Skip to main content

Quick Start

1

Get API Credentials

Generate your API key in the Rhombus Console. Choose token-based (simpler) or certificate-based (more secure) authentication.
2

Make Your First Request

Test your connection with a simple API call. All requests go to https://api2.rhombussystems.com — or https://api2.eu.rhombussystems.com for EU organizations — with your API key in the headers.
3

Explore the API Reference

Browse 900+ endpoints to discover capabilities for your integration.
4

Join the Community

Get help and share experiences at rhombus.community.

Integration Options

OpenAPI 3.0 Specification: Download our machine-readable spec for automated client generation.
JavaScript

What You Can Build

Camera Management

Stream live video, retrieve recordings, manage camera settings, and access metadata

Access Control

Manage doors, users, credentials, and access events across your facilities

Environmental Monitoring

Monitor temperature, humidity, air quality, and other environmental conditions

Analytics & Insights

Access AI-powered analytics, people counting and object detection

Event Management

Create custom workflows, manage notifications, and respond to security events

Device Administration

Configure devices, manage firmware updates, and monitor system health

Authentication & Base URL

All API requests use your region’s base URL:
Not sure which region your organization is in? Check your console URL — console.eu.rhombussystems.com means EU. See API Regions (US & EU) for details.
Include authentication headers in every request:
Store your API key securely - it provides full access to your organization’s data.

API tokens vs federated tokens

Rhombus has two kinds of token, and they are not interchangeable:
  • API token: the key above. It is long-lived, carries its role’s permissions, and is sent as x-auth-scheme: api-token + x-auth-apikey. Keep it on your server. It works against the Rhombus cloud API and cloud media, but devices on your local network never accept it.
  • Federated token: a short-lived token you mint with your API token by calling POST /api/org/generateFederatedSessionToken. It inherits the minting key’s role (optionally limited to one device with deviceUUid), expires after durationSec, and is sent as x-auth-scheme: federated-token + x-auth-ft, as headers or as query parameters on media URLs. Use it anywhere you can’t safely put your API key: browsers, video players, and streaming directly from devices on your LAN.
See Streaming over LAN for the full comparison and examples.

Community & Support

Developer Community

Get help from Rhombus engineers and fellow developers. Share integration examples, troubleshoot issues, and learn best practices.

Rhombus Console

Manage API keys and configure your Rhombus platform. Pro tip: Use Chrome DevTools to inspect network requests for implementation hints.
Always Up to Date: This documentation is generated directly from our production API specification and refreshes automatically whenever the API changes.
Last modified on August 4, 2026