Ask Osolix — instant answers

Developer portal

Build on the
Osolix REST API

A single, JWT-secured REST API covers the entire asset platform — assets, depreciation, leases, CWIP, insurance, maintenance and the intelligence hubs. It ships with a current OpenAPI 3.0.1 specification you can import into Stoplight Studio or browse live in Swagger UI.

OpenAPI version
3.0.1
Paths
1,469
Operations
1,840
Schemas
1,008

Authentication

Every non-anonymous endpoint expects a JWT bearer token. Mint one with your credentials, then send it on the Authorization header. Tokens are issued by osolix-api for the osolix-clients audience. A handful of endpoints (such as GET /health) are deliberately anonymous.

All access is tenant-scoped and enforced server-side — a token only ever sees its own tenant's data.

1 · Obtain a token

POST {API_BASE}/api/auth/login

2 · Call any endpoint with the bearer token

Authorization: Bearer <your-jwt>GET {API_BASE}/api/assets?page=1&pageSize=50

Base URLs

EnvironmentBase URLNotes
Productionhttps://api.osolix.comLive tenant traffic. Swagger UI at /swagger.
Local (HTTPS)https://localhost:7233Dev host from launchSettings.json.
Local (HTTP)http://localhost:5233Same host, plain HTTP.

Spec & tooling

OpenAPI 3.0.1 spec

The committed source of truth for the portal. Download it, or fetch it live from the running API at {API_BASE}/swagger/v1/swagger.json.

openapi-v1.json

Import into Stoplight

In Stoplight Studio, create a project and choose Import → OpenAPI → Upload a file, then select openapi-v1.json. Studio renders every path and model with the JWT scheme already wired up, and a Try-It console.

stoplight.io

Browse in Swagger UI

The running API serves interactive Swagger UI at {API_BASE}/swagger. Authorise with a bearer token and call endpoints straight from the browser.

Endpoints index

Headline endpoint groups

A taste of the surface — the full map lives in the endpoints index.

Assets & lifecycle

The Fixed Asset Register and its full lifecycle — additions, transfers, verifications, retirement.

  • api/assets
  • api/additions
  • api/transfers
  • api/retirements
  • api/asset-revaluations

Depreciation & finance

Depreciation runs, forecasts, tax depreciation, the ledger, impairment and year-end close.

  • api/depreciation
  • api/tax-depreciation
  • api/finance
  • api/finance/impairment-test

Leases

IFRS 16 / ASC 842 lease accounting — ROU assets, liabilities and contracts.

  • api/leases
  • api/contracts

CWIP & Capex

Capital work-in-progress, capital projects, Capex budgets, forecasts and DOA matrix.

  • api/cwip
  • api/capital-projects
  • api/capex
  • api/capex-budgets

Insurance

Policies, renewals, claims, proposals, coverage analysis and the insurance-drift watcher.

  • api/insurance-policies
  • api/insurance-claims
  • api/insurance-drift
  • api/insurance-proposals

Maintenance & reliability

Work orders, predictive maintenance, SLAs, repair-vs-replace, parts and incidents.

  • api/maintenance
  • api/maintenance/predictive
  • api/WorkOrders
  • api/parts

Intelligence hubs

Cross-domain intelligence — marquee KPIs, audit, capex, insurance and market-value drift.

  • api/wave5
  • api/audit-wave5
  • api/capex-wave5
  • api/market-value-drift

Audit, compliance & governance

Audit trails, evidence packs, compliance frameworks, scorecards, standards and the governance dashboard.

  • api/audit
  • api/compliance
  • api/standards
  • api/governance

ERP, webhooks & sync

Inbound/outbound ERP integration, the outbox, connector packs, imports/exports and webhooks.

  • api/erp-inbound
  • api/erp-exports
  • api/webhooks
  • api/sync

Identity & auth

Login, MFA, SSO / SAML, SCIM provisioning, users, roles and permissions.

  • api/auth
  • api/auth/mfa
  • api/auth/sso
  • api/users

Rate limits

The API is protected by named rate-limit policies, applied per endpoint class. A throttled request returns 429 Too Many Requests; back off and retry. Need a higher ceiling for an integration? Ask us when you request access.

erp-inbound

High-volume ERP push / sync endpoints.

ai-copilot

Tenant-facing Osolix AI agent calls.

admin-copilot

Privileged Osolix AI admin assistant operations.

public-checkout

Anonymous checkout — anti-abuse throttle.

All transport is TLS 1.2+. Every request is tenant-scoped and audit-logged server-side, and write operations on approval and transfer resources support optimistic concurrency via the If-Match ETag header. See the compliance reference for the full control stack.

Get API access

Tell us what you want to build and we will set you up with credentials, a sandbox tenant, and the right rate-limit ceiling for your integration.