Skip to content

Create an item

Creates a new item in the team.

Pass location_id (query) together with quantity (body) to seed initial stock at a single location; otherwise the item starts with zero stock everywhere. When the team has more than one active location and quantity is provided without location_id, the request fails with 402 (location quota).

POSThttps://rest.boxhero-app.com/v1/items
Authorizationstringrequired

Bearer authentication header of the form Bearer <token>, where <token> is your API token.

location_idintegerminimum 0, maximum 2147483647

Location at which to seed initial stock. Required together with the body’s quantity when the team has more than one active location.

namestringmin length 1, max length 255required

Item display name. 1–255 characters.

skustringmin length 1, max length 255

Stock Keeping Unit. Optional, but must be unique across the team when set.

barcodestringmax length 255

Primary barcode for the item. Optional.

photo_urlstringmax length 2048

Public URL of the item’s photo. Optional.

coststring

Cost per unit, as a decimal string. Range ±999,999,999.999 with up to 3 decimal places. Example: "12345.234". The team’s currency is reported on GET /v1/teams/linked.

pricestring

Selling price per unit, as a decimal string. Range ±999,999,999.999 with up to 3 decimal places. Example: "12345.234". The team’s currency is reported on GET /v1/teams/linked.

attrsarray of object

Custom attribute values. Official request format is [{ "id": <attr_id>, "value": <value> }, ...]. The legacy object form { "<attr_id>": <value> } is still accepted for compatibility.

Show properties
idintegerminimum 0, maximum 2147483647required

Attribute spec id.

valuestring | numberrequired

Attribute value (typed per the spec).

quantitynumbernullable

Initial on-hand quantity. Pass together with the location_id query to seed stock at a single location. Omit (or set null) to start with zero stock everywhere. Must be non-zero when provided.

201The created item’s id.
idintegerminimum 0, maximum 2147483647required

Id of the newly created item.

400Request validation failed (e.g. duplicate SKU, invalid attribute value, file-type attribute, or quantity = 0). See the response body for field-level errors.
idstringrequired

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringrequired

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringrequired

Human-readable summary of the error, in English.

correlationIDstringrequired

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringrequired

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Show properties
patharray of string | numberrequired
messagestringrequired
401Missing or invalid API token.
idstringrequired

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringrequired

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringrequired

Human-readable summary of the error, in English.

correlationIDstringrequired

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringrequired

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Show properties
patharray of string | numberrequired
messagestringrequired
402The team’s item quota has been reached, or initial stock was requested at a location the current plan does not cover. Upgrade the plan or delete an existing item / pass a covered location_id to continue.
idstringrequired

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringrequired

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringrequired

Human-readable summary of the error, in English.

correlationIDstringrequired

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringrequired

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Show properties
patharray of string | numberrequired
messagestringrequired
429Rate limit exceeded. Check RateLimit, Retry-After, and X-RateLimit-* response headers before retrying.
idstringrequired

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringrequired

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringrequired

Human-readable summary of the error, in English.

correlationIDstringrequired

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringrequired

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Show properties
patharray of string | numberrequired
messagestringrequired

Request

Terminal window
curl --request POST \
--url 'https://rest.boxhero-app.com/v1/items' \
--header "Authorization: Bearer $BOXHERO_API_TOKEN" \
--header 'Content-Type: application/json' \
--data '{
"name": "Finish Setting Powder",
"sku": "SKU-12345678",
"barcode": "2097678335587",
"photo_url": "https://your.image-server.com/item_image.png",
"cost": "8.50",
"price": "19.99",
"attrs": [
{
"id": 485086,
"value": 20
},
{
"id": 413101,
"value": "2026-12-31"
}
],
"quantity": 32
}'

Response

{
"id": 14290445
}