HEXLE API

Rest-API

1.17.0

Checkout Expansion, Account Management, and Enhanced Security 08.06.2026

Opening the file manager now reveals a navigable directory tree, with files downloadable directly via link.

The field holding a permission's user description is now called "permissionUserDescription" in the API.

Customer products can now be created with a custom product name even when there's no Store catalog entry behind them.

Customer deletion now runs through a single endpoint, with permanent deletion available as an optional parameter.

Editing a ticket type no longer triggers the personalization lock by mistake when the setting itself hasn't actually changed.

Administrators now have dedicated endpoints for audit logs, including analytics and export.

Timesheet files are now automatically filed into subfolders.

Discount codes have been migrated from ticketing into the central Store system.

A new instructor area brings together guides, access control, and public-facing documentation.

Course bookings now display an actual booking confirmation on the checkout page instead of the incorrect "being prepared" message shown before.

A new export feature lets users create and manage Excel exports, complete with presets and background jobs.

Employees with active email delivery are now safeguarded against accidental deletion.

The pending-invitations popover on the dashboard now opens correctly in the bottom-right corner instead of in the wrong spot as before.

Real-time events now reach all of a staff member's open sessions reliably, since delivery is routed through the active session rather than the anonymous handshake identity.

A duplicated database migration version has been corrected, and two export permissions now carry distinct names.

When a staff member switches companies, their other open tabs now automatically update to the new tenant via a real-time event.

A critical bug affecting registration during the GDPR flow has been resolved.

The API response for module permissions has been renamed to avoid naming conflicts in the API documentation.

The address field in guest checkout now suggests matching addresses automatically, protected by session validation and rate limiting.

Users can now delete their account or company via email confirmation, with a clearly defined grace and lock period plus a dashboard banner ensuring financially relevant data is retained until the deletion becomes final.

User status and presence changes are now broadcast in real time over WebSocket, eliminating the frontend's previous polling.

New endpoints list a user's organizations and companies and let them switch companies directly through the API in a staff-aware way.

The checkout product page now displays the seller's company name, address, VAT/tax number, and contact link.

Confirmation and informational emails now address customers by name instead of using a formal greeting.

Buyers can now leave feedback on their order right after a successful checkout.

The dashboard now includes a new overview listing all products available to the user.

Ticket shops and ticket types now support custom-defined additional fields, including public-facing management.

System admins can now review incoming dependency audit reports from GitLab repositories and notify repo maintainers by email.

API keys can now be created and managed with their own roles and permissions, inherited from a template staff member.

Incoming security audit reports can now be assigned to a subproject and also display the GitLab project name.