Skip to content

Digital Product Passport API: developer documentation

With the customer API your own systems create products, maintain data fields, publish passports and download QR codes and PDFs. You sign in with an API key that you generate in the platform yourself. The full description is available as an OpenAPI 3.1 file.

Last updated: 1 October 2026

Overview

The customer API is a REST interface that uses JSON. It works on your tenant data, which means the same products and passports you see in the web application. Typical uses are connecting an ERP or PLM system, a nightly sync of master data, or a script that fetches QR codes for printing.

The base URL is https://dpp.com2u.selfhost.eu/api/v1/integration. All responses are JSON, except the QR code and PDF downloads.

Download the specification

The machine-readable reference for all endpoints, fields, examples and error responses is an OpenAPI 3.1 specification with the security scheme ApiKeyAuth:

The API itself serves the same file at GET /api/v1/integration/openapi.json, without a key. Import it into Swagger UI, Postman or the code generator of your choice. The descriptions inside the file are written in German.

Quick start

  1. Register or sign in. The API belongs to the paid plans, see Pricing.
  2. Open the Tenant area in the platform and generate the API key. Copy it immediately, because it is shown only once.
  3. Test the connection:
curl -H "X-API-Key: $DPP_API_KEY" \
  https://dpp.com2u.selfhost.eu/api/v1/integration/me

The response names your tenant, the scopes of the key, your plan and your usage of API calls.

Authentication

Send the key with every call in the X-API-Key header. Authorization: Bearer dpp_key_… works the same way. The tenant is always derived from the key; a tenant ID passed as a parameter is ignored. The API does not accept session tokens of the web application.

The key belongs to the person who generated it. Actions run with that person's rights as owner or admin. If the person loses that role, the API answers with 403 until a new key is generated. Generating a new key revokes the previous one immediately. The platform stores only a SHA-256 hash of the key.

Endpoints

All paths are under /api/v1/integration. Every endpoint requires a scope; a new key carries all four.

Method and pathPurposeScope
GET /meTenant, scopes, plan, usageany key
GET /schemasSchemas with data fieldsproducts:read
POST /productsCreate a product, optionally with data fieldsproducts:write
GET /productsList products (status, q, limit, offset)products:read
GET /products/{id}Read a productproducts:read
GET /products/{id}/fieldsRead current data fieldsproducts:read
PATCH /products/{id}/fieldsSet data fieldsproducts:write
POST /products/{id}/passportsCreate and publish a passportpassports:write
GET /products/{id}/passportsList passport versionspassports:read
POST /passports/{id}/publishPublish a draft versionpassports:write
GET /products/{id}/passport/qrQR code as PNG or SVGpassports:read
GET /products/{id}/passport/pdfPassport as PDFpassports:read

Create a product

name is required. Without schema_key your tenant's default schema applies; GET /schemas returns the available keys. You can pass data fields directly. field_status sets the status of the values, and only approved values flow into a passport.

curl -X POST https://dpp.com2u.selfhost.eu/api/v1/integration/products \
  -H "X-API-Key: $DPP_API_KEY" -H "Content-Type: application/json" \
  -d '{"name":"Battery module X1","category":"Industrial batteries",
       "manufacturer_ref":"ART-4711","schema_key":"battery-v1",
       "fields":{"battery_chemistry":"LFP"},"field_status":"approved"}'

The response with status 201 contains the product id. It is also the unique product identifier encoded in the QR code. The product quota of your plan applies as in the web application.

Publish a passport, download QR code and PDF

A passport freezes the approved data fields as a new version. If required fields are missing, the API answers with 422 and lists them in missing_fields.

curl -X POST -H "X-API-Key: $DPP_API_KEY" \
  https://dpp.com2u.selfhost.eu/api/v1/integration/products/{id}/passports

curl -o qr.png -H "X-API-Key: $DPP_API_KEY" \
  "https://dpp.com2u.selfhost.eu/api/v1/integration/products/{id}/passport/qr?format=png&size=600"

curl -o passport.pdf -H "X-API-Key: $DPP_API_KEY" \
  https://dpp.com2u.selfhost.eu/api/v1/integration/products/{id}/passport/pdf

For a vector QR code use format=svg. The PDF exists only after publication; before that the API answers with 404. The QR code points to the public passport page, see Create a Digital Product Passport from Excel for more.

Error codes

StatusMeaning
401Key missing, invalid, revoked or expired
402Quota used up: API calls, products or passports
403Scope missing, plan without API, key creator no longer owner or admin, tenant blocked
404Object not found or belongs to another tenant
422Invalid input, unknown field or missing required fields

For 401 and 403, detail holds an object with code and message, for example insufficient_scope or api_not_in_plan. For 402, detail names the resource, the limit and the usage so far.

Limits

Through the API you set data fields on the product level. Fields for batches or single items are maintained in the web application. There is no rate limit, but a call quota per plan; every authenticated call counts. Fetching the specification does not count. Current plans and quotas are on the Pricing page. For bulk import without the API, use the data template.

Frequently asked questions

Where do I get an API key?

In the platform, in the Tenant area. Owners and admins generate the key there. It is shown only once, and each tenant has exactly one key.

Which plans include the API?

Starter, Professional and Enterprise, not the free trial plan. Each passport in your plan quota includes 10 API calls. Current values are on the pricing page.

Is there a rate limit?

There is no separate rate limit (HTTP 429). Usage is limited by the call quota of your plan. When it is used up, the API answers with 402.

Can I load the specification into Swagger UI or Postman?

Yes. The OpenAPI 3.1 file is available as JSON and YAML and can be imported into common tools and code generators.

Start with your product data

Try it free for 30 days: import data, check it and publish it as a product passport.