API reference

Endpoints

Every endpoint of the workspace REST API, grouped by resource, with the capability it requires. Authenticate with Authorization: Bearer <access> from POST /login.

Base URL
https://<your-workspace-api-host>/asset_manager_api

Your workspace’s exact host is provided when API access is enabled (Business plan and above).

Paths are relative to https://<your-workspace-api-host>/asset_manager_api. “Cap” is the capability the signed-in user must hold (admins hold all).

Authentication & sessions

Sign in with a user’s email and password to receive a short-lived access token and a rotating refresh token, bound to a device session you can revoke.

POST/loginpublic
Exchange email + password for access and refresh tokens.
Params email, password, device_uuid?, label?, platform?, app_version?
POST/auth/refreshrefresh token
Rotate: returns a new access token and a new refresh token (the old one stops working).
Params refresh, device_uuid
GET/mesigned in
The current user, their capabilities and device.
GET/tenant_configsigned in
Workspace configuration (company, currency and similar settings).
GET/devicessigned in
The caller’s device sessions.
POST/devices/{uuid}/revokesigned in (own) · admin
Revoke a device session. Admins may pass staff_id to revoke another user’s device.

Assets

The asset register. Finance fields are stripped from writes unless the caller holds finance; status changes go through their own endpoint.

GET/assetsview
List assets.
Params q, category_id, property_id, location_id, status_id, custodian_id, page, per_page (≤200)
GET/assets/lookupview
Resolve a scanned QR/barcode value or RFID EPC to an asset (includes check-out availability).
Params tag
GET/assets/{id}view
One asset, with custom fields and availability.
POST/assetscreate
Create an asset. Accepts custom_fields as {field_key: value}.
PUT/assets/{id}edit
Update an asset.
DELETE/assets/{id}delete
Delete an asset (refused if it has disposal or depreciation records).
POST/assets/{id}/imageedit
Upload the main image.
GET/assets/{id}/historyview
Change history for one asset.
GET/statusesview
Asset statuses (in use, in store, in repair, in transit, disposed, lost, written off).
POST/assets/{id}/statusedit
Change status.
Params status_id, note
POST/assets/{id}/disposefinance
Dispose: records method, proceeds and gain/loss, sets a terminal status and freezes NBV. Blocked while checked out.

Movements & check-outs

Record where assets go and who has them. A movement updates the asset’s location/custodian and appends to its history.

GET/movementsview
Movement feed across assets.
POST/movementsedit
Record a movement.
Params asset_id, to_location_id?, to_custodian_id?, reason?, ref?, note?
GET/assets/{id}/movementsview
Movements for one asset.
GET/checkoutsedit
Check-outs (overdue rows are flagged).
Params asset_id, status, overdue, issued_to_id
POST/checkoutsedit
Check an asset out.
Params asset_id, issued_to_type, issued_to_id | issued_to_name, due_at, condition_out, note
POST/checkouts/{id}/returnedit
Return a check-out.
Params condition_in, note, returned_at?
POST/checkinsedit
Return by check-out id.
Params checkout_id, condition_in, note
GET/assets/{id}/checkoutsedit
Check-out history for one asset.

Locations & organisation

Generic CRUD for the location hierarchy and organisation records: properties, buildings, floors, locations, categories, custodians and departments.

GET/{collection}view
List. collection = properties | buildings | floors | locations | categories | custodians | departments.
POST/{collection}manage
Create a record.
PUT/{collection}/{id}manage
Update a record.
DELETE/{collection}/{id}delete
Delete a record.
GET/locations/treeview
Nested property → building → floor → location tree.
GET/custom-fieldsmanage
Custom field definitions.
POST/custom-fieldsmanage
Define a field (text, textarea, number, date, select, multiselect, checkbox, currency).
PUT/custom-fields/{id}manage
Update a definition.
DELETE/custom-fields/{id}manage
Delete a definition and its values.

Tags, tag stock & NFC

Assign QR, barcode, NFC and UHF RFID tags. Duplicate active codes/EPCs are rejected; RFID EPCs are checked against tag stock when provisioning is in use.

GET/assets/{id}/tagsview
Tags on an asset.
POST/tagsedit
Assign a tag.
Params asset_id, tag_type (qr|barcode|rfid_uhf|nfc), code | epc, tid?
DELETE/tags/{id}delete
Remove a tag.
POST/tags/printview
Label payloads for printing.
Params asset_ids[]
GET/tag-ordersdevices
Tag orders.
POST/tag-ordersdevices
Create an order (type, quantity, EPC range, supplier, cost).
PUT/tag-orders/{id}devices
Update an order.
POST/tag-orders/{id}/receivedevices
Receive into stock (idempotent).
GET/tag-stockdevices
Tag stock.
Params order_id, status, epc, code
GET/nfc-linksdevices
NFC tap links.
POST/nfc-linksdevices
Create a link to an allow-listed https destination.
PUT/nfc-links/{id}devices
Update a link.
DELETE/nfc-links/{id}devices
Delete a link.
GET/r/{token}public
Public tap resolver: 302 to the stored destination only (rate-limited).

Stock-take

Scoped count sessions. Scans are append-only; reconcile writes found / missing / misplaced / unregistered / duplicate variances.

GET/stocktake/sessionsview
List sessions.
POST/stocktake/sessionsaudit
Create a session.
Params name, scope_type (all|property|building|floor|location|category|department), scope_id?
GET/stocktake/sessions/{id}view
One session with counts.
POST/stocktake/sessions/{id}/openaudit
Open for counting.
POST/stocktake/sessions/{id}/scansaudit
Bulk-append scans.
Params scans: [{code | epc, location_id, method (qr|barcode|rfid), device_id, scanned_at}]
GET/stocktake/sessions/{id}/scansview
Scans in a session.
POST/stocktake/sessions/{id}/reconcileaudit
Compare expected vs scanned and write variances.
GET/stocktake/sessions/{id}/variancesview
Variances.
PUT/stocktake/variances/{id}audit
Resolve a variance.
Params resolution (confirmed_moved|written_off|ignored), note
POST/stocktake/sessions/{id}/closeaudit
Close the session.

Maintenance & contracts

Work orders, PM schedules, calibration, attachments and warranty/service/insurance contracts. “Due” lists are pull queries — nothing is auto-generated or pushed.

GET/work-ordersview
List work orders.
Params status, type, asset_id, assigned_to, priority, pm_schedule_id, q
GET/work-orders/{id}view
One work order.
POST/work-ordersedit
Create (auto code, e.g. WO-00001).
PUT/work-orders/{id}edit
Update.
POST/work-orders/{id}/statusedit
Change status; completing a PM-linked order rolls its schedule.
GET/assets/{id}/work-ordersview
Work orders for an asset.
GET/pm-schedulesmanage
PM schedules (GET/POST/PUT with manage; DELETE with delete).
POST/pm-schedules/{id}/generateedit
Manually generate one work order from a schedule.
GET/maintenance/dueview
Schedules due, overdue or in lead time.
Params days
GET/calibrations/dueview
Calibrations due.
Params days
GET/assets/{id}/attachmentsview
Documents and photos on an asset.
POST/assets/{id}/attachmentsedit
Upload (multipart: file, doc_type, note; ≤10 MB, type-checked).
DELETE/attachments/{id}edit
Delete an attachment.
GET/contractsview
Contracts.
Params asset_id, type, status, expiring_days, q
GET/contracts/expiringview
Active contracts ending within N days.
Params days
POST/contractsedit
Create (warranty, service, insurance, lease, amc).

Depreciation

Monthly runs per book. Compute a draft (no asset changes), then post. Posting a tax-book run never changes register NBV.

GET/depreciation/runsview
List runs.
Params book (book|tax)
POST/depreciation/runsfinance
Compute a draft run.
Params year, month, book?
GET/depreciation/runs/{id}view
Run detail with lines.
POST/depreciation/runs/{id}/postfinance
Post the run.
POST/depreciation/runs/{id}/discardfinance
Discard a draft.
GET/assets/{id}/depreciationview
An asset’s schedule.
Params book
GET/assets/{id}/depr-profilesfinance
Book/tax depreciation profiles.
POST/assets/{id}/depr-profilesfinance
Upsert a profile (straight_line, reducing_balance, double_declining, sum_of_years, units, macrs, capital_allowance, none).

Reports & exports

JSON reports and CSV exports. CSV cells beginning with = + - @ are neutralised.

GET/reports/registerview
Register report.
GET/reports/by-locationview
Counts and values by location.
GET/reports/by-custodianview
By custodian.
GET/reports/by-categoryview
By category.
GET/reports/depreciationview
Depreciation report.
GET/reports/variance/{sessionId}view
Variance report for a stock-take.
GET/export/register.csvview
Asset register as CSV.
GET/export/variance.csvview
Stock-take variances as CSV.
Params session_id

Readers, zones & alerts

Readers are a separate principal from users. Creating a reader (or rotating its secret) returns the secret once. Alerts are evaluated server-side from authenticated reader events.

GET/readersdevices
List readers.
POST/readersdevices
Create a reader — returns its secret once.
Params name, kind (fixed_portal|handheld_sled|phone), zone_id?, location_id?
PUT/readers/{id}devices
Update a reader.
POST/readers/{id}/rotate-secretdevices
Issue a new secret (shown once).
POST/readers/{id}/revokedevices
Revoke a reader.
GET/zonesdevices
List zones (POST to create; PUT/DELETE /zones/{id}).
PUT/zones/{id}/locationsdevices
Set the locations in a zone.
Params location_ids[]
GET/alert-rulesalerts
List rules (webhook secrets are never returned).
POST/alert-rulesalerts
Create a rule — webhook rules return webhook_secret once.
Params name, scope_type, scope_id?, condition, channel (inapp|email|webhook), channel_target
GET/alertsview
Alerts inbox.
POST/alerts/{id}/ackalerts
Acknowledge.
POST/alerts/{id}/resolvealerts
Resolve.
POST/ingest/eventsreader (HMAC)
Reader event ingest — signed by the reader, not a user token.

Need access or an endpoint we don’t have?

Tell us what you’re integrating. We enable API access per workspace and prioritise endpoints customers ask for.

No card required · Live in a day · Simple USD pricing