Overview
The Mobaro API is organised in endpoint groups, one per kind of record, all under https://app.mobaro.com/api/customers. This article is a map of every group: what you can read, what you can create, update or delete, and the limits that differ from the defaults. Use it to check whether the API can do what your integration needs before you build it.
New to the API? Start with Getting started with the Mobaro API. For every field and filter of each endpoint, open the interactive Mobaro API documentation.
At a glance |
|
Who can do this | A developer or integration tool with a Mobaro API key. Super Users, or a Role with Organization › Administrate, create keys. |
Where |
|
Works on | Public API, including the Power Automate connector |
Availability | Enabled per organization by Mobaro — ask your CSM |
How to read the overview
Most groups follow the same pattern. List is GET on the group, Get is GET with an ID, Create is POST, Update is PUT with an ID and Delete is DELETE with an ID. Other operations are named in the tables.
Read-only keys can only send GET requests. Any other method gets 403 Forbidden. A key that isn't Read-only acts as a Super User of your organization. See Creating and managing API keys.
Updates are partial. A PUT changes only the fields you send. A list field you send, such as a group's members, replaces the whole list.
Beta endpoints are marked Beta in the API documentation and may change. Test them again after Mobaro releases.
Limits: 10 requests per second per key; lists return up to 128 items per page. Exceptions are listed below. See Handling errors, rate limits, and retry logic.
People and competencies
Endpoint group | What you can do |
| List, get, create, update, delete. Get and update also accept the User's External ID or email. Create, update and delete share one limit of 2 requests per second across every API key, not just yours. |
| List, get, create, update, delete. POST |
| List, get, update the name, description, Users and User Groups, delete. No create, and a Role's permissions can't be read or changed. |
| List, get, create, update, delete. |
| List (including expired), get, create, update, delete. Certifications from a Certification Process can't be updated or deleted. |
Locations and assets
Endpoint group | What you can do |
| List, get, create, update, delete. POST |
| List, get, create, update, delete, POST |
| List, get, create, update, delete. |
| List, get, create, update, delete, POST |
Checklists, schedules and results
Endpoint group | What you can do |
| List and get (add |
| Get one Question Category by ID. There's no list. |
| List (up to 20 per page), get, POST |
| List and get only. |
| List (up to 31 days per request) and get. Create, update and delete Ad Hoc Slots only. See Ad Hoc Slots — setup and behavior. |
Assignments, notes and files
Endpoint group | What you can do |
| List, get, create, update (including state changes with |
| List and get, including each definition's states, categories and priorities. |
| List and get only. See Creating and managing Notes. |
| Get one file, POST |
| List, get, create, update, delete. |
| List, get, create, update, delete, and |
Operations and integrations
Endpoint group | What you can do |
| List, get, create, update, POST |
| List, create, update and delete. Update and delete identify the period in the request body. |
| Dispatches, queue times, hourly statistics and signed-in attendants for one Location, up to 31 days per request. POST external dispatches and queue times from other systems. |
|
|
| POST park attendance only. See Sending park attendance to Mobaro via the API. |
| List, create, update, delete webhook subscriptions. See Using webhooks in Mobaro. |
Mobaro's own web and app endpoints, such as other paths under /api/, aren't part of the public API. They can change at any time, and API keys don't work with them.
Best practices
Check this overview and the API documentation before you promise an integration: if an operation isn't listed, the API can't do it.
Use a Read-only key for integrations that only read, and a separate key for each integration.
Pace writes to Users and Location Groups to their lower limits, and retry after 429 Too Many Requests.
Avoid building on Beta endpoints for critical processes, or re-test them regularly.
Frequently asked questions
Is there an API call to close an assignment?
Yes. Send PUT /api/customers/assignments/{id} with a stateChange. For an Assignment with a definition, use the ID of one of its Final states. Don't use the deprecated /solve endpoint.
Results show questions as elements/XXXX. How do I get the question text?
Get the Checklist with GET /api/customers/checklists/{id}?includeContent=true&revision={revision}, using the Result's Checklist revision. See Pulling Results via the API.
Can I open and close rides through the API?
Yes, for Locations with Operational Logging: POST /api/customers/locations/open and /close. The current state is in each Location's operations field. See Utilizing Operational Logging.
Can I create Checklists or add comments to Assignments through the API?
No. The API can only change a Checklist's categories and folders, and has no Assignment comment endpoint. Comments can be added to files only.
Does the developer building our integration need to be a Super User?
No. The API key itself acts as a Super User of your organization. Creating the key needs Super User status or Organization › Administrate. See Creating and managing API keys.
