Skip to content

List items

Returns a cursor-paginated list of items in the team.

Each item carries a quantities per-location breakdown; pass location_ids to scope that breakdown to specific locations.

GEThttps://rest.boxhero-app.com/v1/items
Authorizationstringrequired

Bearer authentication header of the form Bearer <token>, where <token> is your API token.

item_idsinteger | array of integer

Filter the list to specific item ids. Pass repeatedly (?item_ids=1&item_ids=2) or as a single value.

location_idsinteger | array of integer

Scope the quantities breakdown to specific locations. When present, each item’s quantities array carries one entry per requested location. When omitted, the response still includes quantities but only for active locations where the item has nonzero stock.

cursorintegerminimum 0, maximum 2147483647

Page cursor. Pass the cursor field from the previous response to fetch the next page. Omit on the first call.

limitintegerminimum 1, maximum 100

Page size. Accepts 1–100; defaults to 100.

200A page of items.
itemsarray of Itemrequired

Items in this page. Default ordering is by id ascending; see the resource’s list endpoint description for any per-resource overrides.

Show properties
idintegerminimum 0, maximum 2147483647required

Item id.

namestringrequired

Item display name.

skustringrequired

Stock Keeping Unit. Unique within the team when set. Empty string when not assigned.

barcodestringrequired

Primary barcode for the item. Empty string when not assigned.

photo_urlstringnullablerequired

URL of the item’s photo. null when no photo is set.

attrsarray of ItemAttrrequired

Custom attribute values attached to the item. Manage the underlying attribute specs via /item-attrs.

Show properties
idintegerminimum 0, maximum 2147483647required

Attribute spec id (see GET /item-attrs).

typestringrequired

Value type of this attribute (text, date, number, or barcode). File-type attributes are app-only and are never returned here.

Possible valuestextdatenumberbarcode

namestringrequired

Attribute display name.

valuestring | numberrequired

Attribute value. text/date/barcode are returned as strings (date as YYYY-MM-DD); number is returned as a number.

coststringrequired

Cost per unit, as a decimal string (range ±999,999,999.999, up to 3 decimal places). Defaults to “0” when not assigned.

pricestringrequired

Selling price per unit, as a decimal string (range ±999,999,999.999, up to 3 decimal places). Defaults to “0” when not assigned.

quantitynumberrequired

Total on-hand quantity for this item, summed across all locations.

quantitiesarray of objectrequired

Per-location stock breakdown. Always present. With location_ids set, one entry per requested location. Without location_ids, one entry per active location where this item has nonzero stock (empty array when the item is out of stock everywhere).

Show properties
location_idintegerminimum 0, maximum 2147483647required

Location id where this stock breakdown applies.

quantitynumberrequired

On-hand quantity of this item at the location.

countintegerminimum 0, maximum 9007199254740991required

Number of items in this page (items.length).

limitintegerminimum 0, maximum 9007199254740991required

Page size used to build this response.

cursorintegerminimum 0, maximum 2147483647, nullablerequired

Cursor to pass as cursor in the next request. null when has_more is false.

has_morebooleanrequired

True when another page is available. The cursor is monotonic — pass it as cursor on the next request to advance the page. Direction follows each resource’s ordering (default: id ascending).

400Team is not in LOCATION mode.
idstringrequired

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringrequired

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringrequired

Human-readable summary of the error, in English.

correlationIDstringrequired

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringrequired

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Show properties
patharray of string | numberrequired
messagestringrequired
401Missing or invalid API token.
idstringrequired

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringrequired

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringrequired

Human-readable summary of the error, in English.

correlationIDstringrequired

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringrequired

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Show properties
patharray of string | numberrequired
messagestringrequired
429Rate limit exceeded. Check RateLimit, Retry-After, and X-RateLimit-* response headers before retrying.
idstringrequired

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringrequired

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Possible values/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringrequired

Human-readable summary of the error, in English.

correlationIDstringrequired

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringrequired

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Show properties
patharray of string | numberrequired
messagestringrequired

Request

Terminal window
curl --request GET \
--url 'https://rest.boxhero-app.com/v1/items' \
--header "Authorization: Bearer $BOXHERO_API_TOKEN"

Response

{
"items": [
{
"id": 14290445,
"name": "Finish Setting Powder",
"sku": "SKU-12345678",
"barcode": "2097678335587",
"photo_url": "https://your.image-server.com/item_image.png",
"attrs": [
{
"id": 485697,
"type": "text",
"name": "Brand",
"value": "Acme Beauty"
},
{
"id": 413101,
"type": "date",
"name": "Expiration Date",
"value": "2026-12-31"
},
{
"id": 485086,
"type": "number",
"name": "Minimum Stock",
"value": 20
}
],
"cost": "8.50",
"price": "19.99",
"quantity": 152,
"quantities": [
{
"location_id": 47041,
"quantity": 120
},
{
"location_id": 47043,
"quantity": 32
}
]
},
{
"id": 14290446,
"name": "Hydrating Face Toner",
"sku": "SKU-12345679",
"barcode": "2097678335588",
"photo_url": null,
"attrs": [
{
"id": 485697,
"type": "text",
"name": "Brand",
"value": "Acme Beauty"
},
{
"id": 485086,
"type": "number",
"name": "Minimum Stock",
"value": 15
}
],
"cost": "5.25",
"price": "12.50",
"quantity": 318,
"quantities": [
{
"location_id": 47041,
"quantity": 300
},
{
"location_id": 47042,
"quantity": 18
}
]
}
],
"count": 2,
"limit": 100,
"cursor": 14290446,
"has_more": false
}