> ## Documentation Index
> Fetch the complete documentation index at: https://docs.closient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List firmware

> List firmware on products owned by the organizations the caller can see, newest release first. Filter by product GTIN, latest or stable. Paginated.



## OpenAPI

````yaml /openapi/openapi-products.json get /products/api/v1/firmware
openapi: 3.1.0
info:
  title: Products API
  version: 1.0.0
  description: >
    Look up, claim, and browse GTINs in the Closient product repository.


    ## Authentication


    All endpoints require an API key passed via the `X-API-Key` HTTP header,
    unless otherwise noted.


    ```

    X-API-Key: csb_<body>_<checksum>

    ```


    Generate API keys in **Settings > API Keys** in your dashboard, or via the
    Account API.

    Session-based (cookie) authentication is also accepted for browser-based
    access.


    ## Rate Limits


    | Tier        | Requests / minute | Requests / day |

    |-------------|-------------------|----------------|

    | Default     | 300               | 10,000         |

    | Custom      | Contact us        | Contact us     |


    Rate-limit headers are included on every response so callers can
    self-throttle without

    hitting our 429s ("informed governor"):


    - `RateLimit-Policy` — every active window, e.g. `300;w=60, 10000;w=86400`

    - `RateLimit-Limit` — quota for the **most-restrictive** currently-active
    window

    - `RateLimit-Remaining` — requests left in that window

    - `RateLimit-Reset` — seconds until that window resets (relative; clock-skew
    safe)


    Legacy `X-RateLimit-*` aliases are also emitted for back-compat.
    `X-RateLimit-Reset`

    keeps the absolute Unix-timestamp shape to avoid breaking existing
    consumers.


    When rate-limited, you receive `429 Too Many Requests` with a
    `retry_after_seconds` field

    in the error envelope and a `Retry-After` header.


    ## Pagination


    List endpoints return paginated results in this envelope:


    ```json

    {
      "data": [...],
      "pagination": {
        "page": 1,
        "page_size": 25,
        "total_count": 342,
        "total_pages": 14,
        "has_next": true,
        "has_previous": false
      }
    }

    ```


    Use `?page=2&page_size=50` query parameters. Maximum page size is 100.


    ## Error Responses


    All errors conform to [RFC 9457 Problem
    Details](https://www.rfc-editor.org/rfc/rfc9457)

    with `Content-Type: application/problem+json`:


    ```json

    {
      "type": "https://closient.com/docs/errors/not_found",
      "title": "Not Found",
      "status": 404,
      "detail": "The requested resource was not found.",
      "error_code": "not_found",
      "retryable": false,
      "timestamp": "2026-03-31T12:00:00+00:00"
    }

    ```


    Common error codes: `unauthorized` (401), `forbidden` (403), `not_found`
    (404),

    `validation_error` (422), `rate_limited` (429), `internal_error` (500).
  termsOfService: https://www.closient.com/terms/
servers:
  - url: https://www.closient.com
security: []
tags:
  - name: Products
    description: Look up, claim, and browse products and trade items.
  - name: Product Group
    description: Manage GDSN packaging hierarchy relationships.
  - name: Import
    description: >-
      Bulk import products, batch/lots (GS1 AI 10) and serial numbers (GS1 AI
      21) from CSV, TSV or XLSX files, with a downloadable template per entity.
  - name: QR
    description: Generate QR codes encoding GS1 Digital Link URLs.
  - name: Codes
    description: Generate GS1 DataMatrix and 1D barcodes (EAN/UPC/ITF-14/Code128).
  - name: Digital Link
    description: >-
      Parse GS1 Digital Link URIs into structured AIs (GTIN, lot, expiry,
      serial).
  - name: Labels
    description: >-
      Bulk label-export jobs: ZIPs of QR / DataMatrix / 1D symbols and multi-up
      sheet PDFs, async via Celery with status polling.
  - name: Lots
    description: >-
      Lot generator v2: format templates with persistent counters,
      reserve/commit/discard runs, soft/hard collision handling, and an async
      Celery path with SSE progress.
  - name: Retailer Catalog Import
    description: >-
      Server-side retailer catalog import jobs: stage normalised rows, then run
      the GTIN-keyed cross-retailer merge with a dry-run mode, per-field
      provenance and a quarantine report for every row refused.
  - name: HRI Presets
    description: >-
      Saved, named per-organisation Human Readable Interpretation (HRI)
      configurations — placement, layout, notation and typography. Referenceable
      by name from the QR generation endpoint, with an org default applied when
      no options or preset are supplied.
  - name: PIP Embed (Public)
    description: >-
      Unauthenticated, cross-origin read powering the embeddable PIP panel
      (`/widget/v1/pip-panel.js`) that retailers drop into their own product
      detail pages. Reduced to the disclosure level the hosted page would serve
      an anonymous visitor.
  - name: Recipes
    description: >-
      Recipes shown on a product's hosted page. Create a recipe, attach it to
      the organization's products by GTIN, and update or delete it.
  - name: Firmware
    description: >-
      Firmware releases shown on a product's hosted page. Publish a release for
      the organization's products by GTIN, mark it latest or stable, and update
      or delete it.
  - name: App Links
    description: >-
      Companion-app download and launch links shown on a product's hosted page,
      one per platform. Create, list, update and delete the links on the
      organization's products.
  - name: Replacement Parts
    description: >-
      Replacement parts shown on a product's hosted page. List one of the
      organization's products as a part of another, repoint it, or remove it.
  - name: Accessories
    description: >-
      Accessories shown on a product's hosted page. List one of the
      organization's products as an accessory of another, repoint it, or remove
      it.
  - name: Consumables
    description: >-
      Consumables shown on a product's hosted page (filters, refills,
      cartridges). List one of the organization's products as a consumable of
      another, with its lifespan and whether it is required, repoint it, or
      remove it.
  - name: Product Families
    description: >-
      Consumer variant groups: one organization's products that are the same
      concept in different sizes, shades, flavors or scents. Create a family,
      then add, update, reorder and remove its member products. Distinct from
      Product Group, which is packaging hierarchy.
  - name: Product Links
    description: >-
      Generic, GS1-link-type-keyed brand CTA links (e.g. reviews, promotions,
      loyalty programs, homepage) attached to a product or a brand and rendered
      on the hosted page.
externalDocs:
  description: Closient Documentation
  url: https://docs.closient.com
paths:
  /products/api/v1/firmware:
    get:
      tags:
        - Firmware
      summary: List firmware
      description: >-
        List firmware on products owned by the organizations the caller can see,
        newest release first. Filter by product GTIN, latest or stable.
        Paginated.
      operationId: apps_products_api_firmware_list_firmware
      parameters:
        - in: query
          name: gtin
          schema:
            description: >-
              Only firmware shown on the product with this GTIN (any length,
              with or without separators). A value that isn't a valid GTIN
              matches nothing.
            title: Gtin
            pattern: ^[^\x00]{0,}$
            type: string
          required: false
          description: >-
            Only firmware shown on the product with this GTIN (any length, with
            or without separators). A value that isn't a valid GTIN matches
            nothing.
        - in: query
          name: is_latest
          schema:
            description: Only firmware marked (or not marked) as the latest release.
            title: Is Latest
            type: boolean
          required: false
          description: Only firmware marked (or not marked) as the latest release.
        - in: query
          name: is_stable
          schema:
            description: Only stable (or only beta) firmware.
            title: Is Stable
            type: boolean
          required: false
          description: Only stable (or only beta) firmware.
        - in: query
          name: page
          schema:
            default: 1
            description: Page number (1-indexed).
            maximum: 10000000
            minimum: 1
            title: Page
            type: integer
          required: false
          description: Page number (1-indexed).
        - in: query
          name: page_size
          schema:
            default: 25
            description: Number of items per page (max 100).
            maximum: 100
            minimum: 1
            title: Page Size
            type: integer
          required: false
          description: Number of items per page (max 100).
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PagedFirmwareOut'
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '401':
          description: Unauthorized
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '403':
          description: Forbidden
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '404':
          description: Not Found
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '405':
          description: Method Not Allowed
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '422':
          description: Unprocessable Content
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '429':
          description: Too Many Requests
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
      security:
        - APIKeyHeaderAuth: []
        - OAuthTokenAuth: []
        - CookieGatedSessionAuth: []
components:
  schemas:
    PagedFirmwareOut:
      properties:
        data:
          description: >-
            Items on the current page, each conforming to the endpoint's item
            schema. Empty when the result set is empty or ``page`` is past the
            end.
          items:
            $ref: '#/components/schemas/FirmwareOut'
          title: Data
          type: array
        pagination:
          $ref: '#/components/schemas/PaginationMeta'
          description: Pagination envelope describing position within the full result set.
      required:
        - data
        - pagination
      title: PagedFirmwareOut
      type: object
    ErrorOut:
      description: |-
        RFC 9457 Problem Details response.

        All API errors are returned in this format with Content-Type:
        application/problem+json.
      examples:
        - detail: The requested resource was not found.
          error_code: not_found
          retryable: false
          status: 404
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Not Found
          type: https://closient.com/docs/errors/not_found
        - detail: Validation error.
          details:
            - loc:
                - body
                - name
              msg: Field required
              type: missing
          error_code: validation_error
          retryable: false
          status: 422
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Validation Error
          type: https://closient.com/docs/errors/validation_error
        - detail: Rate limit exceeded. Please try again later.
          error_code: rate_limited
          retry_after: 31
          retryable: true
          status: 429
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Rate Limited
          type: https://closient.com/docs/errors/rate_limited
      properties:
        type:
          description: URI reference identifying the error type.
          title: Type
          type: string
        title:
          description: Short human-readable summary of the error.
          title: Title
          type: string
        status:
          description: HTTP status code.
          title: Status
          type: integer
        detail:
          description: Human-readable explanation of this specific occurrence.
          title: Detail
          type: string
        error_code:
          description: Machine-readable error code (e.g. not_found, unauthorized).
          title: Error Code
          type: string
        retryable:
          default: false
          description: Whether retrying the same request can succeed.
          title: Retryable
          type: boolean
        timestamp:
          description: ISO 8601 timestamp of when the error occurred.
          title: Timestamp
          type: string
        retry_after:
          anyOf:
            - type: integer
            - type: 'null'
          description: Seconds to wait before retrying (when applicable).
          title: Retry After
        owner_action_required:
          anyOf:
            - type: boolean
            - type: 'null'
          description: Whether the error requires account owner intervention.
          title: Owner Action Required
        details:
          description: Additional context (validation errors, etc.).
          title: Details
      required:
        - type
        - title
        - status
        - detail
        - error_code
        - timestamp
      title: ErrorOut
      type: object
    FirmwareOut:
      description: A firmware release with the products it is shown on.
      examples:
        - checksum_sha256: 9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08
          created: '2026-09-30T09:00:00Z'
          description: Improves temperature stability.
          file_url: ''
          id: F5n5NdW6dTbvPYkgnLNjte
          is_latest: true
          is_stable: true
          maximum_hardware_version: 3.x
          minimum_hardware_version: '1.0'
          modified: '2026-09-30T09:00:00Z'
          products:
            - gtin: '00850012345671'
              id: SBjSX6xUJPPHQKUXBpYX2C
              product_name: Acme Smart Kettle
          release_date: '2026-09-01'
          release_notes: Fixes a boil-over bug.
          size_kb: 512
          title: Acme Kettle firmware 2.4.1
          url: https://downloads.example.com/kettle/2.4.1.bin
          version: 2.4.1
      properties:
        id:
          description: >-
            URL-safe 22-character shortuuid encoding of the row's UUID primary
            key. Stable across the row's lifetime; suitable for sharing in URLs,
            log lines, and external SDK clients. Accepted on input as either the
            shortuuid form or the canonical UUID form
            (``xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx``).
          format: shortuuid
          maxLength: 22
          minLength: 22
          pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
          title: Id
          type: string
        version:
          description: Firmware version label.
          title: Version
          type: string
        title:
          description: Display title. Empty string when unset.
          title: Title
          type: string
        url:
          description: >-
            Download URL (https). Empty string when only an uploaded file
            exists.
          title: Url
          type: string
        file_url:
          description: >-
            URL of a file uploaded by staff through the admin. Empty string when
            there is none.
          title: File Url
          type: string
        release_date:
          anyOf:
            - format: date
              type: string
            - type: 'null'
          description: Release date, or null when unknown.
          title: Release Date
        description:
          description: Short description. Empty string when unset.
          title: Description
          type: string
        size_kb:
          description: Download size in kilobytes. 0 when unknown.
          title: Size Kb
          type: integer
        minimum_hardware_version:
          description: Oldest hardware revision this runs on. Empty when unset.
          title: Minimum Hardware Version
          type: string
        maximum_hardware_version:
          description: Newest hardware revision this runs on. Empty when unset.
          title: Maximum Hardware Version
          type: string
        checksum_sha256:
          description: Lowercase hex SHA-256 of the download. Empty when unset.
          title: Checksum Sha256
          type: string
        release_notes:
          description: Release notes. Empty string when unset.
          title: Release Notes
          type: string
        is_latest:
          description: Whether this is the current release.
          title: Is Latest
          type: boolean
        is_stable:
          description: Whether this is a stable release rather than a beta.
          title: Is Stable
          type: boolean
        products:
          description: The products this firmware is shown on, by GTIN.
          items:
            $ref: '#/components/schemas/FirmwareProductOut'
          title: Products
          type: array
        created:
          description: Server-side ISO 8601 timestamp of creation (UTC).
          format: date-time
          title: Created
          type: string
        modified:
          description: Server-side ISO 8601 timestamp of last modification (UTC).
          format: date-time
          title: Modified
          type: string
      required:
        - id
        - version
        - title
        - url
        - file_url
        - release_date
        - description
        - size_kb
        - minimum_hardware_version
        - maximum_hardware_version
        - checksum_sha256
        - release_notes
        - is_latest
        - is_stable
        - products
        - created
        - modified
      title: FirmwareOut
      type: object
    PaginationMeta:
      description: >-
        Page envelope returned alongside ``data`` on every paginated list
        endpoint.
      examples:
        - has_next: true
          has_previous: false
          page: 1
          page_size: 25
          total_count: 342
          total_pages: 14
      properties:
        page:
          description: >-
            1-indexed page number that was returned. Echoes the ``?page=`` query
            parameter.
          examples:
            - 1
          minimum: 1
          title: Page
          type: integer
        page_size:
          description: >-
            Number of items returned in ``data`` for this page. Capped at the
            endpoint's ``max_page_size`` (typically 100).
          examples:
            - 25
          minimum: 1
          title: Page Size
          type: integer
        total_count:
          description: Total number of items matching the query across all pages.
          examples:
            - 342
          minimum: 0
          title: Total Count
          type: integer
        total_pages:
          description: >-
            Total number of pages at the current ``page_size``. Always at least
            1 (an empty result still reports ``total_pages: 1``).
          examples:
            - 14
          minimum: 1
          title: Total Pages
          type: integer
        has_next:
          description: >-
            True when ``page < total_pages`` — clients can request
            ``page=page+1`` to continue.
          examples:
            - true
          title: Has Next
          type: boolean
        has_previous:
          description: >-
            True when ``page > 1`` — clients can request ``page=page-1`` to go
            back.
          examples:
            - false
          title: Has Previous
          type: boolean
      required:
        - page
        - page_size
        - total_count
        - total_pages
        - has_next
        - has_previous
      title: PaginationMeta
      type: object
    FirmwareProductOut:
      description: A product a firmware row is shown on.
      examples:
        - gtin: '00850012345671'
          id: 8Jw2nQxK5vTbR3mYcLdZaE
          product_name: Acme Smart Kettle
      properties:
        id:
          description: >-
            URL-safe 22-character shortuuid encoding of the row's UUID primary
            key. Stable across the row's lifetime; suitable for sharing in URLs,
            log lines, and external SDK clients. Accepted on input as either the
            shortuuid form or the canonical UUID form
            (``xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx``).
          format: shortuuid
          maxLength: 22
          minLength: 22
          pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
          title: Id
          type: string
        gtin:
          description: The product's GTIN, normalized to GTIN-14.
          title: Gtin
          type: string
        product_name:
          description: The product's name. Empty string when unknown.
          title: Product Name
          type: string
      required:
        - id
        - gtin
        - product_name
      title: FirmwareProductOut
      type: object
  securitySchemes:
    APIKeyHeaderAuth:
      type: apiKey
      in: header
      name: X-API-Key
    OAuthTokenAuth:
      type: http
      scheme: bearer
    CookieGatedSessionAuth:
      type: apiKey
      in: cookie
      name: sessionid

````