The API Report CardAPI Index
Pabau

Pabau API

Clinic and Med Spa Practice Management · pabau.com

Pabau's REST API is open to every customer: keys and webhook subscriptions are created in the in-app Private Apps Developer Hub and the Postman reference and rate limits are public. Auth is an account key in the URL path with no OAuth, and the docs are labelled Legacy.

Last verified: September 2026HealthcareNO MCP
API GRADE
B
VERIFIED SEP 2026

SCORECARD

ExistenceGOODPublic Postman reference at documenter.getpostman.com covers clients, appointments, invoices, EMR and dozens more resources.
AccessGOODAny customer creates a Private App under Setup, Integrations and copies the API key; the API is included in every plan.
CoverageGOODRead and write across clients, leads, appointments, invoices, payments and forms, with webhooks for clients, appointments, leads and sales.
AuthPOORNo OAuth; the account API key rides in the URL path on every request.
Docs & DXPOORReference is branded Pabau Legacy with sections marked work in progress; no sandbox, no SDK, no OpenAPI.
StabilityGOODThe Legacy reference and a newer docs site on a QA subdomain are both live; no deprecation date is announced for the current API.
MCPNONENo official or community MCP server found for this platform.
What you can do
Create an API key in-app without salesSetup > Private Apps
Subscribe to client, appointment, lead and sales eventswebhooks
Read and write clients, appointments and invoicesLegacy REST
Pull report data for BI toolsReports endpoint
What you can't
Authorize with OAuthstatic key only
Test in a sandboxnone documented
Download an OpenAPI specPostman only
Rely on the QA docs base URLapi.pabau.com unresolved
Supergood turns hard-to-integrate enterprise software into clean REST APIs and MCP tools: stable endpoints, normalized JSON, managed auth.

Frequently asked questions

Pabau scores B on Supergood's API Report Card. Pabau's REST API is open to every customer: keys and webhook subscriptions are created in the in-app Private Apps Developer Hub and the Postman reference and rate limits are public. Auth is an account key in the URL path with no OAuth, and the docs are labelled Legacy.

Tried to integrate with Pabau?
SOURCES
Some users report challenges integrating Pabau with certain third-party apps despite its API capabilities. themedicalpractice.com
Getting certain integrations running and completing initial setup can take a while and may need help from support. softwarefinder.com
Forced migration to Pabau 2 brought a never-ending stream of glitches and outages, including two full days without the system in the first week. trustpilot.com
Recurring bugs and glitches in production, no customer service phone number, and UK time-zone handling that broke appointment and staff schedules. capterra.com
Reviewer says logins failed for weeks on Pabau 2, medical reports reached patients half complete, and only four days were given to export data on leaving. ie.trustpilot.com
Add-ons such as SMS credits, Marketing Plus and Care Plus push the real cost well above the headline price. capterra.co.uk