Getting Started (1.0.0)

Cincopa REST API V2 to get/set and manipulate assets and galleries

Cincopa REST API V2 is a simple set of REST based methods that allow you to access almost every aspect of your galleries and assets. Authentication is done with a simple api_token that can be created and deleted per app, set the permission level according to the needed level and exposure level.

V2 API was designed to be used:

  • in server-to-server scenario where the api_token and information is not exposed to the public, in such scenario the permissions level can allow write and delete.
  • in client-to-server scenario like javascript request from a public web page, in this scenario permission level will be set to read only which ensures the safety of your web app. This unique architecture eliminates the need of creating a "proxy" service that usually needed when working with a 3rd party API thus saving you time in integration.
Download OpenAPI description
Overview
Cincopa API Support support@cincopa.com
License MIT
Languages
Servers
Cincopa API
https://api.cincopa.com/v2/

General

This section offers foundational API endpoints essential for establishing and validating connections with the Cincopa platform. These endpoints are designed to ensure smooth integration and secure interactions between your application and Cincopa's services.

Key FunctionalitiesEndpointPurpose
Validate API Connection/ping.jsonThis endpoint allows you to confirm the validity and responsiveness of your API connection. By sending a request to /ping.json with your api_token, you can verify that your application is properly authenticated and can communicate effectively with Cincopa's servers.
Obtain a Temporary Token/token.get_temp.jsonIn scenarios where frontend applications require direct interaction with Cincopa's API, this endpoint provides a secure method to generate temporary tokens. These tokens facilitate client-to-server communications, enabling operations like updating galleries or assets directly from client-side code without exposing permanent credentials.
Operations

Validate API connection

Request

Verify the validity of your API credentials and confirm connectivity to the Cincopa platform. This endpoint checks if the provided api_token is valid and returns account/user metadata.

Endpoint: GET /ping.json

URL: https://api.cincopa.com/v2/ping.json

Query
api_tokenstringrequired

A unique key used for authentication. Must be a valid API key provided by the system. Without the valid api_token, the request will be rejected with a 403 Unauthorized error.

Example: api_token=abc12345
curl -i -X GET \
  'https://api.cincopa.com/v2/ping.json?api_token=abc12345'

Responses

Returns account and user details if the api_token is valid.

Bodyapplication/json
successboolean

Indicate whether the request was successful. true for success and false for failure.

Example: true
accemailstring

The email address associated with the account. Must be a valid email format

Example: "example@cincopa.com"
accidstring

A unique identifier for the account. Must be a unique string.

Example: "okGbyjhVW40d"
accid_numinteger

A numeric representation of the account ID. Must be a positive integer.

Example: "0"
permissionsstring

A list of permissions granted to the user. Follows a regex pattern-based permission system.

Example: "|asset.*|gallery.*|portal.*|webhook.*|live.*|token.*|account.read|"
pingstring

A sample response value used for testing connectivity. Fixed value.

Example: "pong"
runtimeinteger

The time taken to process the request. Measured in milliseconds.

Example: 77
useremailstring

The email address associated with the request. Must be a valid email address.

Example: "test@company.com"
useridstring

A unique identifier for the user. Must be a unique string.

Example: "ooGAyjfgW00d"
userid_numinteger

A numeric representation of the user ID. Must be a non-negative integer.

Example: "15786836"
Response
application/json
{ "success": true, "accemail": "example@cincopa.com", "accid": "okGbyjhVW40d", "accid_num": "0", "permissions": "|asset.*|gallery.*|portal.*|webhook.*|live.*|token.*|account.read|", "ping": "pong", "runtime": 77, "useremail": "test@company.com", "userid": "ooGAyjfgW00d", "userid_num": "15786836" }

Get a temporary token

Request

Use this method to get a temporary token that you can comfortably share in a front-end scenario. For example, if you've built a UI to update a gallery or asset and need to send an update request to Cincopa via JavaScript, the temporary token provides controlled access with usage limits.

You must first configure specific permissions (e.g., gallery.update or asset.update) for the temporary token to define its access and capabilities.

Endpoint: GET /token.get_temp.json

URL: https://api.cincopa.com/v2/token.get_temp.json

Query
api_tokenstringrequired

A unique key used for authentication. Must be a valid API key provided by the system. Without the valid api_token, the request will be rejected with a 403 Unauthorized error.

Example: api_token=abc12345
ttlstring

Time to live in seconds, after this time the token will expire. Leave empty for never expire.

Example: ttl=3600
permissionsstring

Limit this token to a specific set of permissions. Empty value means no permissions at all

Example: permissions=asset.read|gallery.*
ridstring

Limit this token to be able to update only a specific asset (rid). Empty value means that token can update any asset.

Example: rid=123456
fidstring

Limit this token to be able to update only a specific gallery (fid). Empty value means that token can update any gallery.

Example: fid=987654
sourceipstring

Limit this token to a specific client IP address. Any attempt to use this token from a different IP address will reject the call. Leave empty to not limit the token to a specific IP address.

Example: sourceip=192.168.1.1
curl -i -X GET \
  'https://api.cincopa.com/v2/token.get_temp.json?api_token=abc12345&fid=987654&permissions=asset.read%2Cgallery.*&rid=123456&sourceip=192.168.1.1&ttl=3600'

Responses

Returns a temporary authentication token if the provided api_token is valid. This token can be used for making authorized API requests within a limited scope.

Bodyapplication/json
successboolean

Indicates whether the request was successful. Accepts true for success and false for failure.

Example: true
runtimeinteger

The time taken to process the request, measured in milliseconds. Must be a non-negative integer.

Example: 0
tokenstring

A temporary authentication token. Must be a valid string.

Example: "string"
Response
application/json
{ "success": true, "runtime": 0, "token": "string" }

Assets

This section provides a comprehensive suite of methods for managing assets within your account. The Assets API enables developers to efficiently upload, organize, modify, and retrieve digital assets, ensuring seamless integration into applications, websites, or media platforms.

Whether you're handling large media libraries, automating asset management, or implementing structured metadata, this API offers precise control over asset creation, metadata customization, categorization, and retrieval, enhancing workflow efficiency and content organization.

Key FunctionalitiesEndpointPurpose
List Assets/asset.list.jsonGet a list of assets in the account; those assets can be added to any gallery. Use search to locate specific assets or use reference_id to locate by reference_id of the asset.
List Tags/asset.get_tags.json Fetches all tags associated with assets for categorization and filtering. Returns a structured list for efficient metadata management.
Set meta data of an asset/asset.set_meta.jsonUpdates or adds metadata (title, description, custom fields) for a specific asset. Requires the asset ID and enhances searchability and organization.
Resync an asset/asset.resync.jsonResync an asset will start a process of checking for missing versions and generating them. This method is only needed in cases of a failure to sync a gallery.
Delete an asset/asset.delete.jsonDelete an asset for good, it will be removed also from any gallery that exists.
Get upload URL to POST an asset./asset.get_upload_url.jsonGet upload URL to your assets library, use this URL with an HTTP POST method. Asset can be added directly to a gallery or be attached to another asset to set the video poster, for example. When attaching to another asset, it must provide a type name.
Start uploading an asset from an input URL./asset.upload_from_url.jsonUpload an asset from an input URL. Asset can be added directly to a gallery or be attached to another asset to set the video poster, for example. When attaching to another asset, must provide a type name. This method will return a status ID that can be used by asset.upload_from_url_get_status to get information about the upload process and the ID of the uploaded asset when done.
Get status during and after the uploading process./asset.upload_from_url_get_status.jsonUse this method to get the Id of the uploaded asset when done.
Abort uploading process./asset.upload_from_url_abort.jsonUse this method to abort an upload.
Operations

Upload

This section provides you with a detailed overview of Cincopa's Upload API, which allows users to upload media files to their Cincopa galleries efficiently. The API offers two primary methods for uploading content: an embeddable iFrame for direct user uploads and a secure token-based system for controlled access. These options ensure flexibility, security, and ease of use, making it simple to integrate media uploads into your applications or websites.

With the embeddable iFrame, users can upload media directly through an interactive interface that supports drag-and-drop functionality, media selection, and content management features like metadata editing and file reordering. On the other hand, the token-based system ensures that only authorized users can upload media by generating a secure upload token.

Key FunctionalitiesEndpointPurpose
HTML iframe to manage gallery/upload.iframeProvides an embeddable iFrame URL for users to upload media directly to a Cincopa gallery. The interface supports drag-and-drop uploads, media selection, metadata editing, reordering, and deletion. It is fully responsive across devices.
Invite upload token/upload.get_upload_token.jsonGenerates a unique token that restricts access to the invite upload page, ensuring that only authorized users can upload media to a specified gallery.
Operations

Portal

This section provides a comprehensive suite of methods for managing and customizing portals. The Portal API allows developers to programmatically create, manage, and configure landing pages, video hubs, and share pages for seamless integration into applications, websites, or digital platforms.

Whether you're building a dynamic content hub, a multimedia-rich portal, or a branded video experience, this API offers full control over portal settings, status management, and retrieval of existing portals. The following table provides a breakdown of the available API endpoints and their functions:

Key FunctionalitiesEndpointPurpose
Verify subdomain/portal.check.jsonChecks if a portal exists and retrieves its status. This is useful for validating whether a portal is active before performing further operations.
Create subdomain if available/portal.cease.json Deactivates or ceases an existing portal. This operation is useful when a portal is no longer needed but should not be permanently deleted.
Rename subdomain/portal.rename.jsonRenames a specified portal by providing the existing portal ID and the new desired name. This helps in organizing portals efficiently.
Remove subdomain/portal.remove.jsonDeletes a portal from the system. This operation is irreversible and permanently removes all associated data.
Save subdomain/portal.set.jsonCreates a new portal or updates the settings of an existing one. This allows customization of portal properties such as name, visibility, and other configurations.
List of portals/portal.list.jsonRetrieves a list of all configured portals along with their details. This endpoint helps in managing multiple portals and tracking their statuses.
Operations

Webhook

This section provides a streamlined way to receive real-time notifications about account activities via HTTP POST callbacks. Instead of continuously polling for updates, webhooks allow external applications to listen for specific events and respond accordingly.

This API enables developers to automate workflows, synchronize data, and receive alerts whenever significant actions occur in the system. Additionally, the API supports Slack integration, allowing event notifications to be delivered directly to a Slack channel for easy monitoring and collaboration.

Key FunctionalitiesEndpointPurpose
List of webhooks/webhook.list.jsonRetrieves a list of all active webhooks associated with the account, including their configurations and callback URLs.
Create/update webhook/webhook.set.jsonRegisters a new webhook by specifying a callback URL and event types to trigger notifications.
Create/update webhook to slack/webhook.set_slack.jsonSets up a webhook that sends real-time event notifications directly to a Slack channel for instant updates.
Delete a webhook/webhhook.delete.jsonDeletes an existing webhook, stopping further event notifications and removing it from the system.
Operations

Live

Professional Live Video Streaming Service.

Operations