Authentication
How to authenticate with the Signals API using bearer tokens.
Authentication
The Signals API uses Bearer tokens issued via Laravel Sanctum. Generate tokens from the admin panel at Admin > Settings > API or programmatically via the API.
Creating a Token
Navigate to Admin > Settings > API in the web interface. Click Create Token, name your token, select the abilities it should have, and click Generate. The token value is shown once — copy it immediately.
Using a Token
Include the token in the Authorization header of every API request:
Authorization: Bearer {your-token}
All requests must also include Accept: application/json.
Token Abilities
Tokens are scoped with abilities in resource:action form (e.g. accounts:read,
invoices:write). A request whose token lacks the required ability is rejected
with 403; a missing or invalid token returns 401. The complete catalogue of
registered abilities is below — grant a token only the abilities it needs.
| Ability | Description |
|---|---|
accounts:read | Read accounts |
accounts:write | Write accounts |
action-log:read | Read action logs |
activities:read | Read activities |
activities:write | Write activities |
addresses:read | Read the Global Address List |
addresses:write | Create, update, and delete addresses |
api-log:read | Read API request logs |
api-usage:read | Read API usage aggregates |
asset-costs:read | Read structured maintenance cost history and TCO rollups |
asset-costs:write | Record, update, and delete asset cost entries |
asset-retirements:read | Read asset retirement records and retired asset state |
asset-retirements:write | Retire, void, and reinstate barcoded assets |
assets:read | Read assets & transactions |
assets:write | Write assets & transactions |
availability:read | Read catalogue item availability |
catalogue-items:read | Read catalogue items & catalogue item groups |
catalogue-items:write | Write catalogue items & catalogue item groups |
channel-providers:read | Read notification channel provider configuration |
channel-providers:write | Create, update, delete, and test channel providers |
communication-templates:read | Read communication templates and version history |
communication-templates:write | Create, update, delete, and restore communication templates |
communications:approve | Approve, discard, and send drafted customer communications |
communications:draft | Compose customer communication drafts for human approval |
communications:read | Read communication log entries |
conversations:read | Read conversations and comments |
conversations:write | Create, update, delete conversations and comments |
countries:read | Read countries |
credit-notes:read | Read credit notes |
credit-notes:write | Issue credit notes against invoices |
currencies:read | Read currencies |
custom-fields:read | Read custom fields |
custom-fields:write | Write custom fields |
documents:read | Read generated documents and templates |
documents:write | Generate, finalise, and share documents |
email-layouts:read | Read email layouts and version history |
email-layouts:write | Create, update, delete, default, and restore email layouts |
email-templates:read | Read email templates and version history |
email-templates:write | Update, reset, and restore email templates |
equipment-test-results:read | Read equipment test execution history |
equipment-test-results:write | Perform and delete equipment test results |
equipment_tests:read | Read equipment test definitions |
equipment_tests:write | Create, update, and delete equipment test definitions |
events:read | Read the domain event catalogue |
evidence:read | Read the evidence ledger: proposed facts, their scores, and their provenance |
exchange_rates:read | Read exchange rates |
exchange_rates:write | Write exchange rates |
exports:read | Read export job status and download completed files |
exports:write | Create and cancel data exports |
facilities:read | Read scheduling facilities |
facilities:write | Write scheduling facilities |
flightcases:read | Read flightcases & contents |
flightcases:write | Create, update, pack & unpack flightcases |
imports:read | Read import batches, plans, mappings, and profiles |
imports:write | Upload imports, execute plans, set mappings, and manage profiles |
invoices:read | Read invoices and payments |
invoices:write | Create and manage invoices |
kits:read | Read kit compositions |
kits:write | Manage kit compositions |
live-filters:read | Read saved list views |
live-filters:write | Create, update, clone, and delete saved list views |
notification-preferences:read | Read user and account notification preferences |
notification-preferences:write | Update user and account notification preferences |
notification-settings:read | Read tenant notification type settings |
notification-settings:write | Update tenant notification type settings |
payments:read | Read invoice payments |
payments:write | Record and manage invoice payments |
plugins:read | Read installed plugins and their status |
plugins:write | Enable, disable, and manage plugins |
pricing:read | Read discount and price categories |
pricing:write | Write discount and price categories |
projects:read | Read rental project records |
projects:write | Create, update, and delete rental projects; attach and detach rentals |
purchase_orders:read | Read purchase orders and lines |
purchase_orders:write | Create and manage purchase orders |
rates:read | Read rate specifications & catalogue item rates |
rates:write | Write rate specifications & catalogue item rates |
rentals:read | Read rentals |
rentals:write | Write rentals |
repairs:read | Read repair records |
repairs:write | Raise, update, and release repairs |
reports:read | Read saved reports and run them |
reports:write | Create, update, and delete saved reports |
resource-assignments:read | Read scheduling resource assignments |
resource-assignments:write | Write scheduling resource assignments |
roles:read | Read roles |
roles:write | Write roles |
scanning:read | Read scannable identifiers and scan sessions |
scanning:write | Manage identifiers, sessions, and submit scans |
scheduling-conflicts:read | Read scheduling conflict records |
scheduling-conflicts:write | Resolve scheduling conflict records |
schema:read | Read schema / field metadata |
search:read | Search across every registered searchable entity type |
services:read | Read labour catalogue services |
services:write | Write labour catalogue services |
settings:read | Read all settings groups |
settings:read:action-log | Read the action-log settings group only |
settings:read:ai | Read the ai settings group only |
settings:read:api | Read the api settings group only |
settings:read:api_cli | Read the api_cli settings group only |
settings:read:availability | Read the availability settings group only |
settings:read:branding | Read the branding settings group only |
settings:read:cache | Read the cache settings group only |
settings:read:company | Read the company settings group only |
settings:read:email | Read the email settings group only |
settings:read:finance | Read the finance settings group only |
settings:read:imports | Read the imports settings group only |
settings:read:integrations | Read the integrations settings group only |
settings:read:invoices | Read the invoices settings group only |
settings:read:localisation | Read the localisation settings group only |
settings:read:maintenance | Read the maintenance settings group only |
settings:read:mcp | Read the mcp settings group only |
settings:read:nightwatch | Read the nightwatch settings group only |
settings:read:notifications | Read the notifications settings group only |
settings:read:payments | Read the payments settings group only |
settings:read:preferences | Read the preferences settings group only |
settings:read:pricing | Read the pricing settings group only |
settings:read:rentals | Read the rentals settings group only |
settings:read:scheduling | Read the scheduling settings group only |
settings:read:search | Read the search settings group only |
settings:read:security | Read the security settings group only |
settings:read:sso | Read the sso settings group only |
settings:read:stock_checks | Read the stock_checks settings group only |
settings:read:tax | Read the tax settings group only |
settings:read:webhooks | Read the webhooks settings group only |
settings:read:workflows | Read the workflows settings group only |
settings:write | Write settings |
shortages:read | Read shortages & resolutions |
shortages:write | Write shortage resolutions |
static-data:read | Read static data (lists) |
static-data:write | Write static data (lists) |
stock_checks:read | Read stock check records |
stock_checks:write | Create, count, submit, and revert stock checks |
system:read | Read system info |
tax-types:read | Read tax types |
tax-types:write | Write tax types |
usage-readings:read | Read cumulative usage reading history |
usage-readings:write | Record cumulative usage readings |
users:read | Read users |
users:write | Write users |
vehicles:read | Read fleet vehicles |
vehicles:write | Write fleet vehicles |
virtual_stock:read | Read virtual stock intakes |
virtual_stock:write | Create and manage virtual stock intakes |
warehouse_transfers:read | Read warehouse transfer records |
warehouse_transfers:write | Create, dispatch, receive, and cancel warehouse transfers |
warehouses:read | Read warehouse locations |
warehouses:write | Create, update, and delete warehouse locations |
webhooks:manage | Manage webhooks |
Sending communications
communications:read has no communications:write counterpart, and this is
deliberate. The ability covers reading the communication log; outbound sending
is never gated by a communications:write ability. Sends happen as a side
effect of the domain action that produces them — a document send, for example,
is authorised by that document's own ability — so the permission to send is
always the permission to perform the underlying business operation. Whether a
particular action type may send autonomously (and who must sign it off) is the
approval layer's concern, not a token scope.
Rate Limiting
API requests are rate-limited per token (or per client IP when unauthenticated). Default limits, configurable in Admin > Settings > API:
| Context | Limit |
|---|---|
| Authenticated | 60 requests/minute |
| Unauthenticated | 20 requests/minute |
An individual token can be given a bespoke per-minute limit
(rate_limit_per_minute) from the API Tokens admin screen, overriding the
authenticated default. Every response carries rate-limit headers:
X-RateLimit-Limit— maximum requests per windowX-RateLimit-Remaining— requests remainingRetry-After— seconds until the limit resets (sent on429)
Rate limiting counts requests. It is separate from usage metering, where
each endpoint has a price weight (most are 1, meta endpoints are 0) that is
summed into billable weighted units — see Usage & Metering.
Idempotency
Any side-effecting POST accepts an optional Idempotency-Key header; replaying
the same key returns the stored response with Idempotency-Replayed: true.
Operators can enable strict mode (api.require_idempotency_key) to require
the header on every mutating POST /api/v1/... request (428 if missing).
GET/PUT/PATCH/DELETE and unauthenticated endpoints are never affected.
See API Conventions → Idempotency for the full contract.
Response, errors, pagination & filtering
Response envelopes, the Laravel error shape, offset pagination, Ransack-style filtering, sorting, includes, and sparse fieldsets are identical across every v1 endpoint — they are documented once in API Conventions.