REST API overview

What the FitManager REST API covers, how responses, pagination and errors work, and where to find the full OpenAPI specification.

4 min read Updated 04.10.2026 Requires: API access

The FitManager REST API lets your own software work with your gym's members, plans, check-ins, products and sales. This page is a map of what is available. Start with API keys to get a key.

The basics

Base URL https://fitmanager.com/api/v1 (shown as Base URL on the API keys card)
Authentication Authorization: Bearer fm_live_... or X-Api-Key: fm_live_...
Format JSON in and out. Send Accept: application/json
Rate limit 120 requests per minute per key, 429 with Retry-After above that
Scope One gym per key. Records from other gyms return 404
Retries Add an Idempotency-Key header to writes so a repeat does not run twice (kept for 24 hours)

Endpoints

Method and path What it does Filters
GET /members List members, newest first status, search (name and email)
GET /members/{id} One member
POST /members Create a member. first_name and last_name are required; email, phone, gender, date_of_birth, city, country, status (active or inactive) and facility_id are optional
PUT or PATCH /members/{id} Update the fields you send
GET /memberships, GET /memberships/{id} Your membership plans
GET /membership-subscriptions, GET /membership-subscriptions/{id} Recurring subscription plans
GET /attendance (also /access-logs) Check-ins and access log entries member_id, status, from, to
GET /products, GET /products/{id} Products status
GET /purchases, GET /purchases/{id} Sales member_id, payment_status
GET /statistics Member counts, active memberships, facilities and this month's paid revenue
POST /webhook-deliveries/{id}/redeliver Send a webhook delivery again
POST /import/{entity}, GET /import/status Bulk import from another gym system

When you create a member without facility_id, they go to your first facility.

Lists and pagination

List endpoints return 25 records per page by default. Use per_page (up to 100) and page to move through them:

curl "https://fitmanager.com/api/v1/members?status=active&per_page=100&page=2" \
  -H "Authorization: Bearer fm_live_your_key_here" \
  -H "Accept: application/json"

The response has the records in data, page links in links (first, last, prev, next) and counts in meta (current_page, last_page, per_page, total). Keep requesting links.next until it is null.

Every record carries an object field, such as "object": "member", so you can tell types apart.

Errors

Key, plan and payment errors (401, 402, 403) come back as JSON with an error object:

{ "error": { "type": "unauthorized", "message": "Invalid or missing API key." } }
Status Meaning
401 The key is missing, wrong, revoked or retired
402 Your FitManager subscription is unpaid past its grace period
403 Your plan does not include the feature this endpoint needs
404 The record does not exist or belongs to another gym
422 Validation failed. The response has a message and the problem fields under errors
429 Too many requests. Wait for the Retry-After seconds

Importing from another system

POST /import/{entity} moves data from a previous gym system in batches of up to 500 rows. Send entities in this order: plans, members, memberships, attendance, access_logs, products, purchases. Every row carries a legacy_id, the id it had in the old system, so rows that were already imported are skipped and you can safely resend a batch. GET /import/status shows how many rows of each kind have arrived. For imports from a spreadsheet instead, see Import members.

The OpenAPI specification

The full specification, with every field and response, is an OpenAPI 3 file (openapi.yaml). It is not published at a public address yet. To get the current copy for your developer, open a support ticket and ask for the FitManager API specification. You can load the file into tools such as Postman or Swagger UI to explore and test the API.

Other APIs

Site API for websites

If you build your own gym website, use the Site API instead. It uses a publishable key that is safe to put in browser code and only exposes what your public website already shows, such as plans, classes and blog posts, plus the contact and newsletter forms. See Website API.

Device endpoints

FitManager Control, the Windows app at your front desk, uses its own endpoints under the same /api/v1 address: door polling and doorbell, fiscal printer jobs, card terminal jobs and kiosk orders. They use the same API keys but have a higher rate limit and are licensed by the device features on your plan rather than by API access. They are internal to FitManager Control and not meant for your own integrations. See FitManager Control.

Webhooks

To be told about changes instead of polling for them, set up webhooks.

Newsletter

Get tips in your inbox

One email a month: what we shipped, what gym owners asked for, and one practical idea for running the floor. No spam, unsubscribe in one click.

Unsubscribe any time. We never share your address.

We use cookies to keep you signed in, remember your preferences, and understand how the site is used. Privacy Policy