Bodek Developers
Build on Bodek Files, Forms, SMS and sign-in.
One base URL for every service, keys scoped to exactly what you need, and OAuth so people can sign in to your app with their Bodek account.
The console needs an active Bodek plan. The docs are open to everyone.
curl "https://dev.bodek.us/v1/files/files?parent_id=FoLd5678&limit=50" \
-H "Authorization: Bearer bf_live_XXXX"
# 200 OK · X-Request-Id: 8069ab8f752950692a1c
{
"data": [ { "id": "AbCd1234", "type": "file",
"name": "report.pdf", … } ],
"meta": { "total": 1, "offset": 0, "limit": 50,
"next_offset": null }
}
APIs
Files, Forms, IAM and Users share the gateway at https://dev.bodek.us/v1/<service>. Each has a full endpoint reference.
- Files
/v1/files - Files and folders, chunked uploads, search, share links, storage, workspaces, members and signed webhooks.
- Reference
- Forms
/v1/forms - Create and manage forms, read and export responses, download uploads, send invitations, embed.
- Reference
- IAM
/v1/iam - Workspace members: list, invite, change roles, remove. Pending invites and invite codes.
- Reference
- Users
/v1/users - Create users and businesses, send workspace invitations and password resets. Requires approval.
- Reference
- SMS
sms.bodek.us/api/v1 - Send and read text messages, list numbers, manage groups, start text-menu flows.
- Reference
- Bodek OAuth
accounts.bodek.us - Sign in with Bodek: authorization code with PKCE, refresh tokens, UserInfo, introspection, revocation.
- Reference
Keys you control
Create keys in the console. Each key calls one service and only the scopes you pick.
-
Scopes
Choose from each service's list, such as
files:readorforms.write. Missing scopes return403 insufficient_scope. -
Folder lock
Limit a Files key to one folder. Anything outside it returns
404. -
Allowed origins
Restrict browser keys to your domains, like
*.example.com. Keep unrestricted keys on your server. -
Rate limits
Per-minute and per-day caps on every key, reported in response headers. The console shows the last 24 hours of use.
-
Request IDs
Every response carries
X-Request-Id, also recorded in the key's audit log. -
Signed webhooks
Files sends events to your endpoint, signed so you can verify each delivery.
Sign in with Bodek
Let people sign in to your app with their Bodek account. Passwords and two-factor stay with Bodek.
- Standard OAuth 2.0. Authorization code flow, with PKCE for public apps.
- Discovery. Metadata at
/.well-known/openid-configuration. - Tokens. Refresh tokens with
offline_access, plus introspection and revocation. - Your apps. Register clients and redirect URIs in the OAuth apps console.
| Endpoint | Method | Path |
|---|---|---|
| Authorization | GET | /authorize |
| Token | POST | /token |
| UserInfo | GET / POST | /userinfo |
| Introspection | POST | /introspect |
| Revocation | POST | /revoke |
| End session | GET | /logout |
Create your first key
Sign in with your Bodek account and open the console.