API reference

The versioned REST API

Everything the dashboard does against your workspace data, your scripts can do too. Scoped keys, JSON in and out, and error codes that say what went wrong.

Connecting an AI assistant instead?

The same key works with the SignlOS MCP server, which wraps these endpoints in tools an assistant can pick from. See the MCP server.

Authentication

All API requests require a Bearer token. Create an API key from Settings > API and include it in the Authorization header.

curl https://api.signlos.com/api/v1/posts \
  -H "Authorization: Bearer sk_live_your_key_here"

Scopes

Each API key has scoped permissions. A key can only access endpoints matching its scopes.

boards:read
boards:write
posts:read
posts:write
roadmap:read
changelog:read
changelog:write
status:read
status:write
members:read
todos:read
todos:write

Rate Limits

API keys are limited to 100 requests per minute. Rate limit status is returned in response headers:

X-RateLimit-Limit: 100

X-RateLimit-Remaining: 97

X-RateLimit-Reset: 45

When the limit is exceeded, requests return 429 Too Many Requests.

Endpoints

Base URL: https://api.signlos.com/api/v1

Boards

Posts

Roadmap

Changelog

Status

Members

Todos

Error Codes

All errors follow a consistent format:

{
  "success": false,
  "error": "Human-readable message",
  "code": "ERROR_CODE"
}
CodeStatusDescription
UNAUTHORIZED401Missing or invalid API key.
FORBIDDEN403Valid key but insufficient role.
INSUFFICIENT_SCOPES403Key does not have the required scope for this endpoint.
RATE_LIMITED429Too many requests. Check X-RateLimit-* headers.
VALIDATION_ERROR400Request body failed validation. See details array.
NOT_FOUND404Resource does not exist or is not in your tenant.
PLAN_LIMIT403Free plan limit reached for this resource.