API

Sign in to the API

Understand API sessions, access checks, and safe error handling.

Know which requests are public

Health, Swagger, the OpenAPI file, and some sign in requests do not need a session. Most product requests do.

Use the supported session

The current OpenAPI file lists two ways to send a Pūnaha session. A browser can use the secure punaha_session cookie. An API client can send the session token as a Bearer value.

Do not copy a person's password or browser cookie into an unattended program.

Plan unattended access

The current public API guide does not describe a separate credential for an outside application. Agree a safe sign in design before you use an unattended client in production.

Give exact access

Pūnaha checks the signed in identity, tenant, item, and action for each protected request. View, Search, Run, Create, Update, Work, Publish, and Delete are separate actions.

The Permissions page used to manage API access
Give the signed in identity only the access it needs. Earlier development interface, captured 22 August 2026. Follow the current text for RC1. Open the full image.

Handle an error

  1. Save the HTTP status.
  2. Save the safe error code and request ID.
  3. Do not save the password, token, or secret key.
  4. Reload the item before you repeat a request after a conflict.
  5. Repeat a request only when it is safe to do so.

Keep versions together

Keep the API client, OpenAPI file, and Pūnaha version together. Test them again before an update.

Pūnaha Docs

Search the guides

Enter at least two characters.

    Product screen

    View the full screenshot