Authentication
Authenticate BoxHero API requests with a Bearer token and send them to the versioned base URL.
API tokens
Section titled “API tokens”Every request must carry an API token as a Bearer token in the Authorization header:
Authorization: Bearer <api-token>Issue tokens in the BoxHero app under Settings > Integrations. Each token is bound to a single team: every request reads and writes that team’s data only. To work with several teams, issue a token in each of them.
Anonymous access is not supported. When the token is missing or invalid, every endpoint returns 401 with an error envelope.
Base URL and versioning
Section titled “Base URL and versioning”All requests go to:
https://rest.boxhero-app.comEvery endpoint lives under the /v1 prefix — for example, GET /v1/items.
Team mode
Section titled “Team mode”Most endpoints are available only to teams that manage stock by location. For other teams they return 400 with the error type /errors/invalid-team-mode. Team, member, partner, and attribute endpoints work for every team — call Get the linked team to see which mode your team uses.