Apps API

Apps endpoints in the Brix REST API: 5 operations (GET, POST), with auth, permissions and curl examples.

View as Markdown

Base URL https://api.brixsignage.com. Send Authorization: Bearer $BRIX_API_KEY unless an operation says No auth. The permission chip names what the key must hold. See Authentication and scopes, Errors and rate limits and Pagination.

GET/v1/apps/{key}/render

No auth

Get the rendered HTML for one app from the app catalog. This is the same output used by the player and by the content management system preview.

ParameterInTypeRequiredDescription
keypathstringyesIdentifier for key.
curl "https://api.brixsignage.com/v1/apps/{key}/render"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/apps/catalog

Bearer token app-instance.view

List the apps available to your workspace, including which ones are currently visible for your account to add.

curl "https://api.brixsignage.com/v1/apps/catalog" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.appsarray of object
data.apps[].keystringThe `appKey` to create an instance with.
data.apps[].status"alpha" | "beta" | "ga" | "deprecated"
data.apps[].visiblebooleanTrue when this workspace can add it: enabled and GA, or alpha/beta with early access.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/apps/counter/{token}

No auth

Get the current value of a live counter app, such as Now Serving or Goal Tracker. Access is controlled by the token in the URL rather than by an API key; anyone with the token can read the value.

ParameterInTypeRequiredDescription
tokenpathstringyesIdentifier for token.
curl "https://api.brixsignage.com/v1/apps/counter/{token}"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/apps/counter/{token}

No auth

Set or adjust the value of a live counter app. Provide either an absolute value or a relative change, and the resulting value is clamped between 0 and 999999. Access is controlled by the token in the URL rather than by an API key.

ParameterInTypeRequiredDescription
tokenpathstringyesIdentifier for token.
curl -X POST "https://api.brixsignage.com/v1/apps/counter/{token}"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/apps/counter/{token}/control

No auth

Get an HTML page with simple controls for adjusting a live counter from a phone. The page submits its changes back to the counter endpoint. Access is controlled by the token in the URL.

ParameterInTypeRequiredDescription
tokenpathstringyesIdentifier for token.
curl "https://api.brixsignage.com/v1/apps/counter/{token}/control"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.