Your safety data, in the tools you already use.
The Ryskra API gives your BI dashboards, HR and ERP systems read-only access to incidents, hazards, inspections, corrective actions, training, locations and the OSHA 300 log. Webhooks tell your systems the moment something changes. Included on the Enterprise and Private Cloud plans.
Built so an API key can't become the weak spot.
Switched on deliberately
API access is off until Ryskra switches it on for your organization, and only the administrators you name as API managers can create keys or webhooks. Every administrator is emailed whenever a key or webhook is created, changed or revoked.
Keys always expire
Choose 30, 60 or 90 days when you create a key; there are no keys that live forever. We remind your administrators a week before a key expires. Any administrator can revoke a key, and it stops working immediately.
Least privilege
Keys are read-only and carry only the scopes you choose (for example incidents and locations, but not people or OSHA data). Lock a key to your network with an IP allowlist. Keys are stored only as a one-way hash and shown once.
Your data, and only yours
A key belongs to one organization and every request is answered inside that organization's isolated data. Keys reach only the public API, never the app. Medical and return-to-work details, investigation narratives and anonymous reporters are never exposed.
Three steps.
- Ask your Ryskra account manager to switch on API access and name your API managers.
- An API manager creates a key in Settings → API & webhooks: name it after what uses it, choose its scopes and expiry, and copy it.
- Send it as a bearer token:
curl https://api.ryskra.com/api/v1/public/incidents?limit=50 \ -H "Authorization: Bearer rsk_k3j9x0p2a7q1_••••••••••••••••••••••••••••••••••••••••"
Lists return { data, has_more, next_cursor }, oldest change first. Pass cursor for the next page and updated_since to sync only what changed.
Read-only, versioned, documented.
| GET /api/v1/public… | Scope | Returns |
|---|---|---|
| /incidents | incidents | Incidents and near misses: type, severity, status, location, department, body part, shift, task, root-cause category. |
| /hazards | hazards | Hazard reports and their review status. |
| /inspections | inspections | Inspections with score, summary and findings. |
| /capa | capa | Corrective and preventive actions and their status. |
| /training/assignments | training | Assignments, completion, score and expiry. |
| /osha/establishments, /osha/300 | osha | OSHA 300 log rows per establishment and year; privacy cases are never named. |
| /locations | locations | Sites, buildings, floors and zones. |
| /users | users | Name, email, role and department of people. Nothing else. |
| /me | any | The key's own name, scopes and expiry. |
Know the moment something changes.
Subscribe an HTTPS endpoint to incident.created, incident.updated, hazard.created, capa.status_changed, inspection.completed or training.completed. Each delivery is signed; failed deliveries are retried over about a day, can be replayed from Ryskra, and an endpoint that keeps failing is switched off and your administrators are told.
// Node.js: verify a Ryskra webhook before trusting it.
import crypto from "node:crypto";
export function verifyRyskra(rawBody, signatureHeader, secret) {
const { t, v1 } = Object.fromEntries(signatureHeader.split(",").map((p) => p.split("=")));
if (Math.abs(Date.now() / 1000 - Number(t)) > 300) return false; // older than 5 minutes
const expected = crypto.createHmac("sha256", secret).update(`${t}.${rawBody}`).digest("hex");
return crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(v1));
}
Predictable.
- 300 requests a minute per key (see the
X-RateLimit-*headers); up to 10 active keys and 10 webhook endpoints per organization. - Errors are
{ "error": "…", "code": "…" }with standard status codes: 401 (missing, expired or revoked key), 403 (scope, IP, plan), 429 (rate limit). - Write access and partner app connections are on the roadmap. Tell us what you'd build.