HEXLE API
Rest-API
1.16.0
Customer Management and New Permissions System 01.06.2026Shops and courses can now define a preferred payment method that is automatically preselected at checkout.
Help articles for the HEXLE Control Center can now be managed centrally and published publicly.
Deleted customer numbers are no longer reused when new numbers are assigned automatically.
Companies can now upload and manage their own logo in addition to the preview image.
Time tracking now supports creating, editing, and deleting reusable booking templates.
The previously missing configuration for permission and login mapping has been added for the Editor and HEXLE Control Center projects.
Existing user accounts can no longer be assigned directly to a company and must instead be linked through an email invitation.
Trying to delete a file that is still in use now returns a clear message listing the referencing objects instead of a server error.
Login to the HEXLE Control Center is now restricted exclusively to system administrators.
An internal error in the database query used to check references to ticket shop sponsor images has been fixed.
The internal admin dashboard along with the login and account pages have been redesigned with a new look, including a frontend preview populated with test data.
Role and permission management for employees has been fundamentally restructured.
Revoking roles and permissions now runs its own dedicated permission checks instead of reusing the ones meant for assignment.
The refresh-token cookie name is now configurable per environment, so logins in dev, UAT, and prod no longer overwrite one another.
Customers can now manage products, contracts, and license modules along with their corresponding activations.
A new audit system now logs API access, login events, system actions, and other activity for full traceability.
Re-inviting employees now works reliably, even when a previous invitation had expired or been declined.
Users can now change their own username from their profile once per year.
Changes to roles and permissions now take effect immediately, since they're read live from the database instead of stale token data.
Employees and staff can now be created and displayed with a set of initials.
Error and success messages in the admin dashboard now appear consistently as toast notifications instead of inline banners.
Changing your own username now terminates all sessions server-side, requiring the user to log in again.
A bug that prevented password change requests from being created via the API has been fixed.
Addresses can now also be categorized as "Work" or "Private".
Setting a new primary contact for a customer now automatically replaces the previously assigned one.
Numerous input fields now enforce a maximum character length on the server side.
Creating and editing tax rates now validates the validity period and allows only one default rate per tax type.
Authorized administrators can now view all timesheets across a company.
The ticket overview now shows the stored deletion reason for deleted tickets.
A company's logo and preview image are now automatically marked as public so they display correctly when switching companies.
The path display in file management now scrolls horizontally for long folder paths and automatically jumps to the current folder.
Bank details permissions are now part of the Core permission group instead of a separate Finance group.
Creating or editing employees now checks that the email address isn't already in use within the company.
Customers now clearly expose their type (private or company) along with a completeness status in the API response.
Creating or editing a worker now checks the email address for uniqueness within the company.
At checkout, providing a company name now automatically creates a business customer instead of a private one.
Security permissions can now be given plain-language descriptions aimed at non-technical users.
Customers with no existing links to contracts, invoices, or time tracking can now be deleted.
Customers can now be tagged, searched by tag, and assigned tags in bulk.
After logging in, users now land directly on any pending invitations and can accept them right from the dashboard.
Ticket types now support a preview image that can also be displayed through inheritance.
The customer project list now includes inactive projects as well.
Transactional emails now link the "Why this email" notice straight to the relevant terms and conditions instead of the general homepage.
The frontend now receives company switches and other events in real time over WebSocket instead of through polling.
Reminder and follow-up emails for course dates now go out only for actually confirmed registrations, not for mere date availabilities.
Address fields now offer live suggestions as you type.
Customers can now be duplicated into a new record with one click, complete with an automatically assigned customer number.
Venues can now be managed as their own account, giving them visibility into shops, statistics, and tickets sold at their addresses.
The "My Hexle Products" overview has been temporarily hidden from the dashboard.