Conventions
Responses, request ids, identifiers, dates, money, paging, rate limits and cross-origin rules shared by every endpoint.
Every workspace route follows the same rules for URLs, responses, identifiers, dates, money and paging.
URLs and methods
- Base URL:
https://axisiq.co/api/v1. - Workspace routes live under
/orgs/{orgId}/….{orgId}is the Organization ID from Settings. - Standard methods:
GETto read,POSTto create or run,PUTorPATCHto update,DELETEto remove. - Request bodies are JSON. Bodies larger than 1 MB are refused, except file uploads and imports (Drive, website assets, spreadsheet and calendar imports), which accept larger files.
Responses
A successful call returns the data under a data key:
{ "data": { "id": "0190f0aa-…", "name": "Main store" } }
Some calls return 204 No Content with no body (for example most deletes) or 202 Accepted when work is queued and finishes in the background (for example running a flow).
A failed call returns an error object instead:
{
"error": {
"code": "VALIDATION_ERROR",
"message": "amount: expected a number",
"request_id": "9f2c41a0b7d3e655"
}
}
code is stable and meant for your code to branch on; message is for humans and may change. All codes are in Errors.
Request ids
Every response carries an X-Request-ID header, and every error includes the same value as request_id. Quote it when you contact support. You may send your own X-Request-ID (up to 64 letters, digits, -, _ or .) and it is echoed back, which helps you match your logs to ours.
Identifiers
- Ids are UUIDs, such as
0190f0aa-7c1e-7a3b-9d52-4f0e6c1b2a10. They sort roughly by creation time, so newer items have larger ids. - Many things also have a human-readable key: a record type (
invoices), a queue, a site, a form, a drive space, a calendar. Keys are lowercase letters, digits and hyphens or underscores. Where a route says{typeKey}it takes the key; where it says{queueID}it takes the UUID.
Dates and times
- Timestamps are RFC 3339 in UTC:
2026-10-04T09:30:00Z. - Date-only values (a
datefield, an accounting entry date) areYYYY-MM-DD. - Calendar events accept either a date (
2026-10-04, for all-day) or an RFC 3339 time.
Numbers and money
-
Amounts are exact decimals. Send them as JSON numbers or as strings (
"12500.00"). Do not round-trip money through floating point on your side if you can avoid it. -
A currency field holds an object with the amount and an ISO 4217 code:
{ "amount": 12500, "code": "INR" }If you send a bare number, the code falls back to the field's fixed currency (if it has one), then to the workspace's default currency. A field fixed to one currency ignores any other code you send.
-
Accounting amounts (
debit,credit,total,balance) are decimal strings. -
Reports and the ledger read one currency at a time. Pass
?currency=INRand the response listscurrencyandcurrencies.
Paging
Lists use one of three styles. Each endpoint page says which it uses.
| Style | Parameters | Response |
|---|---|---|
| Cursor | limit, cursor |
A next_cursor (or the last item's id). Pass it back as cursor to get the next page. No next_cursor means you reached the end |
| Page / offset | limit, and page or offset |
A total count |
| Offset only | limit, offset |
total and often next_offset |
Typical limits: the default page is 50 and the maximum is 100 to 200 depending on the endpoint. Asking for more than the maximum is a 400 VALIDATION_ERROR.
Records, for example:
# first page
curl -s "https://axisiq.co/api/v1/orgs/$ORG/records/invoices?limit=100" -H "Authorization: Bearer $AXIS_KEY"
# next page
curl -s "https://axisiq.co/api/v1/orgs/$ORG/records/invoices?limit=100&cursor=0190f0aa-…" -H "Authorization: Bearer $AXIS_KEY"
Rate limits
| Surface | Limit |
|---|---|
| Ask Axis chat | 30 requests per minute per IP address |
Public HTTP functions (/fn/…) |
60 requests per minute per IP address |
Public website content (/content/…) |
240 requests per minute per IP address |
Public forms (/forms/…) |
30 requests per minute per IP address |
Public calendar pages (/cal/…) |
60 requests per minute per IP address |
Going over a limit returns 429 RATE_LIMITED. Wait a minute and retry. Back off when you see it.
Authenticated workspace routes have no per-minute cap of their own, but your plan's limits still apply (see 402 LIMIT_EXCEEDED in Errors). Please keep bulk jobs to a few concurrent requests.
Permissions and hidden data
- A route you are not allowed to use answers
403 FORBIDDEN. - For workspaces you are not a member of, and for records you may not read, the API answers
404 NOT_FOUNDrather than confirming they exist. - Fields your role may not read are left out of record responses and cannot be used to filter or sort.
Cross-origin calls
The API is meant to be called from servers, scripts and back-ends. Browser JavaScript running on other websites is refused, with one exception: the public website-content endpoints (/content/…) accept requests from any origin so a site can read its own published pages.
Workspaces that are busy
While a workspace is being created or upgraded, calls answer 503 ORG_NOT_READY with a Retry-After header (seconds). Wait that long and retry.