REST API
Everything the UI does goes through the JSON REST API under https://sigmaplm.com/api.
Browse the full reference
The complete OpenAPI 3.1 specification is rendered at
/docs/api/ (Redoc), and the raw spec is at
/docs/openapi.yaml.
Authentication
Log in to get a short-lived access token (15 min) and a refresh token (30 days):
curl -s https://sigmaplm.com/api/auth/login \
-H 'Content-Type: application/json' \
-d '{"email": "you@company.com", "password": "..."}'
Send the access token on every call:
curl -s https://sigmaplm.com/api/items?search=bracket \
-H "Authorization: Bearer $ACCESS_TOKEN"
Rotate with POST /api/auth/refresh — each refresh token is single-use and returns a
fresh pair.
Conventions
- List endpoints paginate with
page/limitand usually acceptsearch. - Errors are
{ "error": "...", "message": "..." }with meaningful HTTP status codes (401unauthenticated,403forbidden,402plan limit,409conflict). - All data is tenant-scoped by the token — there is no cross-tenant access.
- Credential endpoints are rate-limited per IP; expect
429under brute force.