Summit NetworksHelp Desk API v1

Help Desk API

Send questions and incidents to the Summit Networks AI help desk from your own systems: a service desk, an RMM alert, a chat bot or a script. The AI answers in the same request. When a ticket needs an engineer, it is handed off and the engineer's replies show up in the ticket's messages.

Base URL https://help.summitnet.io/v1 · JSON in, JSON out · OpenAPI 3.1 spec

1. Get a key

Keys are issued by Summit Networks to client companies. Ask your Summit contact or email support@summitnet.io. A key belongs to your company, acts as one named contact, and sees all of your company's tickets. Keep it on your server: the API does not allow browser (CORS) calls, so a key never has to sit in a web page.

Authorization: Bearer shd_live_...

Lost or leaked key? Ask us to revoke it. A revoked key stops working within 30 seconds.

2. Ask a question or report an incident

curl https://help.summitnet.io/v1/tickets \
  -H "Authorization: Bearer $SUMMIT_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: your-ticket-48213" \
  -d '{
    "type": "incident",
    "subject": "Outlook keeps asking for a password",
    "message": "Since this morning Outlook on two laptops prompts for a password every few minutes.",
    "requester": { "name": "Dana Lee", "email": "dana@yourcompany.com" },
    "externalId": "INC-48213"
  }'

The response is 201 with the ticket and its messages, including the AI's first reply (usually 5 to 30 seconds; allow up to 90).

{
  "ticket": { "id": "…", "number": "SN-T-2026-0042", "status": "triaged", "priority": "p3",
              "handledBy": "ai", "subject": "Outlook password prompts on two laptops", … },
  "messages": [
    { "from": "customer", "author": "Dana Lee", "text": "Since this morning…" },
    { "from": "ai", "author": "Summit AI help desk", "text": "Thanks, Dana. Let's check…" }
  ]
}

3. Continue the conversation

curl https://help.summitnet.io/v1/tickets/SN-T-2026-0042/messages \
  -H "Authorization: Bearer $SUMMIT_KEY" -H "Content-Type: application/json" \
  -d '{ "text": "Signing out of Office and back in fixed it on one laptop, not the other." }'

While the AI handles the ticket, its reply comes back in the response. After a hand-off to an engineer, your message goes to the engineer, and you can poll the ticket for their reply.

GET  /v1/tickets/{id}                 the ticket and its public messages
GET  /v1/tickets?status=triaged,in_progress&updated_since=2026-10-05T00:00:00Z&limit=50
POST /v1/tickets/{id}/resolve         confirm it's fixed  { "resolution": "optional note" }
GET  /v1/me                           which company and contact your key acts as

{id} is the ticket id or its number (SN-T-…). Every create also accepts PUT instead of POST.

4. Get changes pushed to you (webhooks)

Instead of polling, register an HTTPS endpoint and we'll POST to it when something happens on your company's tickets: ticket.created (opened outside your integration, e.g. by phone or the web), ticket.message (a reply from the AI, an engineer or a web user) and ticket.status_changed. Your own API calls are never echoed back.

curl https://help.summitnet.io/v1/webhooks \
  -H "Authorization: Bearer $SUMMIT_KEY" -H "Content-Type: application/json" \
  -d '{ "url": "https://yourinstance.example.com/api/summit/events" }'
# 201 { "id": "…", "secret": "whsec_…", "events": [...] }   (the secret is shown once)

curl -X POST https://help.summitnet.io/v1/webhooks/{id}/ping -H "Authorization: Bearer $SUMMIT_KEY"

Each delivery is a JSON body { id, type, createdAt, ticket, message?, previousStatus? } with headers X-Summit-Event, X-Summit-Delivery (the event id) and X-Summit-Signature: t=<unix seconds>,v1=<hex>. Verify it before trusting the body:

expected = HMAC_SHA256(secret, t + "." + rawBody)   // hex
accept only if expected == v1 and t is within 5 minutes

Engineer time and billing

The AI help desk is included with your plan. Engineer time is billed hourly under your agreement. The AI asks before handing a ticket to an engineer, unless it's an outage or a security incident (priority p1), which goes straight through. You'll see that question as an AI message; answer it with a message on the ticket.

Errors and limits

{ "error": { "code": "rate_limited", "message": "Too many requests. Retry after 42 seconds." } }

Data and security

All traffic is HTTPS. We store only a hash of your key. Tickets live in Summit Networks' systems in the United States and are used to support you. Don't send passwords, MFA codes or full card numbers in tickets; the AI will never ask for them.