Skip to main content

REST API

Everything the UI does goes through the JSON REST API under https://sigmaplm.com/api.

Browse the full reference​

The complete OpenAPI 3.1 specification is rendered at /docs/api/ (Redoc), and the raw spec is at /docs/openapi.yaml.

Authentication​

Log in to get a short-lived access token (15 min) and a refresh token (30 days):

curl -s https://sigmaplm.com/api/auth/login \
-H 'Content-Type: application/json' \
-d '{"email": "you@company.com", "password": "..."}'

Send the access token on every call:

curl -s https://sigmaplm.com/api/items?search=bracket \
-H "Authorization: Bearer $ACCESS_TOKEN"

Rotate with POST /api/auth/refresh — each refresh token is single-use and returns a fresh pair.

Conventions​

  • List endpoints paginate with page / limit and usually accept search.
  • Errors are { "error": "...", "message": "..." } with meaningful HTTP status codes (401 unauthenticated, 403 forbidden, 402 plan limit, 409 conflict).
  • All data is tenant-scoped by the token — there is no cross-tenant access.
  • Credential endpoints are rate-limited per IP; expect 429 under brute force.