Conventions

Responses, request ids, identifiers, dates, money, paging, rate limits and cross-origin rules shared by every endpoint.

Every workspace route follows the same rules for URLs, responses, identifiers, dates, money and paging.

URLs and methods

  • Base URL: https://axisiq.co/api/v1.
  • Workspace routes live under /orgs/{orgId}/…. {orgId} is the Organization ID from Settings.
  • Standard methods: GET to read, POST to create or run, PUT or PATCH to update, DELETE to remove.
  • Request bodies are JSON. Bodies larger than 1 MB are refused, except file uploads and imports (Drive, website assets, spreadsheet and calendar imports), which accept larger files.

Responses

A successful call returns the data under a data key:

{ "data": { "id": "0190f0aa-…", "name": "Main store" } }

Some calls return 204 No Content with no body (for example most deletes) or 202 Accepted when work is queued and finishes in the background (for example running a flow).

A failed call returns an error object instead:

{
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "amount: expected a number",
    "request_id": "9f2c41a0b7d3e655"
  }
}

code is stable and meant for your code to branch on; message is for humans and may change. All codes are in Errors.

Request ids

Every response carries an X-Request-ID header, and every error includes the same value as request_id. Quote it when you contact support. You may send your own X-Request-ID (up to 64 letters, digits, -, _ or .) and it is echoed back, which helps you match your logs to ours.

Identifiers

  • Ids are UUIDs, such as 0190f0aa-7c1e-7a3b-9d52-4f0e6c1b2a10. They sort roughly by creation time, so newer items have larger ids.
  • Many things also have a human-readable key: a record type (invoices), a queue, a site, a form, a drive space, a calendar. Keys are lowercase letters, digits and hyphens or underscores. Where a route says {typeKey} it takes the key; where it says {queueID} it takes the UUID.

Dates and times

  • Timestamps are RFC 3339 in UTC: 2026-10-04T09:30:00Z.
  • Date-only values (a date field, an accounting entry date) are YYYY-MM-DD.
  • Calendar events accept either a date (2026-10-04, for all-day) or an RFC 3339 time.

Numbers and money

  • Amounts are exact decimals. Send them as JSON numbers or as strings ("12500.00"). Do not round-trip money through floating point on your side if you can avoid it.

  • A currency field holds an object with the amount and an ISO 4217 code:

    { "amount": 12500, "code": "INR" }
    

    If you send a bare number, the code falls back to the field's fixed currency (if it has one), then to the workspace's default currency. A field fixed to one currency ignores any other code you send.

  • Accounting amounts (debit, credit, total, balance) are decimal strings.

  • Reports and the ledger read one currency at a time. Pass ?currency=INR and the response lists currency and currencies.

Paging

Lists use one of three styles. Each endpoint page says which it uses.

Style Parameters Response
Cursor limit, cursor A next_cursor (or the last item's id). Pass it back as cursor to get the next page. No next_cursor means you reached the end
Page / offset limit, and page or offset A total count
Offset only limit, offset total and often next_offset

Typical limits: the default page is 50 and the maximum is 100 to 200 depending on the endpoint. Asking for more than the maximum is a 400 VALIDATION_ERROR.

Records, for example:

# first page
curl -s "https://axisiq.co/api/v1/orgs/$ORG/records/invoices?limit=100" -H "Authorization: Bearer $AXIS_KEY"
# next page
curl -s "https://axisiq.co/api/v1/orgs/$ORG/records/invoices?limit=100&cursor=0190f0aa-…" -H "Authorization: Bearer $AXIS_KEY"

Rate limits

Surface Limit
Ask Axis chat 30 requests per minute per IP address
Public HTTP functions (/fn/…) 60 requests per minute per IP address
Public website content (/content/…) 240 requests per minute per IP address
Public forms (/forms/…) 30 requests per minute per IP address
Public calendar pages (/cal/…) 60 requests per minute per IP address

Going over a limit returns 429 RATE_LIMITED. Wait a minute and retry. Back off when you see it.

Authenticated workspace routes have no per-minute cap of their own, but your plan's limits still apply (see 402 LIMIT_EXCEEDED in Errors). Please keep bulk jobs to a few concurrent requests.

Permissions and hidden data

  • A route you are not allowed to use answers 403 FORBIDDEN.
  • For workspaces you are not a member of, and for records you may not read, the API answers 404 NOT_FOUND rather than confirming they exist.
  • Fields your role may not read are left out of record responses and cannot be used to filter or sort.

Cross-origin calls

The API is meant to be called from servers, scripts and back-ends. Browser JavaScript running on other websites is refused, with one exception: the public website-content endpoints (/content/…) accept requests from any origin so a site can read its own published pages.

Workspaces that are busy

While a workspace is being created or upgraded, calls answer 503 ORG_NOT_READY with a Retry-After header (seconds). Wait that long and retry.