Skip to content

Tracking requests

Besides v1/integration/* and v1/dashboard/*, FlowDesk has a third surface: v1/external/*. This surface requires no authentication and returns no personal data (PII). It sits entirely outside the dashboard JWT / API token split described on the Authentication page, because neither is needed.

You are the one who opens the request (your own backend, with an API token), but the person following its status is usually the end user: your customer should be able to see their request without any FlowDesk credentials of their own, using only the link they hold. v1/external/ticket-tracking does exactly that.

Terminal window
curl -s https://api.example.com/v1/external/ticket-tracking/K7xQm9Zp...eF5A
{
"success": true,
"data": {
"ticketId": 501,
"isCompleted": false,
"createdAt": "2026-08-13T09:12:00Z",
"completedAt": null
}
}

The path parameter is the same trackingKey the creating requests endpoints return. No Authorization header is needed: the endpoint is deliberately anonymous, designed for an end user clicking from their browser rather than for a mail vendor.

The response is deliberately limited to four fields: ticketId, isCompleted, createdAt, completedAt. The request’s subject, description, priority, and the requester’s name/e-mail/phone are none of them present in this response.

The reason is design, not access control: this endpoint asks for no authentication, so whoever calls it (anyone who knows the trackingKey) gets the same response. Returning a request’s subject, or the requester’s contact details, from an unauthenticated endpoint would mean that anyone who obtained — or guessed — a trackingKey could read someone else’s personal data. Keeping the response to “does the request exist, is it complete, when was it opened and closed” removes that risk structurally: there is no PII to return, so there is no PII to leak.

If the end user needs to see the content of the request (“what is your answer”), that has to come through an authenticated channel (the dashboard, e-mail). This endpoint is a status indicator only.

If you sent requesterEmailAddress when opening the request with v1/integration/tickets, FlowDesk sends the requester a welcome e-mail containing this tracking link. If you did not send requesterEmailAddress (or the e-mail flow is disabled), passing the trackingKey on to the end user through your own channel — your own notification e-mail, your SMS, your own account panel — is your responsibility. FlowDesk does not do it on your behalf.

404: the request does not exist, or the key is wrong

Section titled “404: the request does not exist, or the key is wrong”

An unknown or mistyped trackingKey returns 404. Unlike the by-tracking-key endpoint in creating requests, this does not mean “not created yet, poll again”: async request creation completes quickly in the background anyway, and the end user usually opens the request a little later by clicking the link in the e-mail. If you keep getting 404, make sure the trackingKey is being stored and passed on correctly.