# Basis > Basis (formerly Centro; legally Basis Technologies) is an advertising automation > platform. Its Basis Platform API is a read-only REST API over agency, client, > brand, campaign, line-item, inventory and delivery-performance data for > omnichannel media buying across display, video, audio, native, connected TV, > DOOH and site-direct channels. Generated by API Evangelist from the Basis Platform API contract and the public Basis developer surface. Basis does not publish an llms.txt of its own (https://basis.com/llms.txt -> 404, https://api.basis.net/llms.txt -> 404, probed 2026-08-13). Source of record: https://api.basis.net/swagger.json ## The API in one paragraph Base URL `https://api.basis.net/v1`. Sandbox `https://api-sandbox.basis.net/v1` (documented by Basis; the host did not resolve from a public resolver on 2026-08-13). OAuth 2.0 only — obtain a token from `https://auth.basis.net/oauth/token` with `audience=https://api.basis.net`, then send `Authorization: Bearer `. Credentials are NOT self-serve: Basis issues them to customers and integration partners through a representative. All 31 published operations are `GET` — nothing in the public contract creates or modifies data. ## Authentication - Authorization server: https://auth.basis.net (OpenID Connect discovery at https://auth.basis.net/.well-known/openid-configuration) - Grants: `authorization_code` (returns a refresh token when `offline_access` is requested), `client_credentials` (machine-to-machine; requires an owner/agency ID or the token endpoint returns 401), `refresh_token` - Deprecated: the `password` grant - Scopes requested in the documented authorize URL: `openid profile email offline_access` - No resource-level scopes are published; access is bounded by the credential's agency, not by scope strings - Token issuance quota: 10 client-credentials tokens per hour, 25 per day (429 when exceeded) ## Conventions - Pagination: cursor. Send `?cursor=`, read `metadata.cursor` from the response; `null` means last page. `metadata.page_size` and `metadata.total` are also returned. There is NO page-size parameter. - Envelope: lists return `{ "metadata": {...}, "data": [...] }`; single reads return `{ "data": {...} }`. - Filtering: `query` (free text, per-endpoint fields), foreign-key filters (`client_id`, `brand_id`, `campaign_id`, `line_item_id`), `status` on campaigns (`live|approved|completed`), `start_date`/`end_date` on stats. - Identifiers are NOT uniform: UUID v4 for most objects, numeric strings for verticals and KPIs, a 40-character alphanumeric for creatives. A mismatch returns 400 echoing the expected regex. - Errors: `{"message": ...}` — not RFC 9457, and there is no machine-readable error code. Routing errors add `error` and `statusCode`. - Rate limit: 75,000 requests/hour per API user across all endpoints; 429 on exhaustion. No RateLimit-* response headers are published or observed. - Versioning: URI path, `v1`. No changelog, no status page, no deprecation policy. - Idempotency: not published (the surface is read-only). ## Resources - `GET /v1/me` — the authenticated user (404 under a client-credentials token) - `GET /v1/agency` — the buying organization - `GET /v1/clients`, `GET /v1/clients/{id}` — advertisers the agency represents - `GET /v1/brands`, `GET /v1/brands/{id}` — brands, with verticals/subverticals - `GET /v1/campaigns`, `GET /v1/campaigns/{id}` — media initiatives (client_id, brand_id, budget, objectives, KPI, flight dates) - `GET /v1/campaigns/{campaign_id}/line_items`, `.../line_items/{id}` — individual media purchases / programmatic buys - `GET /v1/campaigns/{campaign_id}/addons`, `.../addons/{id}` — non-media fees on a campaign - `GET /v1/groups`, `GET /v1/groups/{id}` — budget and pacing containers - `GET /v1/tactics`, `GET /v1/tactics/{id}` — targeting/bidding strategies within a group - `GET /v1/vendors`, `GET /v1/vendors/{id}` — inventory sellers - `GET /v1/properties`, `GET /v1/properties/{id}` — inventory (advertising space) - `GET /v1/creatives`, `GET /v1/creatives/{id}` — ad units - `GET /v1/verticals`, `GET /v1/verticals/{id}` — market/category taxonomy - `GET /v1/kpis`, `GET /v1/kpis/{id}` — key performance indicators and goal types - `GET /v1/conversions`, `GET /v1/conversions/{id}` — tracked conversion definitions - `GET /v1/delivery_sources`, `GET /v1/delivery_sources/{id}` — sources behind delivery data - `GET /v1/stats/{scope}` — delivery and performance metrics; scope is one of `line_item`, `daily_by_line_item`, `daily`, `daily_by_conversion` ## Relationships (published by Basis) Campaigns have 1 client, 1 brand, many line items, many add-ons. Line items have 1 campaign, 1 property, 1 vendor. ## Docs - API specification (OpenAPI 3.0.0): https://api.basis.net/swagger.json - Enterprise API overview: https://basis.com/technology/enterprise-api - Contact / credentials: https://basis.com/connect - Sign in: https://platform.basis.net/auth/login - Privacy policy: https://privacy.basis.com/ - Blog: https://basis.com/blog ## What Basis does NOT publish No SDK or client library in any package registry. No CLI. No MCP server. No A2A agent card. No webhooks or AsyncAPI. No changelog, status page or SLA. No security.txt, trust center or vulnerability-disclosure program. No Postman collection. No public pricing — enterprise contract only. ## API Evangelist artifacts - OpenAPI: openapi/basis-analytics-api-openapi.yml - Authentication: authentication/basis-authentication.yml - OAuth scopes: scopes/basis-scopes.yml - Conventions: conventions/basis-conventions.yml - Errors: errors/basis-problem-types.yml - Lifecycle: lifecycle/basis-lifecycle.yml - Rate limits: rate-limits/basis-rate-limits.yml - Sandbox: sandbox/basis-sandbox.yml - Data model: data-model/basis-data-model.yml - Conformance: conformance/basis-conformance.yml - Well-known probe: well-known/basis-well-known.yml - Candidate MCP tools: mcp/basis-mcp.yml - Agent skills: skills/_index.yml - Agentic access: agentic-access/basis-agentic-access.yml - Catalog entry: https://apis.io/basis