Skip to content

API Endpoint Reference (1.5)

Tenovos has introduced version 1.5 to provide non-breaking improvements over previous versions.

Key Changes:

  • Authentication Standards now include OAuth2 code flow.
  • Client ID is no longer required to be passed when requesting an Authorization token using our Standard Auth from v1.4
  • New endpoints have been added and will continue to be added until v2 is generally available to all customers.
    • Adaptive Template endpoints
    • A new Get Asset endpoint with a simplified Response
    • A new Create Asset endpoint with simplified payloads for the Request and Response
    • A new Update Asset endpoint with simplified payloads for the Request and Response
    • Metadata Admin API endpoints for managing Attributes, Groups, and Templates
  • We've made some performance improvements to most endpoints
Languages
Servers
https://api.uat.tenovos.io/v1
https://api.tenovos.io/v1

ACTIONS

Invoke the Action API to retrieve information about invoked Actions.

Operations

ADAPTIVE TEMPLATES

Invoke the API to retrieve information about invoked Actions.

Operations

ASSETS

Invoke the Asset API to create, retrieve, manipulate, and share Assets. This API also provides operations to manage Asset relationships and download Asset content.

Operations

AUTHENTICATION

Invoke the Authentication API to generate, refresh, and revoke access tokens. An access token is required to perform any authorized API operation.

Operations

CDN (Coming Soon!)

Tenovos Content Delivery Network (CDN) - Coming Soon!

Tenovos CDN: Pull Zone Overview

Tenovos CDN provides global content acceleration and optimization through a pull zone architecture, ensuring that your assets are delivered to end users with maximum speed, reliability, and efficiency. A Content Delivery Network (CDN) works by caching static content—such as images, videos, and other media—on servers distributed across the globe. When an asset is requested, the CDN serves it from the nearest edge location, reducing load times and offloading traffic from the origin server, which in this case is Tenovos DAM.

A pull zone is the core mechanism that powers this system. It automatically fetches content from the origin the first time it is requested, then caches it at the edge. Subsequent requests are served directly from the CDN cache, improving response times and reducing bandwidth consumption.

Through the Tenovos CDN API, you can create, update, and manage pull zones programmatically. Pull zones support advanced features such as global edge caching, cache purging, bandwidth controls, and real-time performance statistics like cache hit rate and geographic request distribution. Optional optimization settings allow you to enhance performance further by enabling image compression, WebP and AVIF support, and content minification.

With just a few API calls, you can fully integrate high-performance content delivery into your Tenovos workflows—no complex infrastructure required.

Operations

COLLECTIONS

Invoke the Collection API to create, retrieve, edit, and delete Collections. Collections are used to group and catalog related Assets for quick access and consumption. Collections can be configured as:

  • private: Visible only to the user who created the Collection.
  • secured: Visible to users with.

When retrieving the Assets within a Collection, the requesting user will only see the Assets that the user has access to view. For example, a librarian may see all Assets within a Collection, but a general consumer user may only see a portion of those Assets, due to limited security access.

Operations

METADATA

Invoke the Metadata API to manage Metadata Attributes, Groups, and Templates. A Metadata Template defines a set of Metadata Attributes of varying types, including Text, Date, Controlled Vocabulary, Tabular, and Cascading Attributes. When a Metadata Template is assigned to a new Asset, the corresponding Metadata Attributes will be available for population on the Asset.

Admin Endpoints (NEW!): Create, read, update, and delete Metadata Attributes and Metadata Groups. These endpoints require the Metadata Management admin privilege.

Operations

REQUESTS

Invoke these API's to create new Requests and manage existing Requests.

Operations

SECURITY

Invoke the Security API to manage Security Templates, Security Roles, Security User Groups, and the Permissions and Privileges that control what a user can see and do across the platform.

Operations

(NEW!) List Security Roles (Paginated)

Request

Retrieve a paginated, searchable list of the security roles configured for the authenticated customer.

Defaults:

  • sortField defaults to roleName.
  • order defaults to asc.
  • from defaults to 0.
  • limit defaults to 100 (clamped to 100 if a higher value is supplied).

Business Rules:

  • searchTerm is a case-insensitive substring match on role name. Special LIKE characters (%, _, \) are treated as literal text, not wildcards.
  • consentForm is not included on list items — it only appears on the get-by-id detail.

The user submitting the request must have the Role Management privilege.

Security
ApiKeyAuth or BasicAuth
Query
searchTermstring

Case-insensitive substring match on role name. Special LIKE characters (%, _, \) are treated as literal text.

sortFieldstring

Field to sort results by. Defaults to roleName.

Default "roleName"
Enum"roleName""privilegeCount""userCount""createdEpoch""lastUpdatedEpoch"
orderstring

Sort direction. Defaults to asc.

Default "asc"
Enum"asc""desc"
frominteger

Result offset from which to start. Defaults to 0.

Default 0
Example: from=0
limitinteger

Number of results to return per page. Defaults to 100, maximum 100 (values above 100 are silently clamped).

Default 100
Example: limit=100
Headers
X-API-Keystringrequired

Customer-specific API key required to invoke API.

Authorizationstringrequired

Provided by Authentication Token creation operation.

curl -i -X GET \
  'https://api.uat.tenovos.io/v1/security/roles?searchTerm=string&sortField=roleName&order=asc&from=0&limit=100' \
  -H 'Authorization: string' \
  -H 'X-API-Key: YOUR_API_KEY_HERE'

Responses

Paginated list of security roles.

Bodyapplication/json
rolesArray of objects

Roles on this page.

pageInfoobject
Response
application/json
{ "roles": [ { … } ], "pageInfo": { "from": 0, "limit": 100, "total": 1, "hasNextPage": false } }

(NEW!) Create Security Role

Request

Create a security role for the authenticated customer.

Business Rules:

  • name must be 1-32 characters after trimming, and unique per customer, case-insensitively — enforced by a database constraint, so a race between two concurrent creates for the same name always resolves to exactly one winner and a 409 for the loser.
  • Any field not in {name, consentForm, privileges} is rejected with 400.

Defaults:

  • consentForm defaults to "". null is treated as absent.
  • privileges defaults to []. Entries are de-duplicated case-insensitively.

Validation:

  • Each privileges entry must be a syntactically valid UUID (400 if not), then must exist and be enabled in the customer's privilege catalog (422 if any id is unknown or disabled).

The user submitting the request must have the Role Management privilege.

Security
ApiKeyAuth or BasicAuth
Headers
X-API-Keystringrequired

Customer-specific API key required to invoke API.

Authorizationstringrequired

Provided by Authentication Token creation operation.

Content-Typestringrequired
Value"application/json"
Bodyapplication/jsonrequired

JSON object defining the role to create. Required: name. Optional: consentForm (defaults to ""), privileges (defaults to []).

namestringrequired

Display name of the role. 1-32 characters after trimming. Must be unique per customer, case-insensitively.

Example: "Compression Engineer"
consentFormstring

Consent text a user must accept to hold this role. Defaults to an empty string. null is treated as absent.

Example: "By accepting this role you agree to safeguard Pied Piper's proprietary middle-out compression algorithm and follow all platform security policies."
privilegesArray of strings(uuid)

Privilege ids to grant to the role. Defaults to []. De-duplicated case-insensitively. Each id must be a syntactically valid UUID and must exist and be enabled in the customer's privilege catalog.

Example: ["31bdde6b-1a2c-4d5e-8f90-1234567890ab"]
curl -i -X POST \
  https://api.uat.tenovos.io/v1/security/roles \
  -H 'Authorization: string' \
  -H 'Content-Type: application/json' \
  -H 'X-API-Key: YOUR_API_KEY_HERE' \
  -d '{
    "name": "Compression Engineer",
    "consentForm": "By accepting this role you agree to safeguard Pied Piper'\''s proprietary middle-out compression algorithm and follow all platform security policies.",
    "privileges": [
      "31bdde6b-1a2c-4d5e-8f90-1234567890ab"
    ]
  }'

Responses

Created. The response body is the new role in the same shape as GET /security/roles/{id} — a brand-new role always has userCount: 0 and usedIn.presets: [].

Bodyapplication/json
idstring(uuid)required

Unique ID of the role.

Example: "6c15af83-d4a9-4772-875a-1c8a2bb1688f"
namestringrequired

Display name of the role.

Example: "Creative Producer"
consentFormstring

Consent text a user must accept to hold this role.

Example: "By accepting this role you agree to uphold Pied Piper's brand and confidentiality guidelines when producing creative assets."
privilegeCountinteger

Number of privileges granted to the role.

Example: 2
privilegesArray of strings(uuid)

Flat array of permitted privilege ids only. Denied/unpermitted entries in the underlying role document are not surfaced.

Example: ["31bdde6b-1a2c-4d5e-8f90-1234567890ab","9e187a4e-cfe4-419e-8c6c-2509e4bf400b"]
userCountinteger

Number of users currently assigned this role.

Example: 12
usedInobject

Everywhere the role is currently referenced.

createdBystring or null(uuid)

User-profile id of the role's creator. null if the row has no recorded author.

Example: "dc63db1b-1e63-43bc-877e-418931b6895c"
createdEpochinteger

Unix timestamp (ms) of creation.

Example: 1734000000000
createdDatestring or null(date-time)

ISO 8601 creation date, derived from createdEpoch.

Example: "2024-12-12T12:00:00.000Z"
lastUpdatedBystring or null(uuid)

User-profile id of the last user to update the role. null if the row has no recorded author.

Example: "a5ae4577-8940-4ca9-bf2c-b1b65b4306ec"
lastUpdatedEpochinteger

Unix timestamp (ms) of the last update.

Example: 1755600000000
lastUpdatedDatestring or null(date-time)

ISO 8601 last-updated date, derived from lastUpdatedEpoch.

Example: "2025-08-19T12:00:00.000Z"
Response
application/json
{ "id": "7d8e9f0a-1b2c-3d4e-5f6a-7b8c9d0e1f2a", "name": "Compression Engineer", "consentForm": "By accepting this role you agree to safeguard Pied Piper's proprietary middle-out compression algorithm and follow all platform security policies.", "privilegeCount": 1, "privileges": [ "31bdde6b-1a2c-4d5e-8f90-1234567890ab" ], "userCount": 0, "usedIn": { "presets": [] }, "createdBy": "dc63db1b-1e63-43bc-877e-418931b6895c", "createdEpoch": 1773070355217, "createdDate": "2026-03-09T15:32:35.217Z", "lastUpdatedBy": "dc63db1b-1e63-43bc-877e-418931b6895c", "lastUpdatedEpoch": 1773070355217, "lastUpdatedDate": "2026-03-09T15:32:35.217Z" }

(NEW!) Get Security Role

Request

Retrieve the full detail of a single security role, including its consent form, granted privileges, and everywhere it's currently referenced.

The user submitting the request must have the Role Management privilege.

Security
ApiKeyAuth or BasicAuth
Path
idstring(uuid)required

The unique ID of the role. Opaque string, not necessarily a UUID.

Example: 6c15af83-d4a9-4772-875a-1c8a2bb1688f
Headers
X-API-Keystringrequired

Customer-specific API key required to invoke API.

Authorizationstringrequired

Provided by Authentication Token creation operation.

curl -i -X GET \
  https://api.uat.tenovos.io/v1/security/roles/6c15af83-d4a9-4772-875a-1c8a2bb1688f \
  -H 'Authorization: string' \
  -H 'X-API-Key: YOUR_API_KEY_HERE'

Responses

Full detail of the security role.

Bodyapplication/json
idstring(uuid)required

Unique ID of the role.

Example: "6c15af83-d4a9-4772-875a-1c8a2bb1688f"
namestringrequired

Display name of the role.

Example: "Creative Producer"
consentFormstring

Consent text a user must accept to hold this role.

Example: "By accepting this role you agree to uphold Pied Piper's brand and confidentiality guidelines when producing creative assets."
privilegeCountinteger

Number of privileges granted to the role.

Example: 2
privilegesArray of strings(uuid)

Flat array of permitted privilege ids only. Denied/unpermitted entries in the underlying role document are not surfaced.

Example: ["31bdde6b-1a2c-4d5e-8f90-1234567890ab","9e187a4e-cfe4-419e-8c6c-2509e4bf400b"]
userCountinteger

Number of users currently assigned this role.

Example: 12
usedInobject

Everywhere the role is currently referenced.

createdBystring or null(uuid)

User-profile id of the role's creator. null if the row has no recorded author.

Example: "dc63db1b-1e63-43bc-877e-418931b6895c"
createdEpochinteger

Unix timestamp (ms) of creation.

Example: 1734000000000
createdDatestring or null(date-time)

ISO 8601 creation date, derived from createdEpoch.

Example: "2024-12-12T12:00:00.000Z"
lastUpdatedBystring or null(uuid)

User-profile id of the last user to update the role. null if the row has no recorded author.

Example: "a5ae4577-8940-4ca9-bf2c-b1b65b4306ec"
lastUpdatedEpochinteger

Unix timestamp (ms) of the last update.

Example: 1755600000000
lastUpdatedDatestring or null(date-time)

ISO 8601 last-updated date, derived from lastUpdatedEpoch.

Example: "2025-08-19T12:00:00.000Z"
Response
application/json
{ "id": "6c15af83-d4a9-4772-875a-1c8a2bb1688f", "name": "Creative Producer", "consentForm": "By accepting this role you agree to uphold Pied Piper's brand and confidentiality guidelines when producing creative assets.", "privilegeCount": 2, "privileges": [ "31bdde6b-1a2c-4d5e-8f90-1234567890ab", "9e187a4e-cfe4-419e-8c6c-2509e4bf400b" ], "userCount": 12, "usedIn": { "presets": [ … ] }, "createdBy": "dc63db1b-1e63-43bc-877e-418931b6895c", "createdEpoch": 1734000000000, "createdDate": "2024-12-12T12:00:00.000Z", "lastUpdatedBy": "a5ae4577-8940-4ca9-bf2c-b1b65b4306ec", "lastUpdatedEpoch": 1755600000000, "lastUpdatedDate": "2025-08-19T12:00:00.000Z" }

PEOPLE

Invoke the User API to retrieve User profile information.

Operations

STORY BOARDS

Invoke the Story Boards API to retrieve and manage Story Boards. Story Boards are curated content experiences that combine collections, saved searches, and other content blocks into a single shareable view.

Coming Soon: Additional endpoints for creating, updating, and deleting Story Boards.

Operations

WEBHOOKS

Tenovos Webhook Subscriptions

For more information about our Webhooks, see the Webhook section of our Developer Portal

Operations

PROOFING

Operations