Sample environment. Data is public, visible to other visitors, and erased nightly — do not enter real names, injuries or personal information.

REST API

Company tierIn the app: /api-keys

The REST API lets your own systems, such as payroll, a BI dashboard or a general contractor's portal, read your records over HTTPS with an API key an admin makes. It only reads records: we never let a key create, change or delete one, and every key can be limited to the records it needs, set to expire and revoked at once.

1.Create a key (admin)

  1. Open API Keys under Admin Settings.
  2. Name the key after what will use it, tick the kinds of records it can read and choose when it expires: in 30 days, 90 days, a year, or never.
  3. Tick Zapier Webhooks only for an integration that subscribes itself to events, such as a Zapier integration. Leave it off for anything that only reads.
  4. Press Create Key and copy the key straight away. It starts with mk_ and is shown only this once; we keep a fingerprint of it, not the key.
  5. Store it where the system that uses it keeps its secrets. Anyone holding it can read what it is allowed to read.

2.Make a request

  1. Send the key in a header on every request: Authorization: Bearer mk_...
  2. GET /api/v1 on your Migna address lists what the key can read. It is a quick way to check a key works.
  3. GET /api/v1/incidents, /observations, /corrective-actions, /audits, /inspections, /training-records, /workers, /job-sites, /changes, /permits, /policies, /sds, /risk-assessments or /subcontractors returns a page of records, newest first, as JSON under data.
  4. GET /api/v1/<resource>/<id> returns one record under data.
  5. Records are read with GET only. A resource answers only if the key may read it and its module is turned on for your company.

3.Page through results

  1. Add limit to set the page size: 50 by default, at most 200.
  2. Each page carries nextCursor. Send it back as cursor to get the next page; it is null on the last page.
  3. Add createdAfter or createdBefore, as a date such as 2026-09-01 or a date and time such as 2026-09-01T12:00:00Z, to fetch only records created in that window. A nightly sync can ask for createdAfter its last run.
  4. To look one record up: /workers and /job-sites take name, which matches part of the name, ignoring case; /corrective-actions takes status: open (including in progress), closed (completed or verified), or one of open, in_progress, completed and verified.

4.Revoke a key (admin)

  1. Open API Keys and press Revoke on the key. Anything using it gets a 401 on its next request, and any webhooks it subscribed are deleted.
  2. The list keeps each key with who made it, when it was last used and how many requests it has made, so you can see which keys are idle.
  3. Creating and revoking keys is recorded in the Activity Log.

Common questions

What does the API leave out?
Files, photos, signatures and voice recordings, workers' phone numbers and email addresses, QR codes, and anything medical such as work restrictions. A privacy case has the person's name and the details that could identify them left out, the same as on an exported log.
Are there limits?
Each key can make 120 requests a minute; past that it gets a 429 with a Retry-After header. A company can hold 20 active keys.
What do the error codes mean?
401: no key, or a key that is unknown, revoked or expired. 403: the key cannot read that resource, or the module or the API is turned off. 404: no such resource or record. 400: a bad cursor, date or filter.
Can the API change our records?
No. Records are only ever read. The one thing a key can create is a webhook subscription, and only if an admin gave it the webhooks permission.

Read next

Something here does not match what you see in the app? Tell us from Help & Support inside the app, or email info@mignasafetysolutions.com. We correct the guide rather than let it drift.

REST API — Migna User Guide