Invoke the Action API to retrieve information about invoked Actions.
- API v1.5 Documentation
- Payload Reference
- (NEW!) Create Security User Group
API Endpoint Reference (1.5)
Tenovos has introduced version 1.5 to provide non-breaking improvements over previous versions.
Key Changes:
- Authentication Standards now include OAuth2 code flow.
- Client ID is no longer required to be passed when requesting an Authorization token using our Standard Auth from v1.4
- New endpoints have been added and will continue to be added until v2 is generally available to all customers.
- Adaptive Template endpoints
- A new Get Asset endpoint with a simplified Response
- A new Create Asset endpoint with simplified payloads for the Request and Response
- A new Update Asset endpoint with simplified payloads for the Request and Response
- Metadata Admin API endpoints for managing Attributes, Groups, and Templates
- We've made some performance improvements to most endpoints
Tenovos Content Delivery Network (CDN) - Coming Soon!
Tenovos CDN: Pull Zone Overview
Tenovos CDN provides global content acceleration and optimization through a pull zone architecture, ensuring that your assets are delivered to end users with maximum speed, reliability, and efficiency. A Content Delivery Network (CDN) works by caching static content—such as images, videos, and other media—on servers distributed across the globe. When an asset is requested, the CDN serves it from the nearest edge location, reducing load times and offloading traffic from the origin server, which in this case is Tenovos DAM.
A pull zone is the core mechanism that powers this system. It automatically fetches content from the origin the first time it is requested, then caches it at the edge. Subsequent requests are served directly from the CDN cache, improving response times and reducing bandwidth consumption.
Through the Tenovos CDN API, you can create, update, and manage pull zones programmatically. Pull zones support advanced features such as global edge caching, cache purging, bandwidth controls, and real-time performance statistics like cache hit rate and geographic request distribution. Optional optimization settings allow you to enhance performance further by enabling image compression, WebP and AVIF support, and content minification.
With just a few API calls, you can fully integrate high-performance content delivery into your Tenovos workflows—no complex infrastructure required.
Invoke the Collection API to create, retrieve, edit, and delete Collections. Collections are used to group and catalog related Assets for quick access and consumption. Collections can be configured as:
- private: Visible only to the user who created the Collection.
- secured: Visible to users with.
When retrieving the Assets within a Collection, the requesting user will only see the Assets that the user has access to view. For example, a librarian may see all Assets within a Collection, but a general consumer user may only see a portion of those Assets, due to limited security access.
Invoke the Metadata API to manage Metadata Attributes, Groups, and Templates. A Metadata Template defines a set of Metadata Attributes of varying types, including Text, Date, Controlled Vocabulary, Tabular, and Cascading Attributes. When a Metadata Template is assigned to a new Asset, the corresponding Metadata Attributes will be available for population on the Asset.
Admin Endpoints (NEW!): Create, read, update, and delete Metadata Attributes and Metadata Groups. These endpoints require the Metadata Management admin privilege.
Request
Retrieve a paginated, searchable list of the security user groups configured for the authenticated customer. This endpoint only ever operates on type: security groups — there is no way to request channel groups through it.
Defaults:
sortFielddefaults togroupName.orderdefaults toasc.fromdefaults to0.limitdefaults to100(clamped to100if a higher value is supplied).
Business Rules:
searchTermis a case-insensitive substring match on group name. Special LIKE characters (%,_,\) are treated as literal text, not wildcards.- There is no
typequery parameter. Every group returned istype: security. Sending atypeparameter of any value — includingsecurity— is rejected with400; it is not silently ignored, and it never changes what's returned. Channel groups are created and managed exclusively by the Publishing flow under a separate privilege, never through this API.
The user submitting the request must have the User Management privilege.
- https://api.uat.tenovos.io/v1/security/user-groups
- https://api.tenovos.io/v1/security/user-groups
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
- Payload
curl -i -X GET \
'https://api.uat.tenovos.io/v1/security/user-groups?searchTerm=string&sortField=groupName&order=asc&from=0&limit=100' \
-H 'Authorization: string' \
-H 'X-API-Key: YOUR_API_KEY_HERE'{ "groups": [ { … } ], "pageInfo": { "from": 0, "limit": 100, "total": 1, "hasNextPage": false } }
Request
Create a security user group for the authenticated customer. name is the only accepted field.
Business Rules:
namemust be 1-255 characters after trimming, and unique per customer, case-insensitively — enforced by a database constraint, so a race between two concurrent creates for the same name always resolves to exactly one winner and a409for the loser.typeis not an accepted input field at all. Sending it, with any value, is rejected with400— the created group is alwaystype: security; this is reflected in the response but can never be set by the caller.
The user submitting the request must have the User Management privilege.
JSON object defining the group to create. name is the only accepted field.
- https://api.uat.tenovos.io/v1/security/user-groups
- https://api.tenovos.io/v1/security/user-groups
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
- Payload
curl -i -X POST \
https://api.uat.tenovos.io/v1/security/user-groups \
-H 'Authorization: string' \
-H 'Content-Type: application/json' \
-H 'X-API-Key: YOUR_API_KEY_HERE' \
-d '{
"name": "Pied Piper Engineering"
}'Created. The response body is the new group in the same shape as GET /security/user-groups/{id} — a brand-new group always has userCount: 0 and usedIn.securityTemplates: [].
Unique ID of the group. Opaque string — ids are generated as UUIDs, but this isn't a format guarantee.
Always security for a group returned by this API. Response-only — never an accepted input field on create or update.
User-profile id of the group's creator. null if the row has no recorded author.
ISO 8601 creation date, derived from createdEpoch.
User-profile id of the last user to update the group. null if the row has no recorded author.
{ "id": "group-pied-piper-engineering", "name": "Pied Piper Engineering", "type": "security", "userCount": 0, "usedIn": { "securityTemplates": [] }, "createdBy": "dc63db1b-1e63-43bc-877e-418931b6895c", "createdEpoch": 1773070355217, "createdDate": "2026-03-09T15:32:35.217Z", "lastUpdatedBy": "dc63db1b-1e63-43bc-877e-418931b6895c", "lastUpdatedEpoch": 1773070355217, "lastUpdatedDate": "2026-03-09T15:32:35.217Z" }
Request
Create multiple security user groups for the authenticated customer in a single all-or-nothing batch. Either every name in the batch is created, or none are — there is no partial success.
Business Rules:
namesmust be a non-empty array of strings, maximum 50 entries per request. A batch over 50 names is rejected outright with a plain400("maximum 50 user groups are allowed in a request") without itemizing individual names — this structural check runs before any per-name validation.- Each name follows the same rules as single-create (1-255 characters after trim).
- A name repeated within the same request (case-insensitively, after trimming) is rejected — it is not silently de-duplicated.
- All entries in one batch share the same
createdEpoch/createdBy(one request, one actor, one timestamp), and each gets its own id. - There is no
Locationresponse header on this endpoint, since it creates multiple resources.
The user submitting the request must have the User Management privilege.
JSON object listing the group names to create. Required: names — non-empty array, maximum 50 entries.
Non-empty array of group names to create. Maximum 50 entries per request. Each name follows the same rules as single-create (1-255 characters after trimming). A name repeated within the same request (case-insensitively, after trimming) is rejected — it is not silently de-duplicated.
- https://api.uat.tenovos.io/v1/security/user-groups/bulk
- https://api.tenovos.io/v1/security/user-groups/bulk
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
- Payload
curl -i -X POST \
https://api.uat.tenovos.io/v1/security/user-groups/bulk \
-H 'Authorization: string' \
-H 'Content-Type: application/json' \
-H 'X-API-Key: YOUR_API_KEY_HERE' \
-d '{
"names": [
"Hooli Corporate",
"Hooli EMEA",
"Hooli APAC"
]
}'{ "created": [ { … }, { … }, { … } ] }
Invoke the Story Boards API to retrieve and manage Story Boards. Story Boards are curated content experiences that combine collections, saved searches, and other content blocks into a single shareable view.
Coming Soon: Additional endpoints for creating, updating, and deleting Story Boards.
Tenovos Webhook Subscriptions
For more information about our Webhooks, see the Webhook section of our Developer Portal