The DeviceCloud REST API gives you programmatic access to the same data available in the console — test results, upload history, and flow analytics.
Include your API key in every request:
x-app-api-key: <your-api-key>
You can create an API key in the console under Settings → API Keys. The full key is shown only once, when it's created or rotated, so store it securely.
Requests can also be authenticated with a DeviceCloud login session, which is how the CLI authenticates after dcd login: send Authorization: Bearer <access-token> together with x-dcd-org: <team-id>, where the signed-in user must be a member of that team. For scripts and CI, use an API key.
A missing or invalid API key returns HTTP 403.
https://api.devicecloud.dev
The API accepts up to 60 requests per minute. Requests over the limit receive HTTP 429 Too Many Requests; wait a moment and try again.
These endpoints aren't rate limited, so they're safe to poll: GET /results/:uploadId, GET /uploads/status and GET /ip-addresses.
Most errors are returned with a matching HTTP status code. Three endpoints are the exception: GET /results/:uploadId, GET /flows and GET /flows/runs respond with HTTP 200 and report the error in the body instead:
{
"statusCode": 400,
"message": "fileName query parameter is required."
}Check the statusCode field in the body as well as the HTTP status. A malformed upload ID (not a UUID) is rejected with a real HTTP 400.
| Resource | Description |
|---|---|
| Uploads | List uploads and poll run status |
| Results | Fetch results, reports, and artifacts for an upload |
| Flows | Aggregated analytics and run history per flow file |
| IP Addresses | Current egress IPs for firewall allow-listing (no API key required) |