> For the complete documentation index, see [llms.txt](https://www.boxhero.io/docs/llms.txt). Every page is available as Markdown by appending `.md` to its URL; this page is [Markdown](https://www.boxhero.io/docs/developers/api/reference/bundles/list-bundles.md).

# List bundles

> Returns a cursor-paginated list of active bundles.

Bundle stock is not tracked directly; stock belongs to the underlying component items.

`GET https://rest.boxhero-app.com/v1/bundles`

## Authorizations

- `Authorization` (string, required): Bearer authentication header of the form `Bearer <token>`, where `<token>` is your [API token](https://www.boxhero.io/docs/developers/api/authentication).

## Query parameters

- `bundle_ids` (integer | array of integer): Filter the list to specific bundle ids. Pass repeatedly (`?bundle_ids=1&bundle_ids=2`) or as a single value.
- `cursor` (integer, minimum 0, maximum 2147483647): Page cursor. Pass the `cursor` field from the previous response to fetch the next page. Omit on the first call.
- `limit` (integer, minimum 1, maximum 100): Page size. Accepts `1`–`100`; defaults to `100`.

## Responses

**200** A page of bundles.

- `items` (array of SimpleBundle, required): Items in this page. Default ordering is by id ascending; see the resource's list endpoint description for any per-resource overrides.

  - `id` (integer, minimum 0, maximum 2147483647, required): Bundle id.
  - `name` (string, required): Bundle display name.
  - `sku` (string, required): Stock Keeping Unit. Unique within the team.
  - `barcode` (string, required): Primary barcode for the bundle. Empty string when not assigned.
  - `cost` (string, required): Cost per bundle, as a decimal string. Independent from component item costs.
  - `price` (string, required): Selling price per bundle, as a decimal string. Independent from component item prices.
  - `photo_url` (string, nullable, required): URL of the bundle photo. `null` when no photo is set.
  - `memo` (string, required): Free-text memo. Empty string when not set.
  - `count_of_components` (integer, minimum 0, maximum 9007199254740991, required): Number of active component rows in the bundle.
- `count` (integer, minimum 0, maximum 9007199254740991, required): Number of items in this page (`items.length`).
- `limit` (integer, minimum 0, maximum 9007199254740991, required): Page size used to build this response.
- `cursor` (integer, minimum 0, maximum 2147483647, nullable, required): Cursor to pass as `cursor` in the next request. `null` when `has_more` is `false`.
- `has_more` (boolean, required): True when another page is available. The cursor is monotonic — pass it as `cursor` on the next request to advance the page. Direction follows each resource's ordering (default: id ascending).

**401** Missing or invalid API token.

- `id` (string, required): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, required): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  Possible values: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, required): Human-readable summary of the error, in English.
- `correlationID` (string, required): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. Pass an `X-Correlation-Id` request header to thread your trace through to ours.
- `instance` (string, required): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on `/errors/invalid-request` (400) responses. Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, required)
  - `message` (string, required)

**429** Rate limit exceeded. Check `RateLimit`, `Retry-After`, and `X-RateLimit-*` response headers before retrying.

- `id` (string, required): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, required): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  Possible values: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, required): Human-readable summary of the error, in English.
- `correlationID` (string, required): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. Pass an `X-Correlation-Id` request header to thread your trace through to ours.
- `instance` (string, required): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on `/errors/invalid-request` (400) responses. Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, required)
  - `message` (string, required)

Request

**cURL**

```bash
curl --request GET \
  --url 'https://rest.boxhero-app.com/v1/bundles' \
  --header "Authorization: Bearer $BOXHERO_API_TOKEN"
```

**JavaScript**

```javascript
const response = await fetch("https://rest.boxhero-app.com/v1/bundles", {
  method: "GET",
  headers: {
    Authorization: `Bearer ${process.env.BOXHERO_API_TOKEN}`,
  },
});
const data = await response.json();
```

**Python**

```python
import os
import requests

response = requests.get(
    "https://rest.boxhero-app.com/v1/bundles",
    headers={
        "Authorization": "Bearer " + os.environ["BOXHERO_API_TOKEN"],
    },
)
data = response.json()
```

**HTTP**

```http
GET /v1/bundles HTTP/1.1
Host: rest.boxhero-app.com
Authorization: Bearer <token>
```

Response

**200**

```json
{
  "items": [
    {
      "id": 4042,
      "name": "Starter Kit",
      "sku": "BUNDLE-STARTER",
      "barcode": "8801234567890",
      "cost": "12.50",
      "price": "29.99",
      "photo_url": null,
      "memo": "",
      "count_of_components": 2
    }
  ],
  "count": 1,
  "limit": 100,
  "cursor": 4042,
  "has_more": false
}
```

**401**

```json
{
  "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a",
  "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2",
  "type": "/errors/tokens/required",
  "title": "Missing API token. Provide a Bearer token in the Authorization header.",
  "example": "Bearer wqnot0dlysdg5vymubzi4kiv"
}
```

**429**

```json
{
  "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a",
  "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2",
  "type": "/errors/too-many-requests",
  "title": "Too many requests.",
  "instance": "/bundles",
  "retryAfter": 60
}
```
