Build on hoa.to
hoa.to is the system of record for a community. Our open API, webhooks and Zapier connector let you sync data both ways, automate workflows, and build on top — instead of being locked into a closed ecosystem.
Authentication
Create an API key in Console → Integrations → API keys, then pass it as a bearer token:
curl https://hoa.to/api/v1/owners \
-H "Authorization: Bearer hoa_live_xxx"The v1 API is live now — scoped to the key’s community. Endpoints below are real.
Endpoints
| GET | /v1/owners | List owners and units in a community |
| POST | /v1/payments | Record or initiate a dues payment |
| GET | /v1/ledger/:unit | Pull a unit's ledger and balance |
| POST | /v1/requests | Create a maintenance or ARC request |
| POST | /v1/violations | File a violation with photos |
| POST | /v1/documents | Upload and publish a document |
| GET | /v1/meetings | List meetings and minutes |
| POST | /v1/webhooks | Register an outbound webhook endpoint |
Webhook events
Every payload is HMAC-SHA256 signed with your endpoint secret in the X-HoaTo-Signature header.
No-code with Zapier
Not a developer? Connect hoa.to to thousands of apps with Zapier — turn “new payment,” “new violation,” or “resident moved out” into any action, no engineering required.
Open the Integration Hub →Getting started
- Create an API key from your community's Console under Integrations → API keys.
- Make a test call against the sandbox with seeded data before pointing at a live community.
- Register a webhook endpoint for the events your integration needs, and verify the HMAC signature on every payload.
- Move to your live API key once the integration behaves as expected against the sandbox.
Frequently asked questions
Do I need to be a developer to connect hoa.to to another tool?
No — the Zapier connector covers common triggers and actions (new payment, new violation, resident moved out) without writing any code. The REST API and webhooks are for custom integrations.
Is the sandbox separate from live community data?
Yes — the sandbox uses seeded test data so you can build and test an integration without touching a real community's records.
How are webhook payloads secured?
Every payload is signed with HMAC-SHA256 using your endpoint's secret, delivered in the X-HoaTo-Signature header, so your endpoint can verify it actually came from hoa.to.
What scopes does OAuth 2.0 support?
Partner apps request scoped access rather than a full account key, so a community can grant only the access a given integration actually needs.