Skip to content

API Endpoint Reference (1.5)

Tenovos has introduced version 1.5 to provide non-breaking improvements over previous versions.

Key Changes:

  • Authentication Standards now include OAuth2 code flow.
  • Client ID is no longer required to be passed when requesting an Authorization token using our Standard Auth from v1.4
  • New endpoints have been added and will continue to be added until v2 is generally available to all customers.
    • Adaptive Template endpoints
    • A new Get Asset endpoint with a simplified Response
    • A new Create Asset endpoint with simplified payloads for the Request and Response
    • A new Update Asset endpoint with simplified payloads for the Request and Response
    • Metadata Admin API endpoints for managing Attributes, Groups, and Templates
  • We've made some performance improvements to most endpoints
Languages
Servers
https://api.uat.tenovos.io/v1
https://api.tenovos.io/v1

ACTIONS

Invoke the Action API to retrieve information about invoked Actions.

Operations

ADAPTIVE TEMPLATES

Invoke the API to retrieve information about invoked Actions.

Operations

ASSETS

Invoke the Asset API to create, retrieve, manipulate, and share Assets. This API also provides operations to manage Asset relationships and download Asset content.

Operations

AUTHENTICATION

Invoke the Authentication API to generate, refresh, and revoke access tokens. An access token is required to perform any authorized API operation.

Operations

CDN (Coming Soon!)

Tenovos Content Delivery Network (CDN) - Coming Soon!

Tenovos CDN: Pull Zone Overview

Tenovos CDN provides global content acceleration and optimization through a pull zone architecture, ensuring that your assets are delivered to end users with maximum speed, reliability, and efficiency. A Content Delivery Network (CDN) works by caching static content—such as images, videos, and other media—on servers distributed across the globe. When an asset is requested, the CDN serves it from the nearest edge location, reducing load times and offloading traffic from the origin server, which in this case is Tenovos DAM.

A pull zone is the core mechanism that powers this system. It automatically fetches content from the origin the first time it is requested, then caches it at the edge. Subsequent requests are served directly from the CDN cache, improving response times and reducing bandwidth consumption.

Through the Tenovos CDN API, you can create, update, and manage pull zones programmatically. Pull zones support advanced features such as global edge caching, cache purging, bandwidth controls, and real-time performance statistics like cache hit rate and geographic request distribution. Optional optimization settings allow you to enhance performance further by enabling image compression, WebP and AVIF support, and content minification.

With just a few API calls, you can fully integrate high-performance content delivery into your Tenovos workflows—no complex infrastructure required.

Operations

COLLECTIONS

Invoke the Collection API to create, retrieve, edit, and delete Collections. Collections are used to group and catalog related Assets for quick access and consumption. Collections can be configured as:

  • private: Visible only to the user who created the Collection.
  • secured: Visible to users with.

When retrieving the Assets within a Collection, the requesting user will only see the Assets that the user has access to view. For example, a librarian may see all Assets within a Collection, but a general consumer user may only see a portion of those Assets, due to limited security access.

Operations

METADATA ATTRIBUTES

Invoke the Metadata Attributes API to retrieve Metadata Attributes, and to create, read, update, and delete Metadata Attribute definitions. Metadata Attributes come in varying types, including Text, Date, Controlled Vocabulary, Tabular, and Cascading, and can be assigned to Metadata Groups and Templates.

Admin Endpoints (NEW!): Create, read, update, and delete Metadata Attributes. These endpoints require the Metadata Management admin privilege.

Operations

METADATA GROUPS

Invoke the Metadata Groups API to create, read, update, and delete Metadata Groups. A Metadata Group organizes related Metadata Attributes together for use within a Metadata Template.

Admin Endpoints (NEW!): These endpoints require the Metadata Management admin privilege.

Operations

METADATA TEMPLATES

Invoke the Metadata Templates API to create, read, update, and delete Metadata Templates, and to apply Metadata definition changes. A Metadata Template defines a set of Metadata Attributes that, when assigned to an Asset, become available for population on that Asset.

Admin Endpoints (NEW!): Create, read, update, and delete Metadata Templates. These endpoints require the Metadata Management admin privilege.

Operations

METADATA VOCABULARIES

Invoke the Controlled Vocabularies API to create, retrieve, update, and delete Controlled Vocabularies used to constrain the values available to a Metadata Attribute.

Operations

(NEW!) List Controlled Vocabularies (Paginated)

Request

Retrieve a paginated, searchable list of controlled vocabularies for UI consumption. Response fields are lightweight by default (valueCount only); each vocabulary's values are returned per row via the include query parameter.

Defaults:

  • sortField defaults to name.
  • order defaults to asc.
  • from defaults to 0.
  • limit defaults to 100, maximum 100.
  • includeSystem defaults to false.
  • searchTerm, inUse, and include are unset by default, applying no filter.

Business Rules:

  • searchTerm is a case-insensitive partial match on vocabulary name. It is trimmed before use, so a blank or whitespace-only value is treated as if omitted.
  • order is matched case-insensitively — asc, ASC, and Asc are equivalent.
  • limit above the maximum is silently capped, not rejected. limit=500 returns 100 results and no error. A limit below 1 or a non-integer limit is still rejected with a 400. This differs from GET /metadata/templates and GET /attributes, which reject an over-maximum limit with a 400.
  • inUse accepts a boolean (true/false — aggregate: used anywhere at all) or one of metadataAttributes, metadataCascades, metadataTables, metadataGroups, metadataTemplates, filtering to vocabularies referenced in that specific usage category. Omitted applies no filter. inUse is also a valid sortField value.
  • includeSystem defaults to false. When true, also returns platform-owned system vocabularies used internally by various platform functionalities, alongside user-created ones.
  • include is a comma-separated list; values is currently the only accepted entry. Omitted returns summary fields only (valueCount); include=values adds values[] to each row. Unlike GET /metadata/cascades, include=values does not clamp limit.
  • usedIn is shaped { metadataAttributes: [], metadataCascades: [], metadataTables: [], metadataGroups: [], metadataTemplates: [] }. A vocabulary's only direct reference is a dropdown attribute pointing at it, so metadataAttributes is the direct edge and the remaining categories are rollups through it. This shape is deliberately not the same as GET /attributes' usedIn, which carries a presets category and no metadataAttributes.

The user submitting the request must have the Metadata Template Management admin privilege.

Security
ApiKeyAuth or BasicAuth
Query
searchTermstring

Case-insensitive partial match on vocabulary name. Trimmed before use — a blank or whitespace-only value is treated as if omitted.

Example: searchTerm=usage
inUsestring

Filters by usage status. true/false filters on aggregate usage (referenced anywhere at all). One of metadataAttributes, metadataCascades, metadataTables, metadataGroups, metadataTemplates filters to vocabularies referenced in that specific usage category. Omitted applies no filter.

Enum"true""false""metadataAttributes""metadataCascades""metadataTables""metadataGroups""metadataTemplates"
Examples:

Returns only vocabularies backing at least one dropdown attribute.

inUse=metadataAttributes

Returns only vocabularies that reach at least one Template.

inUse=metadataTemplates

Returns only vocabularies that are not referenced anywhere at all.

inUse=false
includeSystemboolean

When true, also returns platform-owned system vocabularies used internally by various platform functionalities, in addition to user-created ones. Defaults to false.

Default false
frominteger>= 0

Result offset from which to start. Must be an integer of 0 or greater. Defaults to 0.

Default 0
Example: from=0
limitinteger[ 1 .. 100 ]

Number of results to return per page. Defaults to 100, minimum 1, maximum 100. A value above 100 is silently capped at 100 rather than rejected — the request succeeds and returns at most 100 results. A value below 1, or a non-integer, is rejected with a 400.

Default 100
Example: limit=100
sortFieldstring

Field to sort results by. Defaults to name.

Default "name"
Enum"name""createdEpoch""lastUpdatedEpoch""inUse""valueCount"
orderstring

Sort direction. Matched case-insensitively. Defaults to asc.

Default "asc"
Enum"asc""desc"
includestring

Comma-separated additional data to return per row. values is currently the only accepted entry, adding values[] to each result. Omitted returns summary fields only.

Value"values"
Example: include=values
Headers
Authorizationstringrequired

Provided by Authentication Token creation operation.

curl -i -X GET \
  'https://api.uat.tenovos.io/v1/metadata/vocabularies?searchTerm=usage&inUse=true&includeSystem=false&from=0&limit=100&sortField=name&order=asc&include=values' \
  -H 'Authorization: string' \
  -H 'X-API-Key: YOUR_API_KEY_HERE'

Responses

Paginated list of controlled vocabularies.

Bodyapplication/json
hitCountinteger

Total number of vocabularies matching the search criteria.

Example: 14
resultsArray of objects

Array of vocabulary summary objects.

Response
application/json
{ "hitCount": 14, "results": [ { … } ] }

Get Controlled Vocabularies

Request

Retrieve all the controlled vocabularies available to the current user.

In response, it will contain the list of metadata key/value pair and metadata definition attributes like id, name, type and search fields etc.

Average Response Time: 592ms

Security
ApiKeyAuth or BasicAuth
Headers
X-API-Keystringrequired

Customer-specific API key required to invoke API.

Authorizationstringrequired

Provided by Authentication Token creation operation

curl -i -X GET \
  https://api.uat.tenovos.io/v1/metadata/vocabulary \
  -H 'Authorization: string' \
  -H 'X-API-Key: YOUR_API_KEY_HERE'

Responses

The Response Body will be a JSON-formatted list including the following properties.

  • metadata: Vocabulary metadata
    • values: Key/Value list
      • valueId
      • valueName
    • searchable: Toggle searchability
  • metadataDefinitionId
  • metadataDefinitionName
  • metadataDefinitionSearchField: Map search field for this metadata definition
  • metadataDefinitionType: Metadata definition type
  • createdEpoch: Create time in milliseconds
  • lastUpdatedEpoch: Update time in milliseconds
Bodyapplication/jsonArray [
createdEpochinteger

Create time in milliseconds

Example: 1613877219787
customerIdstring

Customer Id

Example: "157167185123342"
lastUpdatedEpochinteger

Update time in milliseconds

Example: 1613877219787
metadataDefinitionIdstring(uuid)

Field ID

Example: "6c921f5c-24c2-40b9-8718-3ad2d4a6be54"
metadataDefinitionNamestring

Field Name

Example: "Colors"
metadataDefinitionSearchFieldstring

Map search field for this metadata definition

Example: "colors"
metadataDefinitionTypestring
Example: "controlledVocabulary"
metadataobject(ControlledVocabulary_metadata)

Vocabulary metadata

]
Response
application/json
[ { "createdEpoch": 1613877219787, "customerId": "157167185123342", "lastUpdatedEpoch": 1613877219787, "metadataDefinitionId": "6c921f5c-24c2-40b9-8718-3ad2d4a6be54", "metadataDefinitionName": "Colors", "metadataDefinitionSearchField": "colors", "metadataDefinitionType": "controlledVocabulary", "metadata": { … } } ]

Create Controlled Vocabulary

Request

Create a Controlled Vocabulary. User must have permission to create a controlled vocabulary.

Response will contain the object of the metadata definition attributes, such as id, name, type and search fields, etc.

Average Response Time: 585ms

Security
ApiKeyAuth or BasicAuth
Headers
X-API-Keystringrequired

Customer-specific API key required to invoke API.

Authorizationstringrequired

Provided by Authentication Token creation operation

Content-Typestringrequired
Value"application/json"
Bodyapplication/jsonrequired
namestring

Vocabulary Name

Example: "Color List"
valuesArray of strings

List of vocabulary values

Example: ["Red","Blue"]
curl -i -X POST \
  https://api.uat.tenovos.io/v1/metadata/vocabulary \
  -H 'Authorization: string' \
  -H 'Content-Type: application/json' \
  -H 'X-API-Key: YOUR_API_KEY_HERE' \
  -d '{
    "name": "Color List",
    "values": [
      "Red",
      "Blue"
    ]
  }'

Responses

The Response Body is a JSON object.

Bodyapplication/json
createdEpochinteger

Create time in milliseconds

Example: 1613877219787
customerIdstring

Customer Id

Example: "157167185123342"
lastUpdatedEpochinteger

Update time in milliseconds

Example: 1613877219787
metadataDefinitionIdstring(uuid)

Field ID

Example: "6c921f5c-24c2-40b9-8718-3ad2d4a6be54"
metadataDefinitionNamestring

Field Name

Example: "Colors"
metadataDefinitionSearchFieldstring

Map search field for this metadata definition

Example: "colors"
metadataDefinitionTypestring
Example: "controlledVocabulary"
metadataDocumentobject(ControlledVocabulary_metadata)

Vocabulary metadata

Response
application/json
{ "createdEpoch": 1613877219787, "customerId": "157167185123342", "lastUpdatedEpoch": 1613877219787, "metadataDefinitionId": "6c921f5c-24c2-40b9-8718-3ad2d4a6be54", "metadataDefinitionName": "Colors", "metadataDefinitionSearchField": "colors", "metadataDefinitionType": "controlledVocabulary", "metadataDocument": { "values": [ … ], "searchable": true } }

Get Controlled Vocabulary

Request

Retrieve the Controlled Vocabulary and its attributes by Controlled Vocabulary Id

In response, it will contain the list of metadata key/value pair and metadata definition attributes like id, name, type and search fields etc.

Average Response Time: 472ms

Security
ApiKeyAuth or BasicAuth
Path
idstringrequired

Specify a Controlled Vocabulary ID.

Headers
X-API-Keystringrequired

Customer-specific API key required to invoke API.

Authorizationstringrequired

Provided by Authentication Token creation operation

curl -i -X GET \
  'https://api.uat.tenovos.io/v1/metadata/vocabulary/{id}' \
  -H 'Authorization: string' \
  -H 'X-API-Key: YOUR_API_KEY_HERE'

Responses

The Response Body will be a JSON object

Bodyapplication/json
createdEpochinteger

Create time in milliseconds

Example: 1613877219787
customerIdstring

Customer Id

Example: "157167185123342"
lastUpdatedEpochinteger

Update time in milliseconds

Example: 1613877219787
metadataDefinitionIdstring(uuid)

Field ID

Example: "6c921f5c-24c2-40b9-8718-3ad2d4a6be54"
metadataDefinitionNamestring

Field Name

Example: "Colors"
metadataDefinitionSearchFieldstring

Map search field for this metadata definition

Example: "colors"
metadataDefinitionTypestring
Example: "controlledVocabulary"
metadataDocumentobject(ControlledVocabulary_metadata)

Vocabulary metadata

Response
application/json
{ "createdEpoch": 1613877219787, "customerId": "157167185123342", "lastUpdatedEpoch": 1613877219787, "metadataDefinitionId": "6c921f5c-24c2-40b9-8718-3ad2d4a6be54", "metadataDefinitionName": "Colors", "metadataDefinitionSearchField": "colors", "metadataDefinitionType": "controlledVocabulary", "metadataDocument": { "values": [ … ], "searchable": true } }

Delete Controlled Vocabulary

Request

Delete a Controlled Vocabulary.

Average Response Time: 130ms

Security
ApiKeyAuth or BasicAuth
Path
idstringrequired

Specify a Controlled Vocabulary ID.

Headers
X-API-Keystringrequired

Customer-specific API key required to invoke API.

Authorizationstringrequired

Provided by Authentication Token creation operation

curl -i -X DELETE \
  'https://api.uat.tenovos.io/v1/metadata/vocabulary/{id}' \
  -H 'Authorization: string' \
  -H 'X-API-Key: YOUR_API_KEY_HERE'

Responses

Successful operation

Bodyapplication/json
statusstring
Example: "success"
messagestring
Example: "Detailed Message"
Response
application/json
{ "status": "success", "message": "Metadata Definition delete operation succeeded" }

Update Controlled Vocabulary

Request

Update a Controlled Vocabulary. User must have permission to update a controlled vocabulary.

In response, it will contain the object of metadata definition attributes like id, name, type and search fields etc.

Average Response Time: 1462ms (Add Controlled Vocabulary (CV) value) Average Response Time: 716ms (Update a CV value )

Security
ApiKeyAuth or BasicAuth
Path
idstringrequired

Specify a Controlled Vocabulary ID.

Headers
X-API-Keystringrequired

Customer-specific API key required to invoke API.

Authorizationstringrequired

Provided by Authentication Token creation operation

Content-Typestringrequired
Value"application/json"
Bodyapplication/jsonrequired

The Request Body will be a JSON-formatted object including the following properties. Each property here is an operation. All of these operations can be applied in a single request. After updating the Controlled Vocabulary, execute /metadata/apply POST request to apply the new changes.

namestring

New name of the Controlled Vocabulary

Example: "Hooli Employees"
addArray of strings

JSON Array with new values to add into the Controlled Vocabulary

Example: ["Jared Dunn"]
updateArray of objects(ControlledVocabularyUpdateRequest_update)

Payload to update existing values by their IDs

Example: [{"valueId":"2926d594-9c03-4aa1-91a8-76a0b6e67e4f","valueName":"Richard Hendricks"}]
deleteArray of strings

JSON array with the value IDs to delete from Controlled Vocabulary

Example: ["e1dd92fa-ed3a-4038-b837-c7f4d6395f16"]
curl -i -X PATCH \
  'https://api.uat.tenovos.io/v1/metadata/vocabulary/{id}' \
  -H 'Authorization: string' \
  -H 'Content-Type: application/json' \
  -H 'X-API-Key: YOUR_API_KEY_HERE' \
  -d '{
    "name": "Hooli Employees"
  }'

Responses

The response is a JSON-formatted object keyed by the operation(s) performed. Each key — name, add, update, or delete — maps to the updated Controlled Vocabulary definition. When multiple operations are submitted in a single request, the response contains a key for each operation performed.

Bodyapplication/json
nameobject

Returned when the Controlled Vocabulary name is changed (name operation in the request).

addobject

Returned when new values are added (add operation in the request).

updateobject

Returned when existing values are updated (update operation in the request).

deleteobject

Returned when values are deleted (delete operation in the request).

Response
application/json
{ "name": { "metadataDefinitionId": "83559f3a-93a8-4eba-a709-0bca6497450e", "metadataDefinitionName": "Hooli Employees", "metadataDefinitionSearchField": "hooli_employees", "metadataDefinitionType": "controlledVocabulary", "customerId": "1739271540099", "createdBy": "dc63db1b-1e63-43bc-877e-418931b6895c", "createdEpoch": 1781815426034, "lastUpdatedBy": "dc63db1b-1e63-43bc-877e-418931b6895c", "lastUpdatedEpoch": 1781815985807, "metadataDocument": { … }, "securityTemplateIds": [] } }

METADATA CASCADES

Invoke the Metadata Cascades API to create, retrieve, update, and delete Cascading Attributes, a Metadata Attribute type whose available values depend on the value selected in a parent Attribute.

Operations

METADATA TABLES

Invoke the Metadata Tables API to create, retrieve, update, and delete Tabular Attributes, a Metadata Attribute type that stores structured, multi-column data on an Asset.

Operations

REQUESTS

Invoke these API's to create new Requests and manage existing Requests.

Operations

SECURITY ROLES

Invoke the Security Roles API to retrieve, create, update, and delete Security Roles, and to retrieve the Permissions and Privileges that can be assigned to a Role to control what a user can see and do across the platform.

Operations

SECURITY TEMPLATES

Invoke the Security Templates API to retrieve, create, update, and delete Security Templates. A Security Template combines Security Roles and User Groups to define access to Assets and other objects in the platform.

Operations

SECURITY GROUPS

Invoke the Security User Groups API to retrieve, create, update, and delete Security User Groups used to organize users for the purpose of assigning security access.

Operations

USERS

Invoke the User API to retrieve User profile information.

Operations

STORY BOARDS

Invoke the Story Boards API to retrieve and manage Story Boards. Story Boards are curated content experiences that combine collections, saved searches, and other content blocks into a single shareable view.

Coming Soon: Additional endpoints for creating, updating, and deleting Story Boards.

Operations

WEBHOOKS

Tenovos Webhook Subscriptions

For more information about our Webhooks, see the Webhook section of our Developer Portal

Operations

RIGHTS MANAGEMENT

Invoke the Rights Management API to manage rights-management associations between Projects, Agreements, Entities, and Rights.

Operations

PROOFING

Operations