API overview
The concepts every integration needs: where the API lives, the two credentials, organization scoping, timestamps, and error codes. Part of the documentation.
Base URL
Every path in this reference hangs under the product-namespaced base (one prefix per product under the shared domain):
https://filodos.gr/filodos-dashboard/api/scoring
Before 2026-10-10 the product had the name Avlo. Two older base URLs on the old domain still work. They answer as before and do not redirect:
https://avloinnovation.gr/api/scoring
https://avloinnovation.gr/avlo-fleet-management/api/scoring
These URLs work until the old domains expire (about September 2027). Change each feed, ERP connector, and webhook client to https://filodos.gr before that date. Old API keys and old webhook headers also keep working. See Authentication.
The older root form, https://filodos.gr/api/scoring, serves the same endpoints and stays working for existing feeds. New integrations should use the namespaced form above. All requests and answers are JSON. All reads sort newest first unless the page says otherwise.
Versioned paths
Feed reads also live under a /v1/ prefix with stable paths: /v1/fleet, /v1/trips, /v1/events, /v1/telemetry, /v1/telemetry/samples, /v1/scores, /v1/drivers, /v1/assignments, /v1/positions, /v1/visits, /v1/reports/daily, /v1/reports/weekly, /v1/reports/history, /v1/analytics/daily, /v1/analytics/trips, /v1/analytics/events, /v1/analytics/visits, and /v1/analytics/vehicles. Each one takes the documented parameters, needs its key scope, and returns JSON. Build new integrations against /v1/: those paths stay put while unversioned paths may evolve. See one page per function in this reference for parameters and shapes.
curl "https://filodos.gr/filodos-dashboard/api/scoring/v1/trips?device_id=12" \
-H "Authorization: Bearer [REDACTED]…"
Two credentials
Both go in the Authorization header as a bearer credential:
Authorization: Bearer <token-or-key>
- Sign-in token.
POST /auth/loginwith organization, email, and password returns a token that expires. Use it for interactive tools and one-off scripts. See Authentication. - API key. A value starting with
filodos_, created by an administrator on the Organization → API keys page. It never expires until revoked, and it carries scopes that limit exactly which read families it may call. Use it for server-to-server feeds. See API key management and the setup guide.
Keys never write. Management endpoints (keys, webhooks, users) need an administrator sign-in.
Organization scoping
Every read filters to the credential's organization. A device id, driver id, or name from another organization reads as unknown — the API answers 404 rather than confirming it exists. Match plates and driver names once against the fleet list, then read on schedule.
Timestamps
Timestamps are ISO-8601 strings that always carry their UTC offset, for example 2026-10-05T08:00:00+00:00. The dashboard shows fleet-local time (Europe/Athens); the API returns the stored instants — convert at your side for display.
Error codes
| Status | Meaning |
|---|---|
400 | Bad combination of parameters (the message says which). |
401 | Missing, expired, or revoked credential. Sign in again or replace the key. |
403 | Valid credential, not allowed here: an admin-only endpoint, a missing key scope, or a driver login outside its scope. |
404 | Unknown id — or another organization's id, which reads the same way. |
422 | Invalid input: a malformed date, an empty name, an unknown scope or event. |
429 | Too many requests on a rate-limited endpoint (pre-orders, report e-mails). |
502 / 503 | An upstream dependency failed (a webhook receiver, the mail server) or is unconfigured. |