Developers

Your safety data, in the tools you already use.

The Ryskra API gives your BI dashboards, HR and ERP systems read-only access to incidents, hazards, inspections, corrective actions, training, locations and the OSHA 300 log. Webhooks tell your systems the moment something changes. Included on the Enterprise and Private Cloud plans.

Security first

Built so an API key can't become the weak spot.

Switched on deliberately

API access is off until Ryskra switches it on for your organization, and only the administrators you name as API managers can create keys or webhooks. Every administrator is emailed whenever a key or webhook is created, changed or revoked.

Keys always expire

Choose 30, 60 or 90 days when you create a key; there are no keys that live forever. We remind your administrators a week before a key expires. Any administrator can revoke a key, and it stops working immediately.

Least privilege

Keys are read-only and carry only the scopes you choose (for example incidents and locations, but not people or OSHA data). Lock a key to your network with an IP allowlist. Keys are stored only as a one-way hash and shown once.

Your data, and only yours

A key belongs to one organization and every request is answered inside that organization's isolated data. Keys reach only the public API, never the app. Medical and return-to-work details, investigation narratives and anonymous reporters are never exposed.

Getting started

Three steps.

  1. Ask your Ryskra account manager to switch on API access and name your API managers.
  2. An API manager creates a key in Settings → API & webhooks: name it after what uses it, choose its scopes and expiry, and copy it.
  3. Send it as a bearer token:
curl https://api.ryskra.com/api/v1/public/incidents?limit=50 \
  -H "Authorization: Bearer rsk_k3j9x0p2a7q1_••••••••••••••••••••••••••••••••••••••••"

Lists return { data, has_more, next_cursor }, oldest change first. Pass cursor for the next page and updated_since to sync only what changed.

Endpoints

Read-only, versioned, documented.

GET /api/v1/public…ScopeReturns
/incidentsincidentsIncidents and near misses: type, severity, status, location, department, body part, shift, task, root-cause category.
/hazardshazardsHazard reports and their review status.
/inspectionsinspectionsInspections with score, summary and findings.
/capacapaCorrective and preventive actions and their status.
/training/assignmentstrainingAssignments, completion, score and expiry.
/osha/establishments, /osha/300oshaOSHA 300 log rows per establishment and year; privacy cases are never named.
/locationslocationsSites, buildings, floors and zones.
/usersusersName, email, role and department of people. Nothing else.
/meanyThe key's own name, scopes and expiry.
Webhooks

Know the moment something changes.

Subscribe an HTTPS endpoint to incident.created, incident.updated, hazard.created, capa.status_changed, inspection.completed or training.completed. Each delivery is signed; failed deliveries are retried over about a day, can be replayed from Ryskra, and an endpoint that keeps failing is switched off and your administrators are told.

// Node.js: verify a Ryskra webhook before trusting it.
import crypto from "node:crypto";

export function verifyRyskra(rawBody, signatureHeader, secret) {
  const { t, v1 } = Object.fromEntries(signatureHeader.split(",").map((p) => p.split("=")));
  if (Math.abs(Date.now() / 1000 - Number(t)) > 300) return false; // older than 5 minutes
  const expected = crypto.createHmac("sha256", secret).update(`${t}.${rawBody}`).digest("hex");
  return crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(v1));
}
Limits and errors

Predictable.

  • 300 requests a minute per key (see the X-RateLimit-* headers); up to 10 active keys and 10 webhook endpoints per organization.
  • Errors are { "error": "…", "code": "…" } with standard status codes: 401 (missing, expired or revoked key), 403 (scope, IP, plan), 429 (rate limit).
  • Write access and partner app connections are on the roadmap. Tell us what you'd build.