TRACE API

Connect TRACE to the programs you already use.

Read your technicians, certifications, compliance deadlines, jobs, reports and records from another program — and, if your safety or HR system already holds the records, keep TRACE in step with it.

1. Make a key

Your firm's primary contact makes keys in TRACE under Account → API. Give the key a name, tick only what the other program needs (reading is per record type; writing is off unless you tick it), and optionally set an expiry and the addresses it may call from. The key is shown once — copy it then. TRACE keeps only a scrambled fingerprint of it, so nobody can show it to you again; if it is lost, revoke it and make another. Revoking takes effect on the next call.

2. Call an endpoint

Send the key in the Authorization header. Every answer is JSON.

curl https://www.tracendt.com/api/v1/technicians \
  -H "Authorization: Bearer trc_ab12cd34ef_…"

GET /api/v1/me tells you which key you are using, for which firm, and what it may do.

3. Page through a list

Lists come back 100 records at a time (ask for up to 200 with ?limit=), oldest id first. Each page says whether there is another. Keep asking with the cursor it gives you until has_more is false — a list is never cut short without saying so.

{ "data": [ … ], "has_more": true, "next_cursor": "5f0c…" }

GET /api/v1/technicians?cursor=5f0c…

Documents come with a link to the file that works for five minutes; field reports with a link to their PDF that works for ten. Ask again for a fresh link.

4. Handle the rate limit

Each key may make 600 calls every 15 minutes. Past that, TRACE answers 429 with a Retry-After header in seconds — wait that long and carry on. If a regular sync needs more, ask us and we can raise a key's limit.

5. Keep TRACE in step with your safety or HR system

If your firm already keeps safety or HR records elsewhere, your primary contact can mark that module under Account → Modules in Another Tool. TRACE then hides the module's menu, dashboard cards and reminders; nothing is deleted, and your bill does not change. Then send records in with a key that has write permission. Each write is keyed on your system's id, so sending the same record again updates it rather than making a copy:

curl -X POST https://www.tracendt.com/api/v1/safety/trainings \
  -H "Authorization: Bearer trc_ab12cd34ef_…" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 7d2e…" \
  -d '{"external_source": "safety-system", "external_id": "TR-1001",
      "fields": {"training_type": "Radiation Safety", "completed_on": "2026-09-01"},
      "refs": {"technician_external_id": "EMP-42"}}'
  • A new record answers 201, an update 200. Send technicians first; later records can name them by your id (technician_external_id) or by TRACE's.
  • TRACE checks each record the way its own forms do. Anything it cannot accept answers 422 with a list of problems.
  • A record that has been signed or reviewed in TRACE is final: a write to it answers 409, and it changes only by a revision made in TRACE.
  • An Idempotency-Key header is optional. A retry with the same key and body within a day gets the first answer back instead of acting twice.

What you can reach

PathRecordsCan write
/api/v1/techniciansTechniciansYes
/api/v1/certificationsCertificationsYes
/api/v1/compliance-itemsCompliance itemsRead only
/api/v1/companiesCompaniesRead only
/api/v1/jobsJobs (Projects add-on)Read only
/api/v1/field-reportsField reports (Projects add-on)Read only
/api/v1/documentsDocumentsRead only
/api/v1/safety/trainingsSafety trainings (Safety add-on)Yes
/api/v1/safety/dosimetryDosimetry readings (Safety add-on)Yes
/api/v1/safety/sourcesSource inventory (Safety add-on)Yes
/api/v1/safety/source-logSource log (Safety add-on)Yes
/api/v1/safety/jsasJob safety analyses (Safety add-on)Yes
/api/v1/hr/credentialsHR credentials (HR Records add-on)Yes
/api/v1/hr/screeningsMedical and screening records (HR Records add-on)Yes
/api/v1/hr/vision-examsVision exams (HR Records add-on)Yes
/api/v1/hr/time-offTime off (HR Records add-on)Yes

Every field, type and answer is in the OpenAPI description: /api/v1/openapi.json.

How your data is protected

  • A key sees only its own firm's records, and only the kinds of record it was given.
  • Every call is recorded with the key, what it asked for, how many records came back and the address it came from. Unusual volume is flagged to your firm and to us.
  • Every change made through the API is in your audit trail, with the key as the one who made it.
  • Keys of a deactivated account are refused. The shared demo workspace cannot make keys.

More on how TRACE is secured. Using the API is covered by our Terms of Service.