# Bigtincan > Bigtincan is a sales enablement platform. Its Bigtincan Hub Public API is a > Swagger 2.0 REST API at https://pubapi.bigtincan.com covering sales content > (stories and files), content organisation (channels, tabs, tags, bookmarks), > identity and permissions (users, groups, user metadata), external distribution > (public file shares, story sharing), forms, search, CRM story recommendations > and interaction tracking. 69 operations across 62 paths. Generated by API Evangelist on 2026-08-14. Bigtincan does not publish an llms.txt of its own — /llms.txt returns 404 on www.bigtincan.com, help.bigtincan.com and pubapi.bigtincan.com. This file is generated from the provider's published Swagger document and from artifacts in the api-evangelist/bigtincan repo. Source of the contract: https://pubapi.bigtincan.com/api/sandbox/swagger/public-api ## What an agent needs to know first - Base URL: https://pubapi.bigtincan.com - Auth: OAuth 2.0 only. POST https://pubapi.bigtincan.com/services/oauth2/token with grant_type=password plus client_id, client_secret and api_key, or use the authorization code flow at /services/oauth2/authorize. Send `Authorization: Bearer `. Revoke at /services/oauth2/revoke. - Delegation: `As-User: USER_ID` acts on behalf of a tenant user. Available ONLY with the password grant. Admin operations do not honour it. - Scopes: none published. Authorization is decided by the Hub role of the authenticating user, so a 403 cannot be predicted from the token. - Versioning: the version is the FIRST PATH SEGMENT and differs per operation. /v1, /v1.1, /v1.2 and /v1.3 are all live simultaneously. - Pagination: `page` and `limit` query parameters. limit defaults to 10, max 100. - Errors: `{"error":{"scope","code","message"},"trace_id"}` as application/json. NOT RFC 9457. Only observable code without credentials is INVALID_TOKEN on 401. - Idempotency: NONE. There is no Idempotency-Key. Treat every POST create as at-most-once and read back before retrying. - Rate limits: not published, and no RateLimit/Retry-After headers are returned. - Responses: no operation declares a response schema. Expect untyped JSON. ## API reference - Interactive console (the live reference): https://pubapi.bigtincan.com/doc/interactive/ - Swagger 2.0 document: https://pubapi.bigtincan.com/api/sandbox/swagger/public-api - Note: the documentation URL long carried in directories, https://help.bigtincan.com/help/bigtincan-public-api-documentation, now returns 404. ## Operation surface by resource - Story (13 operations): publish, list, update by revision, get by permanent id, search, tag, archive, comment, share by email, upload file, read widgets, CRM recommendations. - File (5): list, get details, add tags, allowed extensions, search. - Channel (8): create, list, get by ids, create personal, update, delete, admin list, admin modify. - Tab (7): create, list, delete, admin list, admin modify, grant groups, revoke group. - Group (8): create, list, add users, admin list, admin get, admin modify, admin delete, remove user. - User (8): create, update, current user, delete, admin list, admin get, change password, forgot password. - User Metadata (3): list all, get for user, update for user. - Public File Share (6): list, create, get, delete, add file, remove file. - Tag (1): list tenant tags. - Bookmark (1): list bookmarked stories and files. - Event (1): list a user's events. - Form (5): list forms, get form, get form data, get submitted file, list categories. - History (1): record user interactions. - Links (1): resolve a URN to its links. - Settings (1): read tenant settings. ## Repo artifacts - OpenAPI (as served, verbatim): openapi/_original/bigtincan-hub-api-swagger.json - OpenAPI (with server, security and operationIds added): openapi/bigtincan-hub-api-openapi.json - What we added and why: overlays/bigtincan-hub-api-overlay.yaml - Authentication: authentication/bigtincan-authentication.yml - Conventions: conventions/bigtincan-conventions.yml - Errors: errors/bigtincan-problem-types.yml - Data model: data-model/bigtincan-data-model.yml - Lifecycle: lifecycle/bigtincan-lifecycle.yml - Conformance and compliance: conformance/bigtincan-conformance.yml - Rate limits: rate-limits/bigtincan-rate-limits.yml - Plans and pricing: plans/bigtincan-plans-pricing.yml - Packages and SDKs: packages/bigtincan-packages.yml - Well-known probe (all 404): well-known/bigtincan-well-known.yml - MCP candidate (no server exists): mcp/bigtincan-mcp.yml - Agent skills: skills/_index.yml ## What does not exist - No MCP server, hosted or stdio. - No A2A agent card at any well-known path. - No webhooks, events or streaming surface, and therefore no AsyncAPI. - No GraphQL or gRPC surface. - No first-party SDK for the REST API in any language. The only first-party npm packages wrap the Hub JavaScript Bridge, not the API. - No CLI. - No public sandbox or test tenant. - No /.well-known/ documents of any kind, including security.txt and oauth-authorization-server. - No API changelog. The seasonal release page https://www.bigtincan.com/seasonal-releases/ is product marketing and still showed "Fall 2025 Release" on 2026-08-14. ## Company - Website: https://www.bigtincan.com/ - Pricing (contact sales only): https://www.bigtincan.com/pricing/ - Status: https://status.bigtincan.com/ - Trust center: https://trust.bigtincan.com/ (operated as "Showpad + Bigtincan"; SOC 2 Type II, ISO 27001, ISO 27701) - Login: https://identity.bigtincan.com - EULA: https://www.bigtincan.com/eula/ - Privacy: https://www.bigtincan.com/privacy-policy/ - Acceptable use: https://www.bigtincan.com/acceptable-use-policy/ - Blog: https://www.bigtincan.com/blog/ - Contact: https://www.bigtincan.com/contact/