Developer API
Developer APIResourcesChangelog

Changelog

Release notes and versioning policy for the TagLogger API

Versioning & Stability

The API is versioned in the path: every endpoint lives under /v1. While v1 is the current stable version, we make only additive, backward-compatible changes to it:

  • New endpoints, new optional request fields, and new response fields can appear at any time.
  • New error code values and new webhook event types can be added.
  • Existing fields are not removed or repurposed, and existing error codes keep their meaning.

Write your integration to ignore unknown fields and to branch on error.code rather than message text. Security fixes may narrow behavior that allowed a key to act beyond its documented scope; we call those exceptions out in the release notes. If we otherwise need a breaking change, it ships under a new path version (for example /v2), and /v1 keeps working. See Error Handling for the stable contract.

Releases

Battery status scale correction

2026-10-01

Tags, locations and webhooks

  • Fix: battery status is always on one scale: 0 unknown, 1 good, 2 medium, 3 low, 4 critical. Some readings were one step too high, so a low battery showed as 4 (critical) and a critical one as 5. Those readings, including stored location history, now carry the correct value, and 5 no longer appears.
  • tag.battery_low keeps firing at low (an early warning to plan a swap) with critical: true at critical (replace soon). Integrations that branch on critical need no change.

Webhook subscription scope hardening

2026-08-15

Webhooks

  • Security change: webhook subscriptions deliver events for every tag in the workspace, so POST /v1/webhooks, PATCH /v1/webhooks/{webhookId}, DELETE /v1/webhooks/{webhookId}, and POST /v1/webhooks/{webhookId}/rotate-secret now require an all-tags key. Keys restricted to specific tags receive 403 forbidden.
  • Security change: subscribing to tag.moved or any geofence.* event (payloads carry coordinates) now also requires read:locations, matching the tag and geofence read scopes. Listing, reading, test deliveries, and delivery history are unchanged, and existing subscriptions keep delivering.

Customer Page zone activity and location history

2026-08-13

Customer Pages

  • Privacy change: a page's entry and exit feed now only shows events recorded after each tag was added to that page. Events from before a tag joined the page (for example, a reused tag's earlier shipments) no longer appear to page viewers. Removing a tag and adding it back later starts a fresh window.
  • New optional feature: locationHistory adds a click-to-show map trail per tag, floored the same way (only movement recorded after the tag was added to the page). It defaults to false everywhere — existing pages are unchanged until an owner turns it on — and requires liveMap. Viewers show one tag's trail at a time; the page loads no history until a viewer asks for it.
  • Applies to pages created or updated through the dashboard and through POST /v1/customer-pages / PATCH /v1/customer-pages/{pageId}. The features map accepts the new optional key; existing requests that omit it keep working. No SDK upgrade is required. Nothing is deleted: owner-facing event history in the dashboard and the API is unaffected.

Flexible tag labels

2026-08-10
  • Added Gmail-style labels for customer names, sites, external system IDs, asset numbers, or any other workspace-defined grouping.
  • The dashboard, map, and tag pickers can display, search, and filter labels. Customer Pages can show labels when the page owner enables that option. Tag Management can download and re-import up to 1,000 rows as spreadsheet-friendly CSV.
  • Tag records now preserve a read-only originalPhysicalLabel when the label used at shipment or provisioning can be determined safely. It remains visible and searchable after a display-name or later sticker change, and is protected from dashboard, CSV, and API edits.
  • GET /v1/tags supports exact label filtering and cross-field search. Tag reads, fleet deltas, and webhook payloads include originalPhysicalLabel and labels; PATCH /v1/tags/{tagId} can change the display name or replace the label list. Tag IDs, original physical labels, and hardware IDs remain read-only, and metadata never links hardware or grants access. TypeScript and Python SDK 1.2.0 expose the same contract.

API scope hardening

2026-08-05

Tags and locations

  • Security change: GET /v1/tags, GET /v1/tags/{tagId}, and tag-control responses now return lastLocation: null unless the key has read:locations. Non-location tag fields and lastSeenAt remain available with read:tags.
  • Inactive or naturally expired alert and recording pauses now return until: null, matching their effective paused: false state.

Geofence alert destinations

  • Security change: API requests that set or clear geofence To/CC email recipient lists now require read:locations in addition to manage:geofences. This covers create, update, and the deprecated emailAddress alias. Dashboard configuration is unchanged.

SDK compatibility

  • TypeScript/JavaScript and Python SDK 1.1.1 document the narrowed location and geofence-recipient scope requirements. Tag.lastLocation was already nullable and the request shapes are unchanged, so upgrading requires no application code changes. Integrations should ensure their API keys carry read:locations wherever they consume coordinates or configure email destinations.

Platform update

2026-08-03

Tag controls

  • Added PATCH /v1/tags/{tagId} with the new manage:tags scope for activation and timed or indefinite alert/recording pauses. Existing history is retained, and activation uses the same plan rules as the dashboard.

Customer Pages

  • Added create/read/update/revoke/token-rotation and workspace-branding endpoints for the existing multi-tag /p/<token> Customer Pages, with read:customer-pages and manage:customer-pages scopes.
  • The TypeScript and Python SDK 1.1.0 clients expose these Customer Page, tag-control, integration-binding, and geofence preference additions.

Geofences

  • Geofence create/update now accepts the existing dashboard fields for color, confirmation checks, entry/exit, email, push, dwell, and outbound integration bindings. GET /v1/integrations returns redacted binding IDs without credentials.
  • Security fix: tag-scoped API keys can now update or delete only geofences whose complete target set is within the key's documented tag scope. This intentionally restricts previously over-broad write access; workspace-wide geofence reads remain unchanged.
  • Added the optional alerts.includeMapLink request and response field. Set it to false to omit the Open Map button from geofence alert emails. It defaults to true for legacy geofences and does not enable the email channel.

SDKs

  • TypeScript/JavaScript and Python SDK version 1.1.0 adds typed support for alerts.includeMapLink and the endTimestampMs / sampleCount location sighting-window fields. This is an additive release; existing SDK methods and request shapes are unchanged, and the new location fields are optional in SDK types for source compatibility.

Platform update

2026-06-23

Observability

  • X-Request-Id is now returned on every API response. Supply the header in your request to have it echoed back unchanged; otherwise the server generates one automatically. Include it in support requests to enable precise log correlation.

v1.0

General Availability2026-06-22

First generally available release of the TagLogger API. The full v1 surface is stable and covered by the additive-change policy above.

Tags & locations

  • List and retrieve tags, including metadata, status, and battery level.
  • Read the latest location and paginated location history for a tag.
  • Fleet delta endpoint for efficient multi-tag synchronization.

Geofences

  • List and retrieve geofences with read:geofences.
  • Create, update, and delete geofences with manage:geofences.

Webhooks

  • Subscription management (create, list, update, delete) with manage:webhooks.
  • Tag event types (tag.moved, tag.battery_low, tag.offline) and geofence event types (geofence.entry, geofence.exit, geofence.dwell), each with signed, at-least-once delivery.
  • Webhook delivery for each event family is operator-gated and off by default at launch; subscriptions activate automatically once production delivery is enabled.
  • Automatic retries with backoff, plus a delivery history endpoint for reconciliation.
  • X-TagLogger-Signature HMAC-SHA256 signatures on every delivery.

Share links

  • List existing share links with read:share-links.
  • Create new share links with manage:share-links.

Account & usage

  • GET /v1/account to confirm the workspace and key a request resolves to.
  • GET /v1/usage for per-day request counts for the calling key (usage history; pass days to widen the window). For live rate-limit headroom, read the X-RateLimit-* response headers instead.

Platform

  • Scoped API keys (tl_live_ / tl_test_) with per-key scope and optional per-key tag allow-lists. See Authentication.
  • Stable, opaque cursor pagination across every list endpoint.
  • Per-key rate limiting with X-RateLimit-* headers.
  • Machine-readable OpenAPI 3.1 specification and an llms.txt index for agents.

Staying Up to Date

  • Subscribe to webhooks rather than polling where you can—new event types are announced here before they appear.
  • Re-read the OpenAPI spec after each release; it is the source of truth for fields and shapes.
  • Run integrations against a tl_test_ key first to validate any new fields before they reach production traffic.