA names such asAsia/Tokyo. - Money is an integer in the currency's minor units. JPY has no minor unit, so
5000is ¥5,000. - Ids are 24-character hexadecimal strings.
- Lists return
{ "items": [...], "nextCursor": "…" }. See the reference.
Where to start#
- Quickstart — a key, a first call, and a booking, with curl.
- Authentication — keys, scopes and what each one allows.
- Reference — every operation, generated from the OpenAPI document.
- Webhooks — get told when something changes, with signature verification in Node and Python.
- Errors — the envelope and every code it can carry.
- Rate limits — the budget and the headers.
- Changelog — what changed, and what "v1" promises.
The OpenAPI document#
Version 1.0.0, OpenAPI 3.1, covering all 12 operations across 9 paths and describing the 4 webhook payloads under the 3.1 webhooks key.
curl https://api.marubox.jp/v1/openapi.json
It needs no token, because every API directory and explorer fetches it anonymously. It is generated from the running code and checked in CI, so it cannot drift from the API — the reference on this site is built from the same file.
Common questions
Do I need a paid plan to use the API?
No. The API, webhooks and the MCP server are on every plan, including free. Taking card payments needs a subscription, but that is a limit on the booking feature, not on the API.Is there a sandbox?
Not a separate one. Create a second event type that is not published and book against that; nothing about a booking made through the API differs from one made in the app.Which language should I use?
Any. It is HTTP and JSON with bearer auth, and the OpenAPI document will generate a client for most languages.Last reviewed 28 September 2026.