Skip to content

Authentication

Authenticate BoxHero API requests with a Bearer token and send them to the versioned base URL.

Every request must carry an API token as a Bearer token in the Authorization header:

Authorization: Bearer <api-token>

Issue tokens in the BoxHero app under Settings > Integrations. Each token is bound to a single team: every request reads and writes that team’s data only. To work with several teams, issue a token in each of them.

Anonymous access is not supported. When the token is missing or invalid, every endpoint returns 401 with an error envelope.

All requests go to:

https://rest.boxhero-app.com

Every endpoint lives under the /v1 prefix — for example, GET /v1/items.

Most endpoints are available only to teams that manage stock by location. For other teams they return 400 with the error type /errors/invalid-team-mode. Team, member, partner, and attribute endpoints work for every team — call Get the linked team to see which mode your team uses.