Skip to content

Get a bundle by SKU

Looks up a bundle by SKU (case-sensitive) and returns the same payload as GET /bundles/{bundle_id}.

URL-encode special characters in the SKU.

GEThttps://rest.boxhero-app.com/v1/bundles/by-sku/{sku}
Authorizationstringrequired

Bearer authentication header of the form Bearer <token>, where <token> is your API token.

skustringmin length 1, max length 255required

Bundle SKU (case-sensitive). URL-encode special characters such as #, %, /, or spaces.

200The requested bundle.
itemBundlerequired

A bundle with its component items. Bundles have no stock of their own; inventory is tracked at the component-item level.

Show properties
idintegerminimum 0, maximum 2147483647required

Bundle id.

namestringrequired

Bundle display name.

skustringrequired

Stock Keeping Unit. Unique within the team.

barcodestringrequired

Primary barcode for the bundle. Empty string when not assigned.

coststringrequired

Cost per bundle, as a decimal string. Independent from component item costs.

pricestringrequired

Selling price per bundle, as a decimal string. Independent from component item prices.

photo_urlstringnullablerequired

URL of the bundle photo. null when no photo is set.

memostringrequired

Free-text memo. Empty string when not set.

componentsarray of BundleComponentrequired

Component list. Bundles cannot contain other bundles.

Show properties
itemExtendedItemEntityrequired

Reference to an item or bundle embedded in order, return, transaction, and bundle component responses.

Show properties
idintegerminimum 0, maximum 2147483647required

Item or bundle id.

namestringrequired

Display name.

skustringrequired

SKU. Empty string when unset.

barcodestringrequired

Barcode. Empty string when unset.

deletedbooleanrequired

Whether the underlying item or bundle is deleted.

quantitynumberrequired

Quantity of this item required per bundle.

401Missing or invalid API token.
idstringrequired

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringrequired

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringrequired

Human-readable summary of the error, in English.

correlationIDstringrequired

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringrequired

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Show properties
patharray of string | numberrequired
messagestringrequired
404No bundle with the given SKU was found in this team.
idstringrequired

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringrequired

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringrequired

Human-readable summary of the error, in English.

correlationIDstringrequired

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringrequired

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Show properties
patharray of string | numberrequired
messagestringrequired
429Rate limit exceeded. Check RateLimit, Retry-After, and X-RateLimit-* response headers before retrying.
idstringrequired

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringrequired

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringrequired

Human-readable summary of the error, in English.

correlationIDstringrequired

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringrequired

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Show properties
patharray of string | numberrequired
messagestringrequired

Request

Terminal window
curl --request GET \
--url 'https://rest.boxhero-app.com/v1/bundles/by-sku/{sku}' \
--header "Authorization: Bearer $BOXHERO_API_TOKEN"

Response

{
"item": {
"id": 4042,
"name": "Starter Kit",
"sku": "BUNDLE-STARTER",
"barcode": "8801234567890",
"cost": "12.50",
"price": "29.99",
"photo_url": null,
"memo": "",
"count_of_components": 2,
"components": [
{
"item": {
"id": 14290445,
"name": "Finish Setting Powder",
"sku": "SKU-12345678",
"barcode": "2097678335587",
"deleted": false
},
"quantity": 1
},
{
"item": {
"id": 14290446,
"name": "Hydrating Face Toner",
"sku": "SKU-12345679",
"barcode": "2097678335588",
"deleted": false
},
"quantity": 2
}
]
}
}