Loading
Loading
Pictage / Docs / API
Programmatic access to workspaces, shoots, galleries, clients, photos, and webhooks. Create a token at Settings → API tokens. This page lists the routes that exist today. It does not invent endpoints.
https://pictage.ai/api/v1Authorization: Bearer pk_live_...Content-Type: application/json on writes.600 requests / 60 seconds per API token, fail-closed. Exhaustion returns 429 rate_limited. A limiter outage refuses the request rather than opening a scrape path. Retry-After is set when the durable limiter supplies it.
A token scoped to another workspace, a caller who is not a member, or another tenant's resource id returns 404 not_found with { "ok": false, "error": "not_found" } and no reason. A 403 would confirm the row exists. Intra-tenant role shortage (a viewer registering webhooks) stays 403 forbidden.
Generated from the same registry as the public OpenAPI 3.1 artifact at /docs/api/openapi-v1.json.
GET /auth/whoami · Token introspectionPOST /client-sessions · Exchange a portal token for a client sessionGET /workspaces · List workspacesGET /galleries · List galleriesPOST /galleries · Create a gallery from keepersGET /galleries/:id · Get a galleryGET /galleries/:id/photos · List gallery photosPOST /galleries/:id/favorites · Favorite a photoDELETE /galleries/:id/favorites · Unfavorite a photoGET /shoots · List shootsPOST /shoots · Create a shootGET /clients · List clientsPOST /clients · Create a clientGET /orders · List paid ordersGET /search · Unified cross-entity searchGET /webhook-endpoints · List legacy webhook endpointsPOST /webhook-endpoints · Register a legacy webhook (admin+)DELETE /webhook-endpoints/:id · Delete a legacy webhook (admin+)POST /webhooks/subscriptions · Subscribe a Zapier REST hook (admin+)DELETE /webhooks/subscriptions · Delete a Zapier REST hook (admin+)GET /webhook-endpoints/:id/deliveries · List delivery history for a webhook endpointPOST /webhook-deliveries/:id/replay · Replay a webhook delivery (admin+)POST /webhook-endpoints/:id/rotate-secret · Rotate a webhook endpoint signing secret (admin+)POST /photos · Start a single-shot uploadPOST /photos/:id/finalize · Finalize a single-shot uploadPOST /upload-sessions · Open a multipart upload sessionPOST /upload-sessions/:id/files · Register files on a sessionPOST /upload-sessions/:id/files/:fileId/parts/sign · Sign multipart part PUT URLsPOST /upload-sessions/:id/files/:fileId/parts/complete · Record a part ETagPOST /upload-sessions/:id/files/:fileId/complete · Assemble a multipart filePOST /upload-sessions/:id/files/:fileId/abort · Abort one filePOST /upload-sessions/:id/finalize · Close an upload sessionGET /upload-sessions/:id · Read a session and its filesPOST /upload-sessions/:id/resume · Get the resume manifest for a sessionPOST /upload-sessions/:id/pause · Pause an in-flight upload sessionPOST /upload-sessions/:id/unpause · Resume a paused upload sessionGET /mobile/dashboard · Mobile home-screen dashboardGET /shoots/:id · Get a shootPATCH /shoots/:id/shot-list · Tick or untick a shot-list itemPOST /ai/cull-jobs · Start a background cull jobGET /ai/jobs/:id · Poll an AI jobPOST /galleries/:id/publish · Publish a galleryGET /invoices · List invoicesGET /tasks · List tasksOne outbound system (API-10 consolidated the two that used to exist). Every event signs with X-Pictage-Signature. Verification recipes live at /docs/webhooks. Legacy /webhook-endpoints is a deprecated compatibility shim over the same system; prefer /webhooks/subscriptions. Every event type, including gallery.delivered and shoot.completed, now has a real emitter.
Request and response examples (pulled from route test fixtures) live in the repository at docs/api/v1.md. HTTP architecture: API_ARCHITECTURE.md.
Questions? Email support@pictage.ai.