Skip to content
Bodek Developers

Bodek Developers

Build on Bodek Files, Forms, SMS and sign-in.

One base URL for every service, keys scoped to exactly what you need, and OAuth so people can sign in to your app with their Bodek account.

The console needs an active Bodek plan. The docs are open to everyone.

List files in a folder GET /v1/files/files
curl "https://dev.bodek.us/v1/files/files?parent_id=FoLd5678&limit=50" \
  -H "Authorization: Bearer bf_live_XXXX"
# 200 OK · X-Request-Id: 8069ab8f752950692a1c
{
  "data": [ { "id": "AbCd1234", "type": "file",
              "name": "report.pdf", … } ],
  "meta": { "total": 1, "offset": 0, "limit": 50,
            "next_offset": null }
}

APIs

Files, Forms, IAM and Users share the gateway at https://dev.bodek.us/v1/<service>. Each has a full endpoint reference.

Files/v1/files
Files and folders, chunked uploads, search, share links, storage, workspaces, members and signed webhooks.
Forms/v1/forms
Create and manage forms, read and export responses, download uploads, send invitations, embed.
IAM/v1/iam
Workspace members: list, invite, change roles, remove. Pending invites and invite codes.
Users/v1/users
Create users and businesses, send workspace invitations and password resets. Requires approval.
SMSsms.bodek.us/api/v1
Send and read text messages, list numbers, manage groups, start text-menu flows.
Bodek OAuthaccounts.bodek.us
Sign in with Bodek: authorization code with PKCE, refresh tokens, UserInfo, introspection, revocation.

Keys you control

Create keys in the console. Each key calls one service and only the scopes you pick.

  • Scopes

    Choose from each service's list, such as files:read or forms.write. Missing scopes return 403 insufficient_scope.

  • Folder lock

    Limit a Files key to one folder. Anything outside it returns 404.

  • Allowed origins

    Restrict browser keys to your domains, like *.example.com. Keep unrestricted keys on your server.

  • Rate limits

    Per-minute and per-day caps on every key, reported in response headers. The console shows the last 24 hours of use.

  • Request IDs

    Every response carries X-Request-Id, also recorded in the key's audit log.

  • Signed webhooks

    Files sends events to your endpoint, signed so you can verify each delivery.

Sign in with Bodek

Let people sign in to your app with their Bodek account. Passwords and two-factor stay with Bodek.

  • Standard OAuth 2.0. Authorization code flow, with PKCE for public apps.
  • Discovery. Metadata at /.well-known/openid-configuration.
  • Tokens. Refresh tokens with offline_access, plus introspection and revocation.
  • Your apps. Register clients and redirect URIs in the OAuth apps console.
Endpoints accounts.bodek.us
EndpointMethodPath
AuthorizationGET/authorize
TokenPOST/token
UserInfoGET / POST/userinfo
IntrospectionPOST/introspect
RevocationPOST/revoke
End sessionGET/logout

Create your first key

Sign in with your Bodek account and open the console.