Skip to content

List bundles

Returns a cursor-paginated list of active bundles.

Bundle stock is not tracked directly; stock belongs to the underlying component items.

GEThttps://rest.boxhero-app.com/v1/bundles
Authorizationstringrequired

Bearer authentication header of the form Bearer <token>, where <token> is your API token.

bundle_idsinteger | array of integer

Filter the list to specific bundle ids. Pass repeatedly (?bundle_ids=1&bundle_ids=2) or as a single value.

cursorintegerminimum 0, maximum 2147483647

Page cursor. Pass the cursor field from the previous response to fetch the next page. Omit on the first call.

limitintegerminimum 1, maximum 100

Page size. Accepts 1–100; defaults to 100.

200A page of bundles.
itemsarray of SimpleBundlerequired

Items in this page. Default ordering is by id ascending; see the resource’s list endpoint description for any per-resource overrides.

Show properties
idintegerminimum 0, maximum 2147483647required

Bundle id.

namestringrequired

Bundle display name.

skustringrequired

Stock Keeping Unit. Unique within the team.

barcodestringrequired

Primary barcode for the bundle. Empty string when not assigned.

coststringrequired

Cost per bundle, as a decimal string. Independent from component item costs.

pricestringrequired

Selling price per bundle, as a decimal string. Independent from component item prices.

photo_urlstringnullablerequired

URL of the bundle photo. null when no photo is set.

memostringrequired

Free-text memo. Empty string when not set.

count_of_componentsintegerminimum 0, maximum 9007199254740991required

Number of active component rows in the bundle.

countintegerminimum 0, maximum 9007199254740991required

Number of items in this page (items.length).

limitintegerminimum 0, maximum 9007199254740991required

Page size used to build this response.

cursorintegerminimum 0, maximum 2147483647, nullablerequired

Cursor to pass as cursor in the next request. null when has_more is false.

has_morebooleanrequired

True when another page is available. The cursor is monotonic — pass it as cursor on the next request to advance the page. Direction follows each resource’s ordering (default: id ascending).

401Missing or invalid API token.
idstringrequired

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringrequired

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringrequired

Human-readable summary of the error, in English.

correlationIDstringrequired

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringrequired

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Show properties
patharray of string | numberrequired
messagestringrequired
429Rate limit exceeded. Check RateLimit, Retry-After, and X-RateLimit-* response headers before retrying.
idstringrequired

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringrequired

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringrequired

Human-readable summary of the error, in English.

correlationIDstringrequired

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringrequired

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Show properties
patharray of string | numberrequired
messagestringrequired

Request

Terminal window
curl --request GET \
--url 'https://rest.boxhero-app.com/v1/bundles' \
--header "Authorization: Bearer $BOXHERO_API_TOKEN"

Response

{
"items": [
{
"id": 4042,
"name": "Starter Kit",
"sku": "BUNDLE-STARTER",
"barcode": "8801234567890",
"cost": "12.50",
"price": "29.99",
"photo_url": null,
"memo": "",
"count_of_components": 2
}
],
"count": 1,
"limit": 100,
"cursor": 4042,
"has_more": false
}