Corporate access
An administrator creates and revokes keys in Company settings → Developer API. The complete key is shown only once.
IWEBIT INTEGRATIONS
A secure, read-only API to integrate Devices and Domotics from your Corporate company.
v1 accepts GET only. It does not include Domotics commands, agent gateway operations, user sessions, or inventory changes.
GET /api/v1/public/devices
Authorization: Bearer iw_live_••••••••
{ "data": [ ... ], "meta": { "next_cursor": null } }API V1
An administrator creates and revokes keys in Company settings → Developer API. The complete key is shown only once.
An administrator creates and revokes keys in Company settings → Developer API. The complete key is shown only once.
v1 accepts GET only. It does not include Domotics commands, agent gateway operations, user sessions, or inventory changes.
The key is stored only as HMAC-SHA-256. Each key can be restricted by IP or CIDR. Passwords, usernames, callback secrets, screenshots, cookies, sessions, and control data are excluded. Every authenticated call is recorded for audit and future billing without retaining requests, responses, or credentials.
REFERENCE
Base URL · https://api.iwebit.app/api/v1/public
/devicesCursor-paginated Device list.
/devices/{deviceId}Safe DeviceView detail: inventory, network, disks, software, updates, alerts, and incidents.
/domoticsCursor-paginated Domotics equipment list.
/domotics/{domoticaId}Safe DomoticaView detail: channels, sensors, telemetry, history, and incidents.
Authentication
curl --request GET 'https://api.iwebit.app/api/v1/public/devices?per_page=50' --header 'Authorization: Bearer iw_live_<key-id>.<secret>' --header 'Accept: application/json'Send the key in the Authorization header and store it in a secrets manager. Never put it in URLs, repositories, or frontend code. The sandbox below is a controlled exception: it sends it directly to the API and keeps it in browser memory only.
Lists accept cursor and per_page (1 to 100). Use meta.next_cursor while it exists. The initial limit is 120 requests per minute per key; X-RateLimit-* headers show consumption.
Errors return error.code, error.message, and error.requestId. Keep X-Request-Id for support. 401 means an invalid key; 403 means a licence, IP, or scope is not allowed; 404 protects missing or another company’s data; 429 means the limit was exceeded.
INTERACTIVE SANDBOX
Try a read-only request with your company key. The request goes directly from your browser to the iWebIT API.
The key is not stored, is not sent to the institutional website, and is cleared when you close or refresh this page.
Sandbox limit: 10 attempts per IP address in each 24-hour period.
Browser → API, no website proxy
Ready to test. The key stays only in this browser memory.
GET /devices?per_page=20
Authorization: Bearer ••••••••
Accept: application/jsonThere is no response yet.