IWEBIT INTEGRATIONS

Connect your operation to iWebIT.

A secure, read-only API to integrate Devices and Domotics from your Corporate company.

v1 accepts GET only. It does not include Domotics commands, agent gateway operations, user sessions, or inventory changes.

iwebit / developer-apiGET

GET /api/v1/public/devices

Authorization: Bearer iw_live_••••••••

200 OK
{ "data": [ ... ], "meta": { "next_cursor": null } }
GET onlyScoped by companyAuditable usageIP allow lists

API V1

Corporate access

An administrator creates and revokes keys in Company settings → Developer API. The complete key is shown only once.

01

Corporate access

An administrator creates and revokes keys in Company settings → Developer API. The complete key is shown only once.

02

Read-only, no commands

v1 accepts GET only. It does not include Domotics commands, agent gateway operations, user sessions, or inventory changes.

03

Security and privacy

The key is stored only as HMAC-SHA-256. Each key can be restricted by IP or CIDR. Passwords, usernames, callback secrets, screenshots, cookies, sessions, and control data are excluded. Every authenticated call is recorded for audit and future billing without retaining requests, responses, or credentials.

REFERENCE

Available endpoints

Base URL · https://api.iwebit.app/api/v1/public

GET/devices

Cursor-paginated Device list.

GET/devices/{deviceId}

Safe DeviceView detail: inventory, network, disks, software, updates, alerts, and incidents.

GET/domotics

Cursor-paginated Domotics equipment list.

GET/domotics/{domoticaId}

Safe DomoticaView detail: channels, sensors, telemetry, history, and incidents.

Authentication

Connection example

cURL
curl --request GET 'https://api.iwebit.app/api/v1/public/devices?per_page=50' --header 'Authorization: Bearer iw_live_<key-id>.<secret>' --header 'Accept: application/json'

Authentication

Send the key in the Authorization header and store it in a secrets manager. Never put it in URLs, repositories, or frontend code. The sandbox below is a controlled exception: it sends it directly to the API and keeps it in browser memory only.

Pagination and limits

Lists accept cursor and per_page (1 to 100). Use meta.next_cursor while it exists. The initial limit is 120 requests per minute per key; X-RateLimit-* headers show consumption.

Errors

Errors return error.code, error.message, and error.requestId. Keep X-Request-Id for support. 401 means an invalid key; 403 means a licence, IP, or scope is not allowed; 404 protects missing or another company’s data; 429 means the limit was exceeded.

INTERACTIVE SANDBOX

Test your key without exposing it.

Try a read-only request with your company key. The request goes directly from your browser to the iWebIT API.

The key is not stored, is not sent to the institutional website, and is cleared when you close or refresh this page.

Sandbox limit: 10 attempts per IP address in each 24-hour period.

Browser → API, no website proxy

Ready to test. The key stays only in this browser memory.

Request
GET /devices?per_page=20
Authorization: Bearer ••••••••
Accept: application/json
Response
There is no response yet.

COOKIES

We use cookies needed for the site to work. With your consent, we can also measure site usage to improve it.