REST API
Company tierIn the app: /api-keys
The REST API lets your own systems, such as payroll, a BI dashboard or a general contractor's portal, read your records over HTTPS with an API key an admin makes. It only reads records: we never let a key create, change or delete one, and every key can be limited to the records it needs, set to expire and revoked at once.
1.Create a key (admin)
- Open API Keys under Admin Settings.
- Name the key after what will use it, tick the kinds of records it can read and choose when it expires: in 30 days, 90 days, a year, or never.
- Tick Zapier Webhooks only for an integration that subscribes itself to events, such as a Zapier integration. Leave it off for anything that only reads.
- Press Create Key and copy the key straight away. It starts with mk_ and is shown only this once; we keep a fingerprint of it, not the key.
- Store it where the system that uses it keeps its secrets. Anyone holding it can read what it is allowed to read.
2.Make a request
- Send the key in a header on every request: Authorization: Bearer mk_...
- GET /api/v1 on your Migna address lists what the key can read. It is a quick way to check a key works.
- GET /api/v1/incidents, /observations, /corrective-actions, /audits, /inspections, /training-records, /workers, /job-sites, /changes, /permits, /policies, /sds, /risk-assessments or /subcontractors returns a page of records, newest first, as JSON under data.
- GET /api/v1/<resource>/<id> returns one record under data.
- Records are read with GET only. A resource answers only if the key may read it and its module is turned on for your company.
3.Page through results
- Add limit to set the page size: 50 by default, at most 200.
- Each page carries nextCursor. Send it back as cursor to get the next page; it is null on the last page.
- Add createdAfter or createdBefore, as a date such as 2026-09-01 or a date and time such as 2026-09-01T12:00:00Z, to fetch only records created in that window. A nightly sync can ask for createdAfter its last run.
- To look one record up: /workers and /job-sites take name, which matches part of the name, ignoring case; /corrective-actions takes status: open (including in progress), closed (completed or verified), or one of open, in_progress, completed and verified.
4.Revoke a key (admin)
- Open API Keys and press Revoke on the key. Anything using it gets a 401 on its next request, and any webhooks it subscribed are deleted.
- The list keeps each key with who made it, when it was last used and how many requests it has made, so you can see which keys are idle.
- Creating and revoking keys is recorded in the Activity Log.
Common questions
- What does the API leave out?
- Files, photos, signatures and voice recordings, workers' phone numbers and email addresses, QR codes, and anything medical such as work restrictions. A privacy case has the person's name and the details that could identify them left out, the same as on an exported log.
- Are there limits?
- Each key can make 120 requests a minute; past that it gets a 429 with a Retry-After header. A company can hold 20 active keys.
- What do the error codes mean?
- 401: no key, or a key that is unknown, revoked or expired. 403: the key cannot read that resource, or the module or the API is turned off. 404: no such resource or record. 400: a bad cursor, date or filter.
- Can the API change our records?
- No. Records are only ever read. The one thing a key can create is a webhook subscription, and only if an admin gave it the webhooks permission.