CORE I/O provides a complete REST API for control, automation, monitoring, and integration. The CORE I/O web interface communicates exclusively through this same API. ToolsOnAir can therefore guarantee that every operation available in the web interface can also be performed through the REST API.
Interactive API documentation
Sign in to CORE I/O, open the user menu, and select REST API. The server opens the interactive API documentation in a new browser tab. Because the documentation is supplied by the installed server, it matches the API version running on that system.
Use the interactive documentation to inspect resource paths, request parameters, response models, and the operations supported by the installed release.
API capabilities
The REST API covers the operational and administrative functions used by the web interface, including:
- Creating, configuring, starting, stopping, and monitoring recording, loop, transcode, and playout flows.
- Assigning sources, destinations, channels, presets, metadata, and file-naming rules.
- Creating, reading, updating, and deleting scheduled recording events.
- Changing the duration or end time of a recording that is already running.
- Reading system health, channel state, telemetry, warnings, and errors.
- Loading and cueing media for playout and controlling play, pause, stop, go-to-timecode, jog, and shuttle operations.
- Working with users, groups, dashboards, integrations, and other configuration resources according to the API user's role.
- Exchanging metadata with automation, newsroom, media-asset-management, and other third-party systems.
Dedicated API users
CORE I/O supports dedicated API users for scripts, automation systems, and third-party integrations. API users are separate from interactive browser accounts and do not sign in with a password. Administrators manage them from Permissions > Users on the API Users tab.
When creating an API user, enter its name and email address and assign the Admin, User, or Viewer role required by the integration. The role controls which resources and operations the account can access.
Bearer tokens
Each API user can hold one bearer token. Send it with every request in the HTTP authorization header:
Authorization: Bearer <token>
CORE I/O displays a newly created or rotated token only once. Copy it immediately and store it in the secret-management system used by the integration.
| Action | Result |
|---|---|
| Create Token | Creates the API user's first token. The token claims a licensed API seat. |
| Rotate Token | Creates a replacement and invalidates the previous token immediately. Rotation does not require an additional seat. |
| Revoke Token | Invalidates the token and releases the API user's licensed seat. |
| Delete User | Removes the API account and its token. |
Licensing and sessions
An API user's first token claims a concurrent seat. The Users and License pages show API seats separately from human browser sessions. If no seat is available, CORE I/O refuses creation of the first token with the server's license message. Revoking the token releases the seat.
Calling external APIs from actions
CORE I/O action sets can also call an external REST API when a recording starts, splits, or stops. This is separate from using the CORE I/O REST API to control the system. Configure the external host, request path, HTTP method, headers, authentication, and request body on the Actions page.
Security recommendations
- Create a separate API user for each application or integration.
- Assign the least-privileged role that can perform the required operations.
- Use HTTPS and never place bearer tokens in URLs, logs, or source code.
- Rotate a token immediately if it may have been disclosed.
- Test automation against the interactive documentation for the installed CORE I/O version before using it in production.