Endpoints
Every endpoint of the workspace REST API, grouped by resource, with the capability it requires. Authenticate with Authorization: Bearer <access> from POST /login.
https://<your-workspace-api-host>/asset_manager_apiYour workspace’s exact host is provided when API access is enabled (Business plan and above).
Paths are relative to https://<your-workspace-api-host>/asset_manager_api. “Cap” is the capability the signed-in user must hold (admins hold all).
Authentication & sessions
Sign in with a user’s email and password to receive a short-lived access token and a rotating refresh token, bound to a device session you can revoke.
/loginpublicemail, password, device_uuid?, label?, platform?, app_version?/auth/refreshrefresh tokenrefresh, device_uuid/mesigned in/tenant_configsigned in/devicessigned in/devices/{uuid}/revokesigned in (own) · adminAssets
The asset register. Finance fields are stripped from writes unless the caller holds finance; status changes go through their own endpoint.
/assetsviewq, category_id, property_id, location_id, status_id, custodian_id, page, per_page (≤200)/assets/lookupviewtag/assets/{id}view/assetscreate/assets/{id}edit/assets/{id}delete/assets/{id}/imageedit/assets/{id}/historyview/statusesview/assets/{id}/statuseditstatus_id, note/assets/{id}/disposefinanceMovements & check-outs
Record where assets go and who has them. A movement updates the asset’s location/custodian and appends to its history.
/movementsview/movementseditasset_id, to_location_id?, to_custodian_id?, reason?, ref?, note?/assets/{id}/movementsview/checkoutseditasset_id, status, overdue, issued_to_id/checkoutseditasset_id, issued_to_type, issued_to_id | issued_to_name, due_at, condition_out, note/checkouts/{id}/returneditcondition_in, note, returned_at?/checkinseditcheckout_id, condition_in, note/assets/{id}/checkoutseditLocations & organisation
Generic CRUD for the location hierarchy and organisation records: properties, buildings, floors, locations, categories, custodians and departments.
/{collection}view/{collection}manage/{collection}/{id}manage/{collection}/{id}delete/locations/treeview/custom-fieldsmanage/custom-fieldsmanage/custom-fields/{id}manage/custom-fields/{id}manageStock-take
Scoped count sessions. Scans are append-only; reconcile writes found / missing / misplaced / unregistered / duplicate variances.
/stocktake/sessionsview/stocktake/sessionsauditname, scope_type (all|property|building|floor|location|category|department), scope_id?/stocktake/sessions/{id}view/stocktake/sessions/{id}/openaudit/stocktake/sessions/{id}/scansauditscans: [{code | epc, location_id, method (qr|barcode|rfid), device_id, scanned_at}]/stocktake/sessions/{id}/scansview/stocktake/sessions/{id}/reconcileaudit/stocktake/sessions/{id}/variancesview/stocktake/variances/{id}auditresolution (confirmed_moved|written_off|ignored), note/stocktake/sessions/{id}/closeauditMaintenance & contracts
Work orders, PM schedules, calibration, attachments and warranty/service/insurance contracts. “Due” lists are pull queries — nothing is auto-generated or pushed.
/work-ordersviewstatus, type, asset_id, assigned_to, priority, pm_schedule_id, q/work-orders/{id}view/work-ordersedit/work-orders/{id}edit/work-orders/{id}/statusedit/assets/{id}/work-ordersview/pm-schedulesmanage/pm-schedules/{id}/generateedit/maintenance/dueviewdays/calibrations/dueviewdays/assets/{id}/attachmentsview/assets/{id}/attachmentsedit/attachments/{id}edit/contractsviewasset_id, type, status, expiring_days, q/contracts/expiringviewdays/contractseditDepreciation
Monthly runs per book. Compute a draft (no asset changes), then post. Posting a tax-book run never changes register NBV.
/depreciation/runsviewbook (book|tax)/depreciation/runsfinanceyear, month, book?/depreciation/runs/{id}view/depreciation/runs/{id}/postfinance/depreciation/runs/{id}/discardfinance/assets/{id}/depreciationviewbook/assets/{id}/depr-profilesfinance/assets/{id}/depr-profilesfinanceReports & exports
JSON reports and CSV exports. CSV cells beginning with = + - @ are neutralised.
/reports/registerview/reports/by-locationview/reports/by-custodianview/reports/by-categoryview/reports/depreciationview/reports/variance/{sessionId}view/export/register.csvview/export/variance.csvviewsession_idReaders, zones & alerts
Readers are a separate principal from users. Creating a reader (or rotating its secret) returns the secret once. Alerts are evaluated server-side from authenticated reader events.
/readersdevices/readersdevicesname, kind (fixed_portal|handheld_sled|phone), zone_id?, location_id?/readers/{id}devices/readers/{id}/rotate-secretdevices/readers/{id}/revokedevices/zonesdevices/zones/{id}/locationsdeviceslocation_ids[]/alert-rulesalerts/alert-rulesalertsname, scope_type, scope_id?, condition, channel (inapp|email|webhook), channel_target/alertsview/alerts/{id}/ackalerts/alerts/{id}/resolvealerts/ingest/eventsreader (HMAC)Need access or an endpoint we don’t have?
Tell us what you’re integrating. We enable API access per workspace and prioritise endpoints customers ask for.
No card required · Live in a day · Simple USD pricing