API overview
Everything the hub does goes through the same HTTP API, so anything you can do on screen you can do from your own systems: push product data from an ERP, pull locations into a WMS, export tag data every night, react to tags moving in real time.
Base URL
https://hub.titanrfid.com/api/v1
Requests and responses are JSON (Content-Type: application/json) unless a page says otherwise. CSV import uses multipart/form-data, and CSV export and the event stream return their own content types.
Authentication
Create an API key in the hub under Settings → API keys (admins only; see Users, API keys and audit log). Send it as a bearer token on every request:
curl https://hub.titanrfid.com/api/v1/auth/me \
-H "Authorization: Bearer tk_9f2c…"
{ "id": "00000000-0000-0000-0000-000000000000", "email": "", "role": "operator", "viaKey": true }
viaKey: true confirms you're authenticated with a key. API keys are tied to your organisation, not a person, so id and email are empty.
Keep keys out of source code and out of anything that runs in a browser. Anyone holding a key can act on your account until the key is revoked.
What a key can do
An API key has operator permissions:
| API key | |
|---|---|
| Read everything: tags, data, readers, zones, inventory, assets, alerts, the live stream | ✅ |
| Write operational data: tag data, columns, imports, zones, antennas, start/stop, assets, alerts | ✅ |
| Manage users, API keys, the audit log or billing | ❌ 403 |
A request that needs more than operator permissions is refused with 403 Forbidden.
Conventions
- IDs are UUIDs, such as
"6f1c2b0e-8d1a-4e8f-9a51-3b6f0e2d7c44". - Timestamps are RFC 3339, in UTC, and may include fractional seconds:
"2026-10-10T14:03:22.418Z". Send them the same way. - EPCs are hexadecimal strings. Titan stores them in uppercase. The tag endpoints accept any case and convert it for you. The asset and correlation endpoints take the EPC exactly as you send it, so always send EPCs in uppercase to be safe.
- Field keys are lowercase letters, digits and underscores (
unit_price). If you send a name likeUnit Price, Titan converts it tounit_price. - Optional fields that have no value are usually left out of responses rather than sent as
null. Treat a missing field andnullthe same. - Lists are returned whole, newest or most relevant first, with a fixed maximum per endpoint (stated on each page). There's no pagination. Use the filters each endpoint offers, or export for complete data.
Your first integration
Push data for a tag, read it back, and see where the tag is:
KEY="tk_…"
API="https://hub.titanrfid.com/api/v1"
# 1. Attach data to an EPC (creates the fields if they don't exist yet)
curl -X PUT "$API/tags/E2801160600002084F1A3C21/data" \
-H "Authorization: Bearer $KEY" -H "Content-Type: application/json" \
-d '{"sku": "BRK-2210", "description": "Brake caliper, front left", "qty": "12"}'
# 2. Read it back
curl "$API/tags/E2801160600002084F1A3C21/data" -H "Authorization: Bearer $KEY"
# 3. Find it in the tag list, with its current zone
curl "$API/tags?q=BRK-2210" -H "Authorization: Bearer $KEY"
Reference
| Area | Endpoints |
|---|---|
| Tags and tag data | Tag list, per-tag data and history, columns, CSV import/export, deleting tags |
| Readers and antennas | Reader status, start/stop, antenna-to-zone mapping and RF settings, claiming |
| Zones and inventory | Zones, what's in each zone now |
| Assets | Assets, check-out/in, timeline, linking tags |
| Alerts | Listing, acknowledging and resolving alerts |
| Live events | A real-time stream of tag reads and zone moves |
| Account | Who you are, your plan and usage |
| Errors and limits | Error format, status codes, rate limits, size limits |
The hub also calls a few endpoints that aren't listed here, such as the ones behind the Dashboard. They're shaped around the screens and may change without notice, so don't build on them.