Get a bundle by SKU
Looks up a bundle by SKU (case-sensitive) and returns the same payload as GET /bundles/{bundle_id}.
URL-encode special characters in the SKU.
https://rest.boxhero-app.com/v1/bundles/by-sku/{sku}Authorizations
Section titled “Authorizations”Bearer authentication header of the form Bearer <token>, where <token> is your API token.
Path parameters
Section titled “Path parameters”Bundle SKU (case-sensitive). URL-encode special characters such as #, %, /, or spaces.
Responses
Section titled “Responses”200The requested bundle.
A bundle with its component items. Bundles have no stock of their own; inventory is tracked at the component-item level.
Show properties
Bundle id.
Bundle display name.
Stock Keeping Unit. Unique within the team.
Primary barcode for the bundle. Empty string when not assigned.
Cost per bundle, as a decimal string. Independent from component item costs.
Selling price per bundle, as a decimal string. Independent from component item prices.
URL of the bundle photo. null when no photo is set.
Free-text memo. Empty string when not set.
Component list. Bundles cannot contain other bundles.
Show properties
Reference to an item or bundle embedded in order, return, transaction, and bundle component responses.
Show properties
Item or bundle id.
Display name.
SKU. Empty string when unset.
Barcode. Empty string when unset.
Whether the underlying item or bundle is deleted.
Quantity of this item required per bundle.
401Missing or invalid API token.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Show properties
404No bundle with the given SKU was found in this team.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Show properties
429Rate limit exceeded. Check RateLimit, Retry-After, and X-RateLimit-* response headers before retrying.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Show properties
Request
curl --request GET \ --url 'https://rest.boxhero-app.com/v1/bundles/by-sku/{sku}' \ --header "Authorization: Bearer $BOXHERO_API_TOKEN"const response = await fetch("https://rest.boxhero-app.com/v1/bundles/by-sku/{sku}", { method: "GET", headers: { Authorization: `Bearer ${process.env.BOXHERO_API_TOKEN}`, },});const data = await response.json();import osimport requests
response = requests.get( "https://rest.boxhero-app.com/v1/bundles/by-sku/{sku}", headers={ "Authorization": "Bearer " + os.environ["BOXHERO_API_TOKEN"], },)data = response.json()GET /v1/bundles/by-sku/{sku} HTTP/1.1Host: rest.boxhero-app.comAuthorization: Bearer <token>Response
{ "item": { "id": 4042, "name": "Starter Kit", "sku": "BUNDLE-STARTER", "barcode": "8801234567890", "cost": "12.50", "price": "29.99", "photo_url": null, "memo": "", "count_of_components": 2, "components": [ { "item": { "id": 14290445, "name": "Finish Setting Powder", "sku": "SKU-12345678", "barcode": "2097678335587", "deleted": false }, "quantity": 1 }, { "item": { "id": 14290446, "name": "Hydrating Face Toner", "sku": "SKU-12345679", "barcode": "2097678335588", "deleted": false }, "quantity": 2 } ] }}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/tokens/required", "title": "Missing API token. Provide a Bearer token in the Authorization header.", "example": "Bearer wqnot0dlysdg5vymubzi4kiv"}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/not-found", "title": "No bundle with the given SKU was found in this team.", "instance": "/bundles/by-sku/SKU-123"}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/too-many-requests", "title": "Too many requests.", "instance": "/bundles/by-sku/SKU-123", "retryAfter": 60}