Quick Start
1
Get API Credentials
Generate your API key in the Rhombus Console. Choose token-based (simpler) or certificate-based (more secure) authentication.
2
Make Your First Request
Test your connection with a simple API call. All requests go to
https://api2.rhombussystems.com — or https://api2.eu.rhombussystems.com for EU organizations — with your API key in the headers.3
Explore the API Reference
Browse 900+ endpoints to discover capabilities for your integration.
4
Join the Community
Get help and share experiences at rhombus.community.
Integration Options
OpenAPI 3.0 Specification: Download our machine-readable spec for automated client generation.
- HTTP Client
- Generated SDKs
- cURL Examples
JavaScript
What You Can Build
Camera Management
Stream live video, retrieve recordings, manage camera settings, and access metadata
Access Control
Manage doors, users, credentials, and access events across your facilities
Environmental Monitoring
Monitor temperature, humidity, air quality, and other environmental conditions
Analytics & Insights
Access AI-powered analytics, people counting and object detection
Event Management
Create custom workflows, manage notifications, and respond to security events
Device Administration
Configure devices, manage firmware updates, and monitor system health
Authentication & Base URL
All API requests use your region’s base URL:Not sure which region your organization is in? Check your console URL —
console.eu.rhombussystems.com means EU. See API Regions (US & EU) for details.API tokens vs federated tokens
Rhombus has two kinds of token, and they are not interchangeable:- API token: the key above. It is long-lived, carries its role’s permissions, and is sent as
x-auth-scheme: api-token+x-auth-apikey. Keep it on your server. It works against the Rhombus cloud API and cloud media, but devices on your local network never accept it. - Federated token: a short-lived token you mint with your API token by calling
POST /api/org/generateFederatedSessionToken. It inherits the minting key’s role (optionally limited to one device withdeviceUUid), expires afterdurationSec, and is sent asx-auth-scheme: federated-token+x-auth-ft, as headers or as query parameters on media URLs. Use it anywhere you can’t safely put your API key: browsers, video players, and streaming directly from devices on your LAN.
Community & Support
Developer Community
Get help from Rhombus engineers and fellow developers. Share integration examples, troubleshoot issues, and learn best practices.
Rhombus Console
Manage API keys and configure your Rhombus platform. Pro tip: Use Chrome DevTools to inspect network requests for implementation hints.
Always Up to Date: This documentation is generated directly from our production API specification and refreshes automatically whenever the API changes.