Changelog
Release notes and versioning policy for the TagLogger API
Versioning & Stability
The API is versioned in the path: every endpoint lives under /v1. While v1 is the current stable version, we make only additive, backward-compatible changes to it:
- New endpoints, new optional request fields, and new response fields can appear at any time.
- New error
codevalues and new webhook event types can be added. - Existing fields are not removed or repurposed, and existing error codes keep their meaning.
Write your integration to ignore unknown fields and to branch on error.code rather than message text. Security fixes may narrow behavior that allowed a key to act beyond its documented scope; we call those exceptions out in the release notes. If we otherwise need a breaking change, it ships under a new path version (for example /v2), and /v1 keeps working. See Error Handling for the stable contract.
Releases
Battery status scale correction
2026-10-01Tags, locations and webhooks
- Fix: battery
statusis always on one scale: 0 unknown, 1 good, 2 medium, 3 low, 4 critical. Some readings were one step too high, so a low battery showed as 4 (critical) and a critical one as 5. Those readings, including stored location history, now carry the correct value, and 5 no longer appears. tag.battery_lowkeeps firing at low (an early warning to plan a swap) withcritical: trueat critical (replace soon). Integrations that branch oncriticalneed no change.
Webhook subscription scope hardening
2026-08-15Webhooks
- Security change: webhook subscriptions deliver events for every tag in the workspace, so
POST /v1/webhooks,PATCH /v1/webhooks/{webhookId},DELETE /v1/webhooks/{webhookId}, andPOST /v1/webhooks/{webhookId}/rotate-secretnow require an all-tags key. Keys restricted to specific tags receive403 forbidden. - Security change: subscribing to
tag.movedor anygeofence.*event (payloads carry coordinates) now also requiresread:locations, matching the tag and geofence read scopes. Listing, reading, test deliveries, and delivery history are unchanged, and existing subscriptions keep delivering.
Customer Page zone activity and location history
2026-08-13Customer Pages
- Privacy change: a page's entry and exit feed now only shows events recorded after each tag was added to that page. Events from before a tag joined the page (for example, a reused tag's earlier shipments) no longer appear to page viewers. Removing a tag and adding it back later starts a fresh window.
- New optional feature:
locationHistoryadds a click-to-show map trail per tag, floored the same way (only movement recorded after the tag was added to the page). It defaults tofalseeverywhere — existing pages are unchanged until an owner turns it on — and requiresliveMap. Viewers show one tag's trail at a time; the page loads no history until a viewer asks for it. - Applies to pages created or updated through the dashboard and through
POST /v1/customer-pages/PATCH /v1/customer-pages/{pageId}. Thefeaturesmap accepts the new optional key; existing requests that omit it keep working. No SDK upgrade is required. Nothing is deleted: owner-facing event history in the dashboard and the API is unaffected.
Flexible tag labels
2026-08-10- Added Gmail-style labels for customer names, sites, external system IDs, asset numbers, or any other workspace-defined grouping.
- The dashboard, map, and tag pickers can display, search, and filter labels. Customer Pages can show labels when the page owner enables that option. Tag Management can download and re-import up to 1,000 rows as spreadsheet-friendly CSV.
- Tag records now preserve a read-only
originalPhysicalLabelwhen the label used at shipment or provisioning can be determined safely. It remains visible and searchable after a display-name or later sticker change, and is protected from dashboard, CSV, and API edits. GET /v1/tagssupports exact label filtering and cross-field search. Tag reads, fleet deltas, and webhook payloads includeoriginalPhysicalLabelandlabels;PATCH /v1/tags/{tagId}can change the display name or replace the label list. Tag IDs, original physical labels, and hardware IDs remain read-only, and metadata never links hardware or grants access. TypeScript and Python SDK 1.2.0 expose the same contract.
API scope hardening
2026-08-05Tags and locations
- Security change:
GET /v1/tags,GET /v1/tags/{tagId}, and tag-control responses now returnlastLocation: nullunless the key hasread:locations. Non-location tag fields andlastSeenAtremain available withread:tags. - Inactive or naturally expired alert and recording pauses now return
until: null, matching their effectivepaused: falsestate.
Geofence alert destinations
- Security change: API requests that set or clear geofence To/CC email recipient lists now require
read:locationsin addition tomanage:geofences. This covers create, update, and the deprecatedemailAddressalias. Dashboard configuration is unchanged.
SDK compatibility
- TypeScript/JavaScript and Python SDK 1.1.1 document the narrowed location and geofence-recipient scope requirements.
Tag.lastLocationwas already nullable and the request shapes are unchanged, so upgrading requires no application code changes. Integrations should ensure their API keys carryread:locationswherever they consume coordinates or configure email destinations.
Platform update
2026-08-03Tag controls
- Added
PATCH /v1/tags/{tagId}with the newmanage:tagsscope for activation and timed or indefinite alert/recording pauses. Existing history is retained, and activation uses the same plan rules as the dashboard.
Customer Pages
- Added create/read/update/revoke/token-rotation and workspace-branding endpoints for the existing multi-tag
/p/<token>Customer Pages, withread:customer-pagesandmanage:customer-pagesscopes. - The TypeScript and Python SDK 1.1.0 clients expose these Customer Page, tag-control, integration-binding, and geofence preference additions.
Geofences
- Geofence create/update now accepts the existing dashboard fields for color, confirmation checks, entry/exit, email, push, dwell, and outbound integration bindings.
GET /v1/integrationsreturns redacted binding IDs without credentials. - Security fix: tag-scoped API keys can now update or delete only geofences whose complete target set is within the key's documented tag scope. This intentionally restricts previously over-broad write access; workspace-wide geofence reads remain unchanged.
- Added the optional
alerts.includeMapLinkrequest and response field. Set it tofalseto omit the Open Map button from geofence alert emails. It defaults totruefor legacy geofences and does not enable the email channel.
SDKs
- TypeScript/JavaScript and Python SDK version
1.1.0adds typed support foralerts.includeMapLinkand theendTimestampMs/sampleCountlocation sighting-window fields. This is an additive release; existing SDK methods and request shapes are unchanged, and the new location fields are optional in SDK types for source compatibility.
Platform update
2026-06-23Observability
X-Request-Idis now returned on every API response. Supply the header in your request to have it echoed back unchanged; otherwise the server generates one automatically. Include it in support requests to enable precise log correlation.
v1.0
General Availability2026-06-22First generally available release of the TagLogger API. The full v1 surface is stable and covered by the additive-change policy above.
Tags & locations
- List and retrieve tags, including metadata, status, and battery level.
- Read the latest location and paginated location history for a tag.
- Fleet delta endpoint for efficient multi-tag synchronization.
Geofences
- List and retrieve geofences with
read:geofences. - Create, update, and delete geofences with
manage:geofences.
Webhooks
- Subscription management (create, list, update, delete) with
manage:webhooks. - Tag event types (
tag.moved,tag.battery_low,tag.offline) and geofence event types (geofence.entry,geofence.exit,geofence.dwell), each with signed, at-least-once delivery. - Webhook delivery for each event family is operator-gated and off by default at launch; subscriptions activate automatically once production delivery is enabled.
- Automatic retries with backoff, plus a delivery history endpoint for reconciliation.
X-TagLogger-SignatureHMAC-SHA256 signatures on every delivery.
Share links
- List existing share links with
read:share-links. - Create new share links with
manage:share-links.
Account & usage
GET /v1/accountto confirm the workspace and key a request resolves to.GET /v1/usagefor per-day request counts for the calling key (usage history; passdaysto widen the window). For live rate-limit headroom, read theX-RateLimit-*response headers instead.
Platform
- Scoped API keys (
tl_live_/tl_test_) with per-key scope and optional per-key tag allow-lists. See Authentication. - Stable, opaque cursor pagination across every list endpoint.
- Per-key rate limiting with
X-RateLimit-*headers. - Machine-readable OpenAPI 3.1 specification and an
llms.txtindex for agents.
Staying Up to Date
- Subscribe to webhooks rather than polling where you can—new event types are announced here before they appear.
- Re-read the OpenAPI spec after each release; it is the source of truth for fields and shapes.
- Run integrations against a
tl_test_key first to validate any new fields before they reach production traffic.