Skip to content

API Reference

The ResponseHub JSON API.

Authentication. Every endpoint except POST /api/v1/auth and GET /api/docs requires a Bearer token:

Authorization: Bearer rh_<secret>

Tokens are created in Settings → API tokens. The secret is shown once at creation and stored only as a SHA-256 digest — it cannot be recovered, only rolled. Browser session cookies are not accepted.

Account scope. A token belongs to exactly one account and can only ever read or write that account’s data. There is no cross-account addressing and no way to create an account through the API.

Scopes. Binary: every token may read (GET); a token additionally needs write for any other verb. A token can never exceed its user’s role — a viewer’s token is read-only regardless of scope, and admin-only endpoints still require the admin role.

Identifiers. Records are addressed by opaque prefixed IDs (qu_…, kbi_…, cust_…), never raw database IDs. A record outside your account returns 404, not 403.

Pagination. List endpoints return 20 per page and a pagination block. Pass ?page=N.

Rate limits. Per token: 600 reads/min, 120 writes/min; asking a question 10/min; creating or answering questionnaires and RFPs 3/min each. Exceeding a limit returns 429 with X-RateLimit-* and Retry-After headers.

AI calls. Asking a question is asynchronous (202 Accepted, then poll). The per-item AI actions (generate_answer, rewrite_answer, ai_enhance_answer) are synchronous — they block until the model responds and return 200 with the updated record.

Errors. Every error uses the same envelope, on every endpoint — including POST /api/v1/auth and rate-limit (429) responses:

{"error": {"code": "not_found", "message": "…", "details": ["…"]}}

Information

  • OpenAPI version: 3.1.0

An API token secret, e.g. rh_1f3c…

Security scheme type: http