# Installations and addresses

> Each company's Solk installation runs at its own address. The API, MCP, hook, and discovery URLs are all derived from it.

Instead of "workspaces", Solk has **installations**: each customer company gets its own subdomain, its own database, and its own settings. There is no shared API server; you send requests directly to the installation's address.

| What | Address |
|---|---|
| Web app | `https://<company>.solk.app` |
| REST API | `https://<company>.solk.app/api/v1/…` |
| MCP connector | `https://<company>.solk.app/mcp` |
| OAuth discovery | `https://<company>.solk.app/.well-known/oauth-authorization-server` |
| SCIM 2.0 | `https://<company>.solk.app/api/scim/v2` |
| Inbound hooks | `https://<company>.solk.app/in/<app>/<secret>` |
| Version and health | `https://<company>.solk.app/health` |
| Calendar (CalDAV) | `https://<company>.solk.app/radicale/` |

If you don't know the installation address, ask your users: it's the address they open the CRM at in their browser. The [solk.app](https://solk.app) sign-in page redirects to the right installation when you type the company name.

## Version

All installations are updated from the same codebase, but because each one is updated on its own schedule, two installations may briefly run different versions. To find out which version is running:

```bash
curl https://ornek.solk.app/health
```

```json
{
  "ok": true,
  "version": "v22",
  "code": "bff893f1",
  "started": "2026-10-02T09:12:40",
  "restart_needed": false,
  "time": "2026-10-02T14:20:03",
  "schema_missing": {},
  "last_backup": "2026-10-02",
  "last_sync": "2026-10-02T14:10"
}
```

Checking the version before you use a new API field or endpoint keeps you from getting a `404` on an installation that's still on an older version. New fields are **added** to responses; the meaning of existing fields never changes, and they're never removed.

## License and modules

Each installation's license determines which modules are enabled: Customers, Opportunities, Visits, Tasks, Calendar, Fair leads, Reports, Sales forecast, Support tickets, Contracts, Email automation, AI. Endpoints of a disabled module return `403 module`. The enabled modules are listed in the [`GET /api/v1/me`](/rest-api/auth/me) response under `license.modules` and, per user, `user.modules`.

When the license expires, the installation stays open to admins only; API requests from other users get `403 license`.

## Time zone and date format

Installations run on Turkey time (UTC+3). The API returns and expects dates as `YYYY-MM-DD` and date-times as `YYYY-MM-DDTHH:MM:SS` (local time) without a time zone suffix. In inbound hooks, you can send ISO 8601 (with a time zone offset) or a Unix timestamp; it's converted to local time.