Creatives API

Creatives endpoints in the Brix REST API: 7 operations (GET, POST, PATCH, DELETE), with auth, permissions and curl examples.

View as Markdown

Base URL https://api.brixsignage.com. Send Authorization: Bearer $BRIX_API_KEY unless an operation says No auth. The permission chip names what the key must hold. See Authentication and scopes, Errors and rate limits and Pagination.

GET/v1/creatives

Bearer token creative.view

Return the workspace's canvas creatives, including each one's name, stage size, location, and sharing state. The full layout of shapes is not included; use the get-creative operation to retrieve that.

ParameterInTypeRequiredDescription
limitqueryintegernoPage size. Omit to get every row; pass it to page by `cursor`.
cursorquerystringnoThe `nextCursor` of the previous page.
countquery"1"noWith `limit`: also return `total`, the number of matching rows.
usableAtquerystringnoLocation id: only rows usable at that location (homed there, at the workspace root, or shared to it).
curl "https://api.brixsignage.com/v1/creatives" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataarray of Creative
data[].idstringCreative id.
data[].spaceIdstring
data[].namestring
data[].backgroundUrlstring | null
data[].boxesarray of objectThe design's boxes (text, image, data-bound fields…), in paint order.
data[].dataSourceIdstring | nullThe data source the boxes bind to, if any.
data[].stagestring | nullStage preset name.
data[].stageWidthinteger | null
data[].stageHeightinteger | null
data[].scenesarray of objectScenes, for a multi-scene design; often empty.
data[].touchEnabledboolean | null
data[].nodeIdstring | null
data[].approvalState"draft" | "pending" | "approved" | "rejected"Review state. Editing an approved row returns it to `draft`.
data[].approvedSnapshotstring | nullJSON TEXT of the last approved version (not parsed).
data[].sourceSignageany | nullThe template it was made from (JSON), if any.
data[].lookany | nullAccent / Brand Kit / light-dark settings (JSON), if set.
data[].masterIdstring | nullThe master template id, for a design made from one.
data[].shareLockDefaultany | nullWhich boxes recipients may edit when shared (JSON), if set.
data[].shareEditsSkipApprovalboolean
data[].recalledAtstring | null
data[].recalledBystring | null
data[].createdAtstringISO-8601 timestamp (UTC).
data[].updatedAtstringISO-8601 timestamp (UTC).
data[].deletedAtstring | nullAlways null on these reads: deleted rows are not listed.
nextCursorstring | nullPresent when `?limit` was passed. Send it back as `?cursor=` for the next page; null on the last page.
totalintegerTotal matching rows, when the route computes it.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/creatives

Bearer token creative.create

Create a canvas creative. Accepts name and optional boxes, scenes, stageWidth, stageHeight, backgroundUrl, dataSourceId, touchEnabled, nodeId, and masterId. Safe to retry with the same Idempotency-Key header without creating duplicates. **Notes.** - The 201 body is the row as written, not re-read from the database, so columns the create does not set (for example lastSnapshotAt) are absent rather than null. GET returns every column. - Send an Idempotency-Key header to make a retry safe.

Request body application/json

FieldTypeRequiredDescription
namestringyes
backgroundUrlstring | nullnoAn unsafe URL scheme is stored as null.
boxesarray of objectnoThe whole box list; each box is checked and filled out with defaults. Default `[]`.
dataSourceIdstring | nullnoA data source in this workspace.
stagestring | nullno
stageWidthinteger | nullno
stageHeightinteger | nullno
scenesarray of objectnoDefault `[]`.
touchEnabledboolean | nullno
nodeIdstring | nullnoHome location. Default: the caller's own location.
sourceSignageanyno
masterIdstring | nullnoThe master template it was made from (`GET /v1/signage-master-templates`).
shareLockDefaultanynoWhich box fields recipients may edit when it is shared (JSON).
shareEditsSkipApprovalbooleannoRecipients' edits air without review. Needs `creative.approve`.
lookobject | nullno
curl -X POST "https://api.brixsignage.com/v1/creatives" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json"

Response 201 Success.

FieldTypeDescription
dataobject
data.idstringCreative id.
data.spaceIdstring
data.namestring
data.backgroundUrlstring | null
data.boxesarray of objectThe design's boxes (text, image, data-bound fields…), in paint order.
data.dataSourceIdstring | nullThe data source the boxes bind to, if any.
data.stagestring | nullStage preset name.
data.stageWidthinteger | null
data.stageHeightinteger | null
data.scenesarray of objectScenes, for a multi-scene design; often empty.
data.touchEnabledboolean | null
data.nodeIdstring | null
data.approvalState"draft" | "pending" | "approved" | "rejected"Review state. Editing an approved row returns it to `draft`.
data.approvedSnapshotstring | nullJSON TEXT of the last approved version (not parsed).
data.sourceSignageany | nullThe template it was made from (JSON), if any.
data.lookany | nullAccent / Brand Kit / light-dark settings (JSON), if set.
data.masterIdstring | nullThe master template id, for a design made from one.
data.shareLockDefaultany | nullWhich boxes recipients may edit when shared (JSON), if set.
data.shareEditsSkipApprovalboolean
data.recalledAtstring | null
data.recalledBystring | null
data.createdAtstringISO-8601 timestamp (UTC).
data.updatedAtstringISO-8601 timestamp (UTC).
data.deletedAtstring | nullAlways null on these reads: deleted rows are not listed.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 Setting `shareEditsSkipApproval` without `creative.approve`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 `dataSourceId` names no data source in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 Missing name, invalid JSON, malformed boxes, scenes or look, or a location outside this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/creatives/{id}

Bearer token creative.view

Return one creative in full, including its boxes, scenes, background, any linked data source, and stage dimensions.

ParameterInTypeRequiredDescription
idpathstringyesCreative id.
curl "https://api.brixsignage.com/v1/creatives/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.idstringCreative id.
data.spaceIdstring
data.namestring
data.backgroundUrlstring | null
data.boxesarray of objectThe design's boxes (text, image, data-bound fields…), in paint order.
data.dataSourceIdstring | nullThe data source the boxes bind to, if any.
data.stagestring | nullStage preset name.
data.stageWidthinteger | null
data.stageHeightinteger | null
data.scenesarray of objectScenes, for a multi-scene design; often empty.
data.touchEnabledboolean | null
data.nodeIdstring | null
data.approvalState"draft" | "pending" | "approved" | "rejected"Review state. Editing an approved row returns it to `draft`.
data.approvedSnapshotstring | nullJSON TEXT of the last approved version (not parsed).
data.sourceSignageany | nullThe template it was made from (JSON), if any.
data.lookany | nullAccent / Brand Kit / light-dark settings (JSON), if set.
data.masterIdstring | nullThe master template id, for a design made from one.
data.shareLockDefaultany | nullWhich boxes recipients may edit when shared (JSON), if set.
data.shareEditsSkipApprovalboolean
data.recalledAtstring | null
data.recalledBystring | null
data.createdAtstringISO-8601 timestamp (UTC).
data.updatedAtstringISO-8601 timestamp (UTC).
data.deletedAtstring | nullAlways null on these reads: deleted rows are not listed.
data.requiresApprovalbooleanThe home location requires approval before content airs.
data.canEditBasebooleanThe caller may edit the design itself (not only its unlocked boxes).
data.canWaiveApprovalbooleanThe caller holds `creative.approve` at its home location.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such creative in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

PATCH/v1/creatives/{id}

Bearer token creative.edit

Edit a creative. The boxes and scenes fields each replace the entire existing list, so retrieve the creative first and send back the complete array with changes included. If the location requires approval before content goes live, updating the creative resets that approval. **Notes.** - The response is the stored row: it has no requiresApproval, canEditBase or canWaiveApproval (GET has them).

ParameterInTypeRequiredDescription
idpathstringyesCreative id.

Request body application/json

FieldTypeRequiredDescription
namestringno
backgroundUrlstring | nullnoAn unsafe URL scheme is stored as null.
boxesarray of objectnoThe whole box list; each box is checked and filled out with defaults. Default `[]`.
dataSourceIdstring | nullnoA data source in this workspace.
stagestring | nullno
stageWidthinteger | nullno
stageHeightinteger | nullno
scenesarray of objectnoDefault `[]`.
touchEnabledboolean | nullno
nodeIdstring | nullnoHome location. Default: the caller's own location.
sourceSignageanyno
masterIdstring | nullnoThe master template it was made from (`GET /v1/signage-master-templates`).
shareLockDefaultanynoWhich box fields recipients may edit when it is shared (JSON).
shareEditsSkipApprovalbooleannoRecipients' edits air without review. Needs `creative.approve`.
lookobject | nullno
baseUpdatedAtstringnoOptimistic concurrency: the `updatedAt` you read. A stale value is refused with 409 `conflict` and the `current` row.
curl -X PATCH "https://api.brixsignage.com/v1/creatives/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json"

Response 200 Success.

FieldTypeDescription
dataCreativeA canvas design (data-bound boxes on a stage).
data.idstringCreative id.
data.spaceIdstring
data.namestring
data.backgroundUrlstring | null
data.boxesarray of objectThe design's boxes (text, image, data-bound fields…), in paint order.
data.dataSourceIdstring | nullThe data source the boxes bind to, if any.
data.stagestring | nullStage preset name.
data.stageWidthinteger | null
data.stageHeightinteger | null
data.scenesarray of objectScenes, for a multi-scene design; often empty.
data.touchEnabledboolean | null
data.nodeIdstring | null
data.approvalState"draft" | "pending" | "approved" | "rejected"Review state. Editing an approved row returns it to `draft`.
data.approvedSnapshotstring | nullJSON TEXT of the last approved version (not parsed).
data.sourceSignageany | nullThe template it was made from (JSON), if any.
data.lookany | nullAccent / Brand Kit / light-dark settings (JSON), if set.
data.masterIdstring | nullThe master template id, for a design made from one.
data.shareLockDefaultany | nullWhich boxes recipients may edit when shared (JSON), if set.
data.shareEditsSkipApprovalboolean
data.recalledAtstring | null
data.recalledBystring | null
data.createdAtstringISO-8601 timestamp (UTC).
data.updatedAtstringISO-8601 timestamp (UTC).
data.deletedAtstring | nullAlways null on these reads: deleted rows are not listed.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 Moving it to a location where you lack creative.edit, or changing `shareEditsSkipApproval` without `creative.approve`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such creative (or `dataSourceId`) in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 409 `conflict`: the row changed since `baseUpdatedAt`; the body carries `current`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 Invalid JSON or malformed boxes, scenes or look.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

DELETE/v1/creatives/{id}

Bearer token creative.delete

Move a creative to the recycle bin. If the creative is shared into other locations, the request fails with a 409 error unless the deletion is explicitly confirmed, since deleting a shared creative removes it everywhere it is shared.

ParameterInTypeRequiredDescription
idpathstringyesCreative id.
forcequery"true"noDelete even when it is shared into other places; the shares go with it.
curl -X DELETE "https://api.brixsignage.com/v1/creatives/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.idstring
data.deletedtrue
data.sharesRemovedintegerShares removed with it.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such creative in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 409 `content_shared`: it is shared into other places; `shareCount`, `crossSpaceShares`, `contentShares` say where. Repeat with `?force=true` to delete it and those shares.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/creatives/{id}/restore

Bearer token creative.delete

Bring back a deleted creative so it returns to the library. The shares removed by the delete come back with it.

ParameterInTypeRequiredDescription
idpathstringyesCreative id.
curl -X POST "https://api.brixsignage.com/v1/creatives/{id}/restore" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.idstring
data.restoredtrue

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such creative in this workspace, or it was purged.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 409 `not_deleted`: the creative is not in the recycle bin.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/creatives/{id}/thumbnail

Bearer token creative.view

Return an image of the creative, showing its shapes and pictures along with a representative preview of each content slot, such as a file's poster image, a playlist's first item, or an app's most recent snapshot. Text boxes are not drawn. The image is cached; add ?fresh=1 to bypass the cache after making an edit.

ParameterInTypeRequiredDescription
idpathstringyesCreative id.
freshquery"1"noSkip the cached image and draw it again.
curl "https://api.brixsignage.com/v1/creatives/{id}/thumbnail" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such creative in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.