SIGNALS Documentation
API Reference

Authentication

How to authenticate with the Signals API using bearer tokens.

Authentication

The Signals API uses Bearer tokens issued via Laravel Sanctum. Generate tokens from the admin panel at Admin > Settings > API or programmatically via the API.

Creating a Token

Navigate to Admin > Settings > API in the web interface. Click Create Token, name your token, select the abilities it should have, and click Generate. The token value is shown once — copy it immediately.

Using a Token

Include the token in the Authorization header of every API request:

Authorization: Bearer {your-token}

All requests must also include Accept: application/json.

Token Abilities

Tokens are scoped with abilities in resource:action form (e.g. accounts:read, invoices:write). A request whose token lacks the required ability is rejected with 403; a missing or invalid token returns 401. The complete catalogue of registered abilities is below — grant a token only the abilities it needs.

AbilityDescription
accounts:readRead accounts
accounts:writeWrite accounts
action-log:readRead action logs
activities:readRead activities
activities:writeWrite activities
addresses:readRead the Global Address List
addresses:writeCreate, update, and delete addresses
api-log:readRead API request logs
api-usage:readRead API usage aggregates
asset-costs:readRead structured maintenance cost history and TCO rollups
asset-costs:writeRecord, update, and delete asset cost entries
asset-retirements:readRead asset retirement records and retired asset state
asset-retirements:writeRetire, void, and reinstate barcoded assets
assets:readRead assets & transactions
assets:writeWrite assets & transactions
availability:readRead catalogue item availability
catalogue-items:readRead catalogue items & catalogue item groups
catalogue-items:writeWrite catalogue items & catalogue item groups
channel-providers:readRead notification channel provider configuration
channel-providers:writeCreate, update, delete, and test channel providers
communication-templates:readRead communication templates and version history
communication-templates:writeCreate, update, delete, and restore communication templates
communications:approveApprove, discard, and send drafted customer communications
communications:draftCompose customer communication drafts for human approval
communications:readRead communication log entries
conversations:readRead conversations and comments
conversations:writeCreate, update, delete conversations and comments
countries:readRead countries
credit-notes:readRead credit notes
credit-notes:writeIssue credit notes against invoices
currencies:readRead currencies
custom-fields:readRead custom fields
custom-fields:writeWrite custom fields
documents:readRead generated documents and templates
documents:writeGenerate, finalise, and share documents
email-layouts:readRead email layouts and version history
email-layouts:writeCreate, update, delete, default, and restore email layouts
email-templates:readRead email templates and version history
email-templates:writeUpdate, reset, and restore email templates
equipment-test-results:readRead equipment test execution history
equipment-test-results:writePerform and delete equipment test results
equipment_tests:readRead equipment test definitions
equipment_tests:writeCreate, update, and delete equipment test definitions
events:readRead the domain event catalogue
evidence:readRead the evidence ledger: proposed facts, their scores, and their provenance
exchange_rates:readRead exchange rates
exchange_rates:writeWrite exchange rates
exports:readRead export job status and download completed files
exports:writeCreate and cancel data exports
facilities:readRead scheduling facilities
facilities:writeWrite scheduling facilities
flightcases:readRead flightcases & contents
flightcases:writeCreate, update, pack & unpack flightcases
imports:readRead import batches, plans, mappings, and profiles
imports:writeUpload imports, execute plans, set mappings, and manage profiles
invoices:readRead invoices and payments
invoices:writeCreate and manage invoices
kits:readRead kit compositions
kits:writeManage kit compositions
live-filters:readRead saved list views
live-filters:writeCreate, update, clone, and delete saved list views
notification-preferences:readRead user and account notification preferences
notification-preferences:writeUpdate user and account notification preferences
notification-settings:readRead tenant notification type settings
notification-settings:writeUpdate tenant notification type settings
payments:readRead invoice payments
payments:writeRecord and manage invoice payments
plugins:readRead installed plugins and their status
plugins:writeEnable, disable, and manage plugins
pricing:readRead discount and price categories
pricing:writeWrite discount and price categories
projects:readRead rental project records
projects:writeCreate, update, and delete rental projects; attach and detach rentals
purchase_orders:readRead purchase orders and lines
purchase_orders:writeCreate and manage purchase orders
rates:readRead rate specifications & catalogue item rates
rates:writeWrite rate specifications & catalogue item rates
rentals:readRead rentals
rentals:writeWrite rentals
repairs:readRead repair records
repairs:writeRaise, update, and release repairs
reports:readRead saved reports and run them
reports:writeCreate, update, and delete saved reports
resource-assignments:readRead scheduling resource assignments
resource-assignments:writeWrite scheduling resource assignments
roles:readRead roles
roles:writeWrite roles
scanning:readRead scannable identifiers and scan sessions
scanning:writeManage identifiers, sessions, and submit scans
scheduling-conflicts:readRead scheduling conflict records
scheduling-conflicts:writeResolve scheduling conflict records
schema:readRead schema / field metadata
search:readSearch across every registered searchable entity type
services:readRead labour catalogue services
services:writeWrite labour catalogue services
settings:readRead all settings groups
settings:read:action-logRead the action-log settings group only
settings:read:aiRead the ai settings group only
settings:read:apiRead the api settings group only
settings:read:api_cliRead the api_cli settings group only
settings:read:availabilityRead the availability settings group only
settings:read:brandingRead the branding settings group only
settings:read:cacheRead the cache settings group only
settings:read:companyRead the company settings group only
settings:read:emailRead the email settings group only
settings:read:financeRead the finance settings group only
settings:read:importsRead the imports settings group only
settings:read:integrationsRead the integrations settings group only
settings:read:invoicesRead the invoices settings group only
settings:read:localisationRead the localisation settings group only
settings:read:maintenanceRead the maintenance settings group only
settings:read:mcpRead the mcp settings group only
settings:read:nightwatchRead the nightwatch settings group only
settings:read:notificationsRead the notifications settings group only
settings:read:paymentsRead the payments settings group only
settings:read:preferencesRead the preferences settings group only
settings:read:pricingRead the pricing settings group only
settings:read:rentalsRead the rentals settings group only
settings:read:schedulingRead the scheduling settings group only
settings:read:searchRead the search settings group only
settings:read:securityRead the security settings group only
settings:read:ssoRead the sso settings group only
settings:read:stock_checksRead the stock_checks settings group only
settings:read:taxRead the tax settings group only
settings:read:webhooksRead the webhooks settings group only
settings:read:workflowsRead the workflows settings group only
settings:writeWrite settings
shortages:readRead shortages & resolutions
shortages:writeWrite shortage resolutions
static-data:readRead static data (lists)
static-data:writeWrite static data (lists)
stock_checks:readRead stock check records
stock_checks:writeCreate, count, submit, and revert stock checks
system:readRead system info
tax-types:readRead tax types
tax-types:writeWrite tax types
usage-readings:readRead cumulative usage reading history
usage-readings:writeRecord cumulative usage readings
users:readRead users
users:writeWrite users
vehicles:readRead fleet vehicles
vehicles:writeWrite fleet vehicles
virtual_stock:readRead virtual stock intakes
virtual_stock:writeCreate and manage virtual stock intakes
warehouse_transfers:readRead warehouse transfer records
warehouse_transfers:writeCreate, dispatch, receive, and cancel warehouse transfers
warehouses:readRead warehouse locations
warehouses:writeCreate, update, and delete warehouse locations
webhooks:manageManage webhooks

Sending communications

communications:read has no communications:write counterpart, and this is deliberate. The ability covers reading the communication log; outbound sending is never gated by a communications:write ability. Sends happen as a side effect of the domain action that produces them — a document send, for example, is authorised by that document's own ability — so the permission to send is always the permission to perform the underlying business operation. Whether a particular action type may send autonomously (and who must sign it off) is the approval layer's concern, not a token scope.

Rate Limiting

API requests are rate-limited per token (or per client IP when unauthenticated). Default limits, configurable in Admin > Settings > API:

Context Limit
Authenticated 60 requests/minute
Unauthenticated 20 requests/minute

An individual token can be given a bespoke per-minute limit (rate_limit_per_minute) from the API Tokens admin screen, overriding the authenticated default. Every response carries rate-limit headers:

  • X-RateLimit-Limit — maximum requests per window
  • X-RateLimit-Remaining — requests remaining
  • Retry-After — seconds until the limit resets (sent on 429)

Rate limiting counts requests. It is separate from usage metering, where each endpoint has a price weight (most are 1, meta endpoints are 0) that is summed into billable weighted units — see Usage & Metering.

Idempotency

Any side-effecting POST accepts an optional Idempotency-Key header; replaying the same key returns the stored response with Idempotency-Replayed: true. Operators can enable strict mode (api.require_idempotency_key) to require the header on every mutating POST /api/v1/... request (428 if missing). GET/PUT/PATCH/DELETE and unauthenticated endpoints are never affected. See API Conventions → Idempotency for the full contract.

Response, errors, pagination & filtering

Response envelopes, the Laravel error shape, offset pagination, Ransack-style filtering, sorting, includes, and sparse fieldsets are identical across every v1 endpoint — they are documented once in API Conventions.