Programmatic REST access to Nimbio community access control — keys, latches, members, opens, access logs and messaging. Turn any gate into software.
The Nimbio API is a REST API for programmatic access to Nimbio's cellular smart-gate access control platform — opening gate latches, granting and revoking community member keys, sending community messages, and reading access logs, all authenticated with a scoped API key over HTTPS. The Nimbio API is served from api.nimbio.com and is documented with an interactive OpenAPI reference, downloadable Postman and Bruno collections, and an official Python SDK.
Every endpoint takes a bearer token. Use a nimbio_test_… key to explore safely — it runs the full pipeline (auth, rate limit, scope, validation) but never fires a gate or mutates data. Switch to nimbio_live_… for real side effects.
/v1/community/*) need a community-scoped key from a community manager.429 with a Retry-After header. Limit headers are returned on every response.request_id for support.Interactive references generated from the live OpenAPI schema, plus official clients for Python and TypeScript/JavaScript and an MCP server for AI assistants.
The full reference, grouped into Account and Community APIs. Browse endpoints, schemas, and examples in one place.
Build on your own account: read your keys and their latches, and open your latches. Uses an account API key.
Build for a community you manage: gate status, members, member keys, opens, and access logs. Uses a community API key.
Interactive reference. Click Authorize, paste a key, and call endpoints live from the browser.
A clean, readable three-panel view of the same reference — good for skimming the whole API.
Official Python client, synchronous and asynchronous. Install with pip install nimbio-community-api.
Official TypeScript/JavaScript client — zero dependencies, runs in Node, the browser, Deno, Bun, and edge. Install with npm install @nimbio/community-api.
Official Model Context Protocol server — connect Claude, ChatGPT, Cursor or any MCP client and run your community in plain language. Read-only by default. Run with npx -y @nimbio/mcp-server.
Yes — Nimbio publishes an official Model Context Protocol server. Connect Claude, ChatGPT, Cursor or any MCP client and work in plain language instead of code. It is built on the TypeScript SDK, so it reaches the same API surface.
Add this to your assistant’s MCP configuration. There is nothing to clone and nothing to build.
Start with a test key. Test keys run the full pipeline — authentication, rate limiting, permissions, validation — and then simulate, so no gate opens and nobody is messaged. Everything below is safe to explore with one.
Coverage spans gates and hold opens, members and keys, guest links, access codes and GuestView Entry, the access and audit logs, community settings, hardware, and webhooks.
The cautious answer is the default in every case.
A fresh install can see the whole community and change nothing. Write access is a deliberate step.
A live key registers zero write tools without NIMBIO_MCP_ALLOW_LIVE, so a hurried install can only look.
Opening a gate, holding one open, revoking a guest link, removing a home, replaying webhooks, switching access-code mode and messaging every member all stop and confirm first. The assistant cannot answer that prompt for you.
A guest link opens your gate for anyone holding it, so its token and URL are redacted unless you explicitly ask for them.
Results are labelled TEST MODE or LIVE and name the host they came from.
Everything is set through environment variables in your MCP configuration.
NIMBIO_MCP_MODE=write, and for a live key also NIMBIO_MCP_ALLOW_LIVE.NIMBIO_ENV defaults to prod. Every result names the host it came from, so check there first.NIMBIO_API_KEY.The repository README and CHANGELOG carry the full tool list, the confirmation behaviour, and the release history.
Kept in sync with the live API. Import a collection, or codegen straight from the OpenAPI spec.
The full machine-readable OpenAPI 3 spec — import into any client or codegen tool.
Ready-to-run Postman collection with every endpoint, plus dev / prod / local environments.
The same requests as a Bruno collection (open-source API client) — download and open the folder.
Yes. Every endpoint accepts test keys (prefixed nimbio_test_) that run the full request pipeline — authentication, rate limiting, scope checks, and validation — but never fire a gate or mutate data; writes come back simulated. Switch to a live key (nimbio_live_) only when you want real side effects.
Two official clients with matching endpoint coverage: a Python client (nimbio-community-api on PyPI, pip install nimbio-community-api) with synchronous and asynchronous interfaces, and a TypeScript/JavaScript client (@nimbio/community-api on npm) that runs in Node, the browser, Deno, Bun, and edge runtimes. Every endpoint is also reachable directly over HTTPS, and importable Postman and Bruno collections are available on this page. For AI assistants there is also an official MCP server, @nimbio/mcp-server on npm.
Yes. Nimbio publishes an official Model Context Protocol (MCP) server, @nimbio/mcp-server on npm, which connects any MCP client — Claude, ChatGPT, Cursor and others — to a community you manage. Run it with npx -y @nimbio/mcp-server and an API key, and you can ask for gate status, access-log history, member and key changes, guest links and hold opens in plain language. It is built on the TypeScript SDK, so it covers the same API surface.
The MCP server is built so the cautious answer is the default. It starts in read-only mode, so a fresh install can read everything and change nothing. A live key registers no write tools at all unless you set NIMBIO_MCP_ALLOW_LIVE, so the worst outcome of a hurried setup is an assistant that can only look. Anything irreversible — opening a gate, holding one open, revoking a guest link, removing a home, messaging every member — stops and asks a person first, and the assistant cannot answer that prompt on your behalf. Guest-link tokens are redacted unless you ask for them, and every result is labelled TEST MODE or LIVE. Start with a test key, which simulates every write.
Yes. Requests are limited per minute and per month, with separate counters for test and live keys. When you exceed a limit the API returns HTTP 429 with a Retry-After header telling you how long to wait, and the current usage is returned on every response in X-RateLimit headers.
No. The interactive documentation at /docs and /redoc, and the raw OpenAPI specification at /openapi.json, are public — you can browse the entire API reference without a key. An API key is only needed to actually call an endpoint.