---
title: Kisi API Integration on Truto
slug: kisi
category: Security
canonical: "https://truto.one/integrations/detail/kisi/"
---

# Kisi API Integration on Truto



**Category:** Security  
**Status:** Beta

## MCP-ready AI tools

Truto exposes 229 tools for Kisi that AI agents can call directly.

- **list_all_kisi_calendar_summaries** — Get a summary of a Kisi scheduleable's calendar events for a time window. Returns: events, exceptions, schedules_by_day. Duration-only around values are not supported. Required: around, consequence.
- **list_all_kisi_cameras** — List Kisi cameras. Returns camera objects including id, name, description, status, enabled, place_id, lock_id, and snapshot/clip settings. Supports filtering and name-based sorting.
- **create_a_kisi_camera** — Create a Kisi camera. Returns the created camera object including id, resource_type, name, description, enabled, status, created_at, place_id, and lock_id. Required: camera.
- **get_single_kisi_camera_by_id** — Get a Kisi camera by id. Returns the full camera object including id, name, description, status, enabled, place_id, and lock_id, plus integration details for Rhombus Systems cameras. Required: id.
- **update_a_kisi_camera_by_id** — Update a Kisi camera by id, changing attributes such as name, description, enabled state, lock assignment, or snapshot and clip settings. Returns an empty 204 response on success. Required: id, camera.
- **delete_a_kisi_camera_by_id** — Delete a Kisi camera by id. Returns an empty 204 response on success. Required: id.
- **get_single_kisi_camera_video_link_by_id** — Get a Kisi camera video link by id. Returns the url of the camera's video stream. Required: id.
- **list_all_kisi_card_assignments** — List card assignments in Kisi, filterable by assignee, card, and status. Returns card assignment objects including id, resource_type, status, assignee_type, assignee_id, card_id, two_factor_pin, created_at, updated_at, and created_by.
- **create_a_kisi_card_assignment** — Create a card assignment in Kisi, linking a card to a user or guest assignee. Returns the created assignment including id, status, assignee_type, assignee_id, card_id, two_factor_pin, created_at, and created_by. Requires a card_assignment object with assignee_type, assignee_id, and card_id. Required: card_assignment.
- **get_single_kisi_card_assignment_by_id** — Get a single card assignment in Kisi by id. Returns the assignment including id, resource_type, status, assignee_type, assignee_id, card_id, two_factor_pin, created_at, updated_at, and created_by. Required: id.
- **update_a_kisi_card_assignment_by_id** — Update a card assignment in Kisi by id, e.g. to set or clear its two factor pin. Accepts a card_assignment object with two_factor_pin and send_two_factor_pin_notification. Returns an empty 204 response on success. Required: id, card_assignment.
- **delete_a_kisi_card_assignment_by_id** — Delete a card assignment in Kisi by id, unassigning the associated card. Returns an empty 204 response on success. Required: id.
- **kisi_card_assignments_activate** — Activate a card assignment in Kisi by id. Returns an empty 204 response on success. Required: card_assignment_id.
- **kisi_card_assignments_deactivate** — Deactivate a card assignment in Kisi by id. Returns an empty 204 response on success. Required: card_assignment_id.
- **create_a_kisi_card_assignment_activate_with_token** — Activate a card assignment in Kisi using its activation token. Returns an empty 204 response on success. Required: activation_token.
- **list_all_kisi_cards** — List cards in Kisi. Returns card records with id, type, token or uid, model, frequency, third_party, last_used_at, and created_at. Filter by status, token, uid, data_block_value, or LF card identifiers. Max 250 per page.
- **create_a_kisi_card** — Create a card in Kisi by registering its token or UID. Returns the created card with id, type, token or uid, model, frequency, and third_party.g. token and type for mifare_desfire, uid and type for third_party_hf).
- **get_single_kisi_card_by_id** — Get a single card in Kisi by id. Returns the card record including id, type, token or uid, model, frequency, third_party, and last_used_at. Required: id.
- **update_a_kisi_card_by_id** — Update the two-factor PIN settings of a card in Kisi by id. Returns an empty 204 response on success. This endpoint and its two_factor_pin fields are deprecated upstream. Required: id, card.
- **delete_a_kisi_card_by_id** — Delete a card in Kisi by id. Returns an empty 204 response on success. Required: id.
- **kisi_cards_assign** — Assign a Kisi card to a user as their primary card; if the user already has a primary card, the card is assigned as backup. Returns an empty 204 response on success.email. Required: card_id, card.
- **kisi_cards_activate** — Activate a Kisi card by id. Only cards that have already been assigned can be activated. Returns an empty 204 response on success. Required: card_id.
- **kisi_cards_deactivate** — Deactivate a Kisi card by id. Returns an empty 204 response on success. Required: card_id.
- **create_a_kisi_card_deassign** — Deassign a card in Kisi by id. Returns an empty 204 response on success. This endpoint is deprecated upstream. Required: card_id.
- **create_a_kisi_card_activate_with_token** — Activate a card in kisi by its activation token; only assigned cards can be activated. Returns an empty 204 response on success. This endpoint is deprecated. Required: activation_token.
- **list_all_kisi_controller_input_connections** — List the controller input connections of a Kisi controller, covering contact sensor, request-to-exit, third-party alarm, and tamper detection types. Returns: id, created_at, updated_at, type, name. Required: controller_id.
- **create_a_kisi_controller_input_connection** — Create a controller input connection in Kisi for a controller input. Returns the created connection with id, name, type, controller_input, lock, zone, action, and enabled.
- **get_single_kisi_controller_input_connection_by_id** — Get a single Kisi controller input connection by id. Returns: id, created_at, updated_at, type. Required: id.
- **update_a_kisi_controller_input_connection_by_id** — Update a Kisi controller input connection by id; accepts only the fields editable for its type (e.g. name, enabled, duration, action, end-of-line settings). Returns an empty 204 response on success. Required: id.
- **delete_a_kisi_controller_input_connection_by_id** — Delete a Kisi controller input connection by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_controller_inputs** — List controller inputs in Kisi for a specific controller. Returns: id, channel, name, type, status, created_at, updated_at, controller_id, controller_input_connection_id. The type field is only populated for Controller Pro 1.0 and 1.1 controllers. Required: controller_id.
- **list_all_kisi_controller_relay_connections** — List Kisi controller relay connections for a given controller. Returns: id, created_at, updated_at, type, name. Required: controller_id.
- **create_a_kisi_controller_relay_connection** — Create a Kisi controller relay connection linking a controller relay to a lock, elevator stop, siren, or third-party alarm zone. Returns: id, created_at, updated_at, name, type, duration, controller_relay_id, controller_relay, lock_id, lock, elevator_stop_id, elevator_stop, zone_id, zone, duration_for_away_mode, duration_for_stay_mode.
- **get_single_kisi_controller_relay_connection_by_id** — Get a single Kisi controller relay connection by id. Returns: id, created_at, updated_at, type, name. Required: id.
- **update_a_kisi_controller_relay_connection_by_id** — Update a Kisi controller relay connection by id. Accepts a new name, relay duration, or third-party alarm away/stay mode durations. Returns an empty 204 response on success. Required: id.
- **delete_a_kisi_controller_relay_connection_by_id** — Delete a Kisi controller relay connection by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_controller_relays** — List Kisi controller relays for a given controller. Returns: id, channel, name, status, aux, created_at, updated_at, controller_id, controller_relay_connection_id. Required: controller_id.
- **list_all_kisi_controllers** — List Kisi controllers. Returns each controller's id, name, description, created_at, device_id, model, online status, token, place_id, and its associated place. Max 250 per page.
- **kisi_controllers_assign** — Assign a Kisi controller by its token, binding it to a name and place. Returns an empty 204 response on success. Required: token, controller.
- **get_single_kisi_controller_by_id** — Get a single Kisi controller by id. Returns the full controller object including id, name, device_id, model, network and IP details, online status, token, and its place. Required: id.
- **update_a_kisi_controller_by_id** — Update a Kisi controller by id, optionally changing its name, description, or zone_controller flag. Returns an empty 204 response on success. Required: id, controller.
- **create_a_kisi_controller_deassign** — Deassign a controller in Kisi, removing its current assignment. Returns an empty 204 response on success. Required: controller_id.
- **create_a_kisi_controller_reboot** — Reboot a controller in Kisi. Returns an empty 204 response on success. Required: controller_id.
- **list_all_kisi_controller_wiegand_connections** — List Kisi controller wiegand connections for a controller. Returns: id, created_at, updated_at, type, name. Required: controller_id.
- **create_a_kisi_controller_wiegand_connection** — Create a Kisi controller wiegand connection (legacy_reader, legacy_controller, or legacy_keypad_reader). Returns the created connection including id, name, type, controller_wiegand, lock, created_at, and updated_at, plus variant-specific fields.
- **get_single_kisi_controller_wiegand_connection_by_id** — Get a Kisi controller wiegand connection by id. Returns the connection including id, name, type, controller_wiegand, lock, created_at, and updated_at, plus variant-specific fields (virtual card, keypad, or elevator). Required: id.
- **update_a_kisi_controller_wiegand_connection_by_id** — Update a Kisi controller wiegand connection by id; accepts name and virtual card attributes (format, card number, facility code, card id, oem, uid, uid length) under controller_wiegand_connection. Returns an empty 204 response on success. Required: id, controller_wiegand_connection.
- **delete_a_kisi_controller_wiegand_connection_by_id** — Delete a Kisi controller wiegand connection by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_controller_wiegands** — List Kisi controller wiegands for a specific controller. Returns: id, channel, name, created_at, updated_at, controller_id, controller_wiegand_connection_id. Required: controller_id.
- **create_a_kisi_csv_card_import** — Create a CSV card import in Kisi to start importing cards from a previously uploaded CSV file. Returns: id, name, created_at, updated_at, import_errors, file_name, status, organization_id, organization.file_name. The CSV file must first be uploaded using the Signed upload URL endpoint. Required: csv_card_import.
- **get_single_kisi_csv_card_import_by_id** — Get a single CSV card import in Kisi by id. Returns: id, name, created_at, updated_at, import_errors, file_name, status, organization_id, organization. Required: id.
- **create_a_kisi_csv_user_import** — Create a CSV user import in Kisi to start importing users from a CSV file previously uploaded via a signed upload URL; the file is referenced by its file_name inside the csv_user_import body object. Returns: id, name, created_at, updated_at, import_errors, file_name, status, organization_id, organization. Required: csv_user_import.
- **get_single_kisi_csv_user_import_by_id** — Get a single CSV user import by id in Kisi, including its current import status and any import errors. Returns: id, name, created_at, updated_at, import_errors, file_name, status, organization_id, organization. Required: id.
- **list_all_kisi_elevators** — List Kisi elevators. Returns each elevator's id, name, description, created_at, updated_at, place_id, and integration. Max 250 per page.
- **create_a_kisi_elevator** — Create an elevator in Kisi. Returns the created elevator object including id, name, description, created_at, place_id, and integration. Required: elevator.
- **get_single_kisi_elevator_by_id** — Get a single Kisi elevator by id. Returns the full elevator object including id, name, description, created_at, place_id, and integration. Required: id.
- **update_a_kisi_elevator_by_id** — Update a Kisi elevator by id. Returns an empty 204 response on success. Required: id, elevator.
- **delete_a_kisi_elevator_by_id** — Delete a Kisi elevator by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_elevator_stops** — List elevator stops in Kisi for a given place. Returns each stop with id, name, locked_down, permitted, time_restriction_enabled, elevator, floor, and place. Required: place_id.
- **create_a_kisi_elevator_stop** — Create an elevator stop in Kisi linking an elevator to a floor. Returns the created stop with id, name, locked_down, permitted, elevator, floor, and place. Required: elevator_stop.
- **get_single_kisi_elevator_stop_by_id** — Get a single Kisi elevator stop by id. Returns the stop with id, name, locked_down, permitted, time_restriction_enabled, elevator, floor, and place. Required: id.
- **update_a_kisi_elevator_stop_by_id** — Update a Kisi elevator stop by id, changing its elevator_stop attributes such as elevator_id, floor_id, or time_restriction_enabled. Returns an empty 204 response on success. Required: id, elevator_stop.
- **delete_a_kisi_elevator_stop_by_id** — Delete a Kisi elevator stop by id. Returns an empty 204 response on success. Required: id.
- **create_a_kisi_elevator_stop_lock_down** — Lock down an elevator stop in Kisi, locking that stop for everyone until the lockdown is cancelled. Returns an empty 204 response on success. Required: elevator_stop_id.
- **create_a_kisi_elevator_stop_cancel_lockdown** — Cancel the lockdown of an elevator stop in Kisi. Returns an empty 204 response on success. Required: elevator_stop_id.
- **create_a_kisi_event_set** — Create a Kisi event set of filtered events for cursor pagination; the set persists for approximately 24 hours. Returns: id, created_at, status, interval, event_actor_id, event_actor_type, event_authenticated_by_id, event_authenticated_by_type, event_object_id, event_object_type, event_place_id, event_success, event_sequence, event_type, event_uuid, events, cursor, place_id.…. Required: event_set.
- **get_single_kisi_event_set_by_id** — Fetch a Kisi event set by id to check its status or paginate its events with the returned cursor. Returns: id, created_at, status, interval, event_actor_id, event_actor_type, event_authenticated_by_id, event_authenticated_by_type, event_object_id, event_object_type, event_place_id, event_success, event_sequence, event_type, event_uuid, events, cursor, place_id. Events are omitted…. Required: id.
- **list_all_kisi_events_types** — List the event types available in Kisi. Returns an array of event type strings such as 'lock.opened', 'user.create', and 'card.assign'. Takes no parameters.
- **list_all_kisi_favorites** — List favorites in Kisi, optionally filtered by favoritable type or favoritable id. Returns: id, resource_type, created_at, updated_at, favoritable_type, favoritable_id.
- **create_a_kisi_favorite** — Create a favorite in Kisi for a Place or Lock. Returns the created favorite including its id, resource_type, favoritable_type, favoritable_id, created_at, and updated_at. Requires favorite (favoritable_type, favoritable_id). Required: favorite.
- **delete_a_kisi_favorite_by_id** — Delete a favorite in Kisi by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_floors** — List floors in Kisi for a given place, with optional filtering by ids and freetext name search. Returns floors with id, resource_type, name, description, number, created_at, updated_at, and place_id. Required: place_id.
- **create_a_kisi_floor** — Create a floor in Kisi. Returns the created floor object with id, resource_type, name, number, description, created_at, updated_at, and place_id. Requires the floor object with number, name, and place_id. Required: floor.
- **get_single_kisi_floor_by_id** — Get a single floor by id in Kisi. Returns the floor object with id, resource_type, name, description, number, created_at, updated_at, and place_id. Required: id.
- **update_a_kisi_floor_by_id** — Update a floor by id in Kisi, changing its number, name, or description. Returns an empty 204 response on success. Required: id, floor.
- **list_all_kisi_group_elevator_stops** — List Kisi group elevator stops scoped to a group, including each stop's elevator, floor, group, and place details. Returns: id, resource_type, created_at, updated_at, elevator_id, elevator, elevator_stop_id, floor_id, floor, group_id, group, place_id, place. Max 250 per page. Required: group_id.
- **create_a_kisi_group_elevator_stop** — Create a group elevator stop in Kisi, attaching an elevator stop to a group. Returns the created stop with id, resource_type, created_at, updated_at, elevator, floor, group, and place details. Required: group_id, group_elevator_stop.
- **get_single_kisi_group_elevator_stop_by_id** — Get a Kisi group elevator stop by id, including its elevator, floor, group, and place details. Returns: id, resource_type, created_at, updated_at, elevator_id, elevator, elevator_stop_id, floor_id, floor, group_id, group, place_id, place. Required: id.
- **delete_a_kisi_group_elevator_stop_by_id** — Delete a Kisi group elevator stop by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_group_links** — List Kisi group links. Returns group link records including id, name, email, phone, link_enabled, the linked group, and the validity window (valid_from, valid_until). Supports filtering and sorting.
- **create_a_kisi_group_link** — Create a Kisi group link that grants a person access to a group. Returns the created group link including id, name, email, phone, link_enabled, valid_from, valid_until, secret, and quick_response_code_token. Requires a group_link object with group_id and name. Required: group_link.
- **delete_a_kisi_group_link_by_id** — Delete a Kisi group link by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_group_locks** — List group locks in Kisi for a specific group. Returns: id, resource_type, created_at, updated_at, group_id, group, lock_id, lock, place_id, place. Required: group_id.
- **create_a_kisi_group_lock** — Create a group lock in Kisi that links a group to a lock. Returns the created group lock object including id, resource_type, created_at, updated_at, and the associated group, lock, and place objects. Requires group_lock.group_id and group_lock.lock_id. Required: group_lock.
- **get_single_kisi_group_lock_by_id** — Get a single group lock in Kisi by id. Returns: id, resource_type, created_at, updated_at, group_id, group, lock_id, lock, place_id, place. Required: id.
- **delete_a_kisi_group_lock_by_id** — Delete a group lock in Kisi by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_groups** — List Kisi groups. Returns each group including id, name, description, place, created_at, updated_at, access-restriction flags, and users/locks counts.
- **create_a_kisi_group** — Create a group in Kisi. Returns the created group including id, name, description, place, created_at, and access-restriction settings. Requires group.name. Required: group.
- **get_single_kisi_group_by_id** — Get a Kisi group by id. Returns the full group object including id, name, description, place, created_at, and access-restriction settings. Required: id.
- **update_a_kisi_group_by_id** — Update a Kisi group by id. Returns an empty 204 response on success. Required: id, group.
- **delete_a_kisi_group_by_id** — Delete a Kisi group by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_group_terminals** — List Kisi group terminals for a group. Returns: id, resource_type, created_at, updated_at, group_id, group, terminal_id, terminal, place_id, place. Required: group_id.
- **create_a_kisi_group_terminal** — Create a Kisi group terminal linking a terminal to a group. Returns the created group terminal including id, group, terminal, place, and created_at/updated_at timestamps. Required: group_terminal.
- **get_single_kisi_group_terminal_by_id** — Get a Kisi group terminal by id. Returns: id, resource_type, created_at, updated_at, group_id, group, terminal_id, terminal, place_id, place. Required: id.
- **delete_a_kisi_group_terminal_by_id** — Delete a Kisi group terminal by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_group_zones** — List Kisi group zones for a group. Returns: id, resource_type, created_at, updated_at, group_id, group, zone_id, zone, place_id, place. Required: group_id.
- **create_a_kisi_group_zone** — Create a Kisi group zone that links a group to a zone. Returns the created group zone including id, group, zone, place, and created_at. Requires group_zone containing group_id and zone_id. Required: group_zone.
- **get_single_kisi_group_zone_by_id** — Get a single Kisi group zone by id. Returns: id, resource_type, created_at, updated_at, group_id, group, zone_id, zone, place_id, place. Required: id.
- **delete_a_kisi_group_zone_by_id** — Delete a Kisi group zone by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_guests** — List guests in Kisi. Returns each guest's id, resource_type, name, email, phone_number, created_at, and updated_at. Supports filtering by ids or a freetext query against name.
- **create_a_kisi_guest** — Create a guest in Kisi. Returns the created guest object including id, resource_type, name, email, phone_number, created_at, and updated_at. Required: guest.
- **get_single_kisi_guest_by_id** — Get a guest in Kisi by id. Returns the guest object with id, resource_type, name, email, phone_number, created_at, and updated_at. Required: id.
- **delete_a_kisi_guest_by_id** — Delete a guest in Kisi by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_holiday_calendar_holidays** — List Kisi holidays for a given region and year. Returns each holiday with its date and name. Required: region, year, observed.
- **list_all_kisi_holiday_calendars_regions** — List the holiday calendar regions supported by Kisi. Returns a map of region entries including alpha2, alpha3, name, continent, country_code, world_region, and nested subregions.
- **list_all_kisi_integrations** — List Kisi integrations. Returns each integration including id, name, type, enabled, organization, and place details.
- **create_a_kisi_integration** — Create a Kisi integration of type active_directory_user_import, braxos_elevator, event_webhook, jumpcloud_user_import, or rhombus_systems_camera. Returns the created integration including id, name, type, enabled, organization, and place.
- **get_single_kisi_integration_by_id** — Get a Kisi integration by id. Returns the integration including id, name, type, enabled, organization, and place, plus additional fields that depend on the integration type. Required: id.
- **update_a_kisi_integration_by_id** — Update a Kisi integration by id, for example to rename it, toggle enabled, or change type-specific settings inside the integration object. Returns an empty 204 response on success. Required: id.
- **delete_a_kisi_integration_by_id** — Delete a Kisi integration by id. Returns an empty 204 response on success. Required: id.
- **create_a_kisi_invite** — Create an invite in Kisi that grants a User or Guest access to a Place, Group, or Team. Returns the created invite with its id, invites_to_type, invitee, access_key, and created_at.
- **list_all_kisi_locks** — List Kisi locks with optional filters (ids, query, floor_id, place_id, configured, online, unlocked, locked_down). Returns each lock's id, name, description, online/unlocked/locked_down state, place_id, and nested place. Max 250 per page. A reduced subset of the lock resource is returned when authenticating with a GroupLink.
- **create_a_kisi_lock** — Create a lock in Kisi. Returns the created lock object including id, name, description, latitude/longitude, restriction flags, floor_id, and nested place. Required: lock.
- **get_single_kisi_lock_by_id** — Get a single Kisi lock by id. Returns the lock object including id, name, description, configured, online/unlocked/locked_down state, place_id, and nested place. Required: id.
- **update_a_kisi_lock_by_id** — Update a Kisi lock by id with partial changes to fields such as name, description, latitude/longitude, order_id, floor_id, and restriction settings. Returns an empty 204 response on success. Required: id, lock.
- **delete_a_kisi_lock_by_id** — Delete a Kisi lock by id. Returns an empty 204 response on success. Required: id.
- **kisi_locks_unlock** — Unlock a specific lock in Kisi. Returns: message!') on success. Required: lock_id.
- **create_a_kisi_lock_first_to_arrive** — Activate a Kisi lock's first to arrive side effects. Returns an empty 204 response on success. Required: lock_id.
- **create_a_kisi_lock_last_to_leaf** — Reset a lock's last-to-leave state in Kisi, clearing first-to-arrive status and disabling scheduled unlock side effects. Returns an empty 204 response on success. Required: lock_id.
- **create_a_kisi_lock_lock_down** — Lock down a specific lock in Kisi by its id, putting the lock into lockdown mode. Returns an empty 204 response on success. Required: lock_id.
- **create_a_kisi_lock_cancel_lockdown** — Cancel an active lockdown on a lock in Kisi. Returns an empty 204 response on success. Required: lock_id.
- **create_a_kisi_lock_favorite** — Favorite a lock in Kisi. Deprecated — use POST /favorites instead. Returns an empty 204 response on success. Required: lock_id.
- **create_a_kisi_lock_unfavorite** — Unfavorite a lock in Kisi by removing it from the caller's favorites. Deprecated: use DELETE /favorites/{id} instead. Returns an empty 204 response on success. Required: lock_id.
- **list_all_kisi_logins** — List logins in Kisi, of type api or device. Returns: id, created_at, updated_at, type, name, primary, expire, last_used_at, device_brand, device_model, os_name, user_id, user, app, user_agent, device, os, in, schema. Defaults to the current user's logins unless user_id is passed. Max 250 per page.
- **create_a_kisi_login** — Create a login in Kisi of type api or device. Returns the created login including id, type, name, secret, user_id, and user. Users can have up to 40 device logins and 10 api logins; api logins cannot be created on behalf of other users. Required: login, user.
- **delete_a_kisi_login_by_id** — Delete a Kisi login by id. Returns an empty 204 response on success. Required: id.
- **create_a_kisi_login_promote** — Promote a Kisi login to become the primary login, demoting any other primary logins. Returns an empty 204 response on success. Required: login_id.
- **create_a_kisi_logins_resolve** — Resolve a provisional login in Kisi by exchanging its resolution token. Returns the login object including its id, type, secret, user, and device_brand. Required: login.
- **kisi_login_elsewheres_bulk_delete** — Delete all logins except the current one in Kisi. Returns an empty 204 response on success.
- **create_a_kisi_login_offline_certificate** — Create an offline certificate for the current Kisi login, keyed to a beacon id. Returns the login object containing offline_certificate, the hex certificate used to unlock the lock or elevator. Required: login.
- **list_all_kisi_members** — List Kisi members, with support for filtering and sorting. Returns each member's id, name, access_enabled, scim_access_enabled, user (including email and name), metadata, notes, and created_at/updated_at timestamps.
- **create_a_kisi_member** — Create a Kisi member. Returns the created member object including id, name, access_enabled, user (with email and name), metadata, and created_at. Requires member.email. Required: member.
- **get_single_kisi_member_by_id** — Get a single Kisi member by id. Returns the full member object including id, name, access_enabled, scim_access_enabled, user (with email and name), metadata, notes, and created_at/updated_at timestamps. Required: id.
- **update_a_kisi_member_by_id** — Update a Kisi member by id. Returns an empty 204 response on success. Required: id, member.
- **delete_a_kisi_member_by_id** — Delete a Kisi member by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_organizations** — List organizations in Kisi. Returns: id, resource_type, name, domain, logo, address, description, device_logins_expire_after, places_count, scim_enabled, sso_flow_enabled, sso_expiration_override_enabled, sso_expiration_override, metadata, time_zone, web_authentication_api_enabled, apple_pass_enabled, created_at, updated_at, user_id, transfer_to_id, transfer_to, image, color. When authenticated…
- **list_all_kisi_organization_publics** — Fetch a public Kisi organization by its domain. Returns: id, resource_type, name, domain, places_count, logo, sso_flow_enabled, web_authentication_api_enabled, image, color. Required: domain.
- **create_a_kisi_organizations_find** — Find a user's Kisi organizations by sending an email to the specified address with the list of all their organizations. Returns an empty 204 response on success.email. Required: user.
- **list_all_kisi_organization_settings** — Fetch the current organization's settings in Kisi. Returns the organization object including its id, name, domain, places_count, scim_enabled, sso_flow_enabled, time_zone, created_at, and updated_at, plus the associated user. Takes no parameters.
- **list_all_kisi_organization_dashboards** — Fetch the current organization dashboard in Kisi. Returns the aggregate resource counts for the organization: apple_passes_count, cameras_count, users_count, places_count, locks_count, groups_count, and members_count (deprecated).
- **create_a_kisi_organization_generate_next_certificate** — Generate the next encryption certificate for the Kisi organization. Returns: next_sp_certificate. Requires no parameters.
- **create_a_kisi_organization_rotate_certificate** — Rotate the Kisi organization's certificate. Returns an empty 204 response on success.
- **list_all_kisi_organization_transfers** — List organization ownership transfers for the current user's organizations in Kisi. Returns organization objects including id, name, domain, time_zone, transfer_to_id, and the transfer_to user (id, email, name).
- **create_a_kisi_organization_request_transfer** — Request transfer of the Kisi organization ownership to another user, who must accept the transfer for it to take effect. Returns an empty 204 response on success. Required: organization.
- **create_a_kisi_organization_accept_transfer** — Accept a pending transfer of the organization ownership in kisi. Returns an empty 204 response on success.
- **create_a_kisi_organization_reject_transfer** — Reject a pending organization ownership transfer in Kisi. Returns an empty 204 response on success.
- **create_a_kisi_organization_cancel_transfer** — Cancel the pending transfer of organization ownership in Kisi. Returns an empty 204 response on success.
- **list_all_kisi_places** — List places in Kisi. Returns an array of places including: id, name, description, address, latitude, longitude, time_zone, and organization. Max 250 per page.
- **create_a_kisi_place** — Create a place in Kisi. Returns the created place including id, name, address, latitude, longitude, time_zone, and organization. Requires name and address inside the place object. Required: place.
- **get_single_kisi_place_by_id** — Get a single place by id in Kisi. Returns: id, description, created_at, updated_at, name, in, schema. Required: id.
- **update_a_kisi_place_by_id** — Update a place by id in Kisi with partial place attributes (name, description, address, latitude, longitude, image, time_zone). Returns an empty 204 response on success. Required: id, place.
- **delete_a_kisi_place_by_id** — Delete a place by id in Kisi. Returns an empty 204 response on success. Required: id.
- **create_a_kisi_place_lock_down** — Lock down a place in Kisi. Returns an empty 204 response on success. Required: place_id.
- **create_a_kisi_place_cancel_lockdown** — Cancel the active lockdown for a Kisi place. Returns an empty 204 response on success. Required: place_id.
- **create_a_kisi_place_favorite** — Favorite a place in Kisi. Returns an empty 204 response on success. Requires place_id and id. This endpoint is deprecated — Kisi recommends using POST /favorites instead. Required: place_id.
- **create_a_kisi_place_unfavorite** — Unfavorite a place in kisi by removing it from the caller's favorites. Deprecated — use DELETE /favorites/{id} instead. Returns an empty 204 response on success. Required: place_id.
- **list_all_kisi_presences** — List presences for a place in Kisi, showing which users were present on a given date. Returns: actor_type, actor_id, actor_name, actor_email, last_unlocked_lock_name, last_unlocked_lock_id, first_unlock_at, last_unlock_at, status, place_id. Required: place_id, date.
- **list_all_kisi_readers** — List Kisi readers. Returns each reader's id, name, description, model, online status, device_id, token, and associated place, lock, elevator, zone, and terminal objects. Max 250 per page.
- **kisi_readers_assign** — Assign a Kisi reader to a place using the reader's token. Returns an empty 204 response on success.name, reader.place_id. Required: token, reader.
- **get_single_kisi_reader_by_id** — Get a single Kisi reader by id. Returns the full reader object including id, name, description, model, online status, device_id, token, and associated place, lock, elevator, zone, and terminal objects. Required: id.
- **update_a_kisi_reader_by_id** — Update a Kisi reader by id. Returns an empty 204 response on success. Required: id, reader.
- **create_a_kisi_reader_deassign** — Deassign a reader in Kisi, removing the reader's current assignment. Returns an empty 204 response on success. Required: reader_id.
- **create_a_kisi_reader_reset_tamper** — Reset the tampered state of a Kisi reader, clearing the tamper flag after the reader has been serviced. Returns an empty 204 response on success. Required: reader_id.
- **create_a_kisi_reader_reboot** — Reboot a reader in Kisi. Returns an empty 204 response on success. Required: reader_id.
- **list_all_kisi_reports** — List Kisi reports. Returns each report with id, name, status, created_at, updated_at, start_date, end_date, time_zone, organization, place_id, and reporter_id.
- **create_a_kisi_report** — Create a Kisi report. Returns the created report object with id, name, status, created_at, start_date, end_date, and organization. The reporting interval cannot exceed 180 days. Required: report.
- **get_single_kisi_report_by_id** — Get a Kisi report by id. Returns the full report object with id, name, status, created_at, updated_at, start_date, end_date, time_zone, organization, and reporter_id. Required: id.
- **delete_a_kisi_report_by_id** — Delete a Kisi report by id. Returns an empty 204 response on success. Required: id.
- **create_a_kisi_report_download** — Create a download for a Kisi report, retrieving a download URL for the generated report file. Returns: url. Required: report_id.
- **list_all_kisi_role_assignments** — List Kisi role assignments that grant roles to users, teams, or guests at the organization, place, or group level. Returns: id, created_at, updated_at, type, name, in, schema. The user_id, place_id, group_id, and scope filters are deprecated.
- **create_a_kisi_role_assignment** — Create a Kisi role assignment that grants a role to a user, team, or guest at the organization, place, or group level. Returns: id, resource_type, created_at, updated_at, role_id, notify, applies_to_type, applies_to_id, applies_to, assignee_type, assignee_id, assignee, created_by_type, created_by_id, valid_from, valid_until, user_id, user, assignee_team_id, assignee_team, guest_id, guest,…
- **get_single_kisi_role_assignment_by_id** — Get a single Kisi role assignment by id. Returns: id, created_at, updated_at, type, name, in, schema. Required: id.
- **update_a_kisi_role_assignment_by_id** — Update a Kisi role assignment by id, for example to change the assigned role or the email notification setting. Returns an empty 204 response on success. Required: id.
- **delete_a_kisi_role_assignment_by_id** — Delete a Kisi role assignment by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_roles** — List roles in Kisi. Returns role objects with their id, resource_type, applies_to, name, description, custom flag, full permissions map, and custom_role_id.
- **get_single_kisi_role_by_id** — Get a single role in Kisi by id. Returns the full role object including id, resource_type, applies_to, name, description, custom flag, permissions map, and custom_role_id. Required: id.
- **list_all_kisi_schedules** — List Kisi schedules — time-based rules that allow, permit, or unlock a lock, group, or elevator stop, as holiday calendars, recurring, single, or single all-day events. Returns schedules with: id, name, type, consequence, scheduleable, place_id, and variant-specific timing fields.
- **create_a_kisi_schedule** — Create a Kisi schedule that allows, permits, or unlocks a lock, group, or elevator stop, as a holiday calendar, recurring event, single event, or single all-day event. Returns the created schedule: id, name, type, consequence, scheduleable, place_id, and variant-specific timing fields.
- **get_single_kisi_schedule_by_id** — Get a Kisi schedule by id — a holiday calendar, recurring event, single event, or single all-day event that allows, permits, or unlocks a lock, group, or elevator stop. Returns: id, created_at, updated_at, type, name, in, schema. Required: id.
- **update_a_kisi_schedule_by_id** — Update a Kisi schedule's name, enabled flag, override flag, or type-specific schedule fields (region/observed, weekdays, or event dates/times) by id. Returns an empty 204 response on success. Required: id.
- **delete_a_kisi_schedule_by_id** — Delete a Kisi schedule by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_scheduled_reports** — List Kisi scheduled reports. Returns each report's id, name, period, frequency, scheduled_at, emails, enabled, and organization. Max 250 per page.
- **create_a_kisi_scheduled_report** — Create a scheduled report in Kisi for a reporter. Returns the created report's id, name, period, frequency, scheduled_at, time_zone, emails, and enabled state. Requires a scheduled_report payload with name, reporter_id, period, frequency, scheduled_at, and time_zone. Required: scheduled_report.
- **get_single_kisi_scheduled_report_by_id** — Get a Kisi scheduled report by id. Returns the full report including id, name, period, frequency, scheduled_at, time_zone, emails, enabled, and organization. Required: id.
- **update_a_kisi_scheduled_report_by_id** — Update a Kisi scheduled report by id — change its name, enabled state, period, frequency, scheduled_at, emails, or time_zone. Returns an empty 204 response on success. Required: id, scheduled_report.
- **delete_a_kisi_scheduled_report_by_id** — Delete a Kisi scheduled report by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_shares** — List Kisi shares — access-right assignments linking users to groups, filterable by group, member, place, user, or role. Returns: id, resource_type, created_at, updated_at, email, notify, role_id, valid_from, valid_until, group_id, group, member_id, member, place_id, place, user_id, user, created_by_type, created_by_id, created_by, lock_id, apply_to_place, role, issued_to_id, issued_to_email,…
- **create_a_kisi_share** — Create a Kisi share granting a user access to a group by email. Returns the created share: id, email, role_id, group_id, valid_from, valid_until, user, group. Deprecated — use Kisi's access rights API instead. Required: share.
- **get_single_kisi_share_by_id** — Get a Kisi share by id. Returns the full share object: id, email, role_id, group_id, valid_from, valid_until, user, group. Deprecated — use Kisi's access rights API instead. Required: id.
- **update_a_kisi_share_by_id** — Update a Kisi share by id, e.g. its notify setting, role_id, or validity window. Returns an empty 204 response on success. Deprecated — use Kisi's access rights API instead. Required: id, share.
- **delete_a_kisi_share_by_id** — Delete a Kisi share by id. Returns an empty 204 response on success. Deprecated — use Kisi's access rights API instead. Required: id.
- **create_a_kisi_signed_upload_url** — Create a signed upload URL in Kisi for uploading a file. Returns the signed_upload_url to POST the file to and the file_name. Required: signed_upload_url.
- **list_all_kisi_team_memberships** — List team memberships in Kisi. Returns memberships with id, resource_type, created_at, updated_at, team_id, team, member_type, member_id, and member. Filters: ids, member_type, team_id, member_id (member_id must be used with member_type).
- **create_a_kisi_team_membership** — Create a team membership in Kisi. Returns the created membership including id, resource_type, created_at, updated_at, team_id, team, member_type, member_id, and member. Required: team_membership.
- **get_single_kisi_team_membership_by_id** — Get a team membership in Kisi by id. Returns: id, resource_type, created_at, updated_at, team_id, team, member_type, member_id, member, name, in, schema. Required: id.
- **delete_a_kisi_team_membership_by_id** — Delete a team membership in Kisi by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_teams** — List Kisi teams, ordered as requested. Returns: id, resource_type, name, created_at, updated_at. Max 250 per page.
- **create_a_kisi_team** — Create a Kisi team with the given name. Returns the created team including id, resource_type, name, created_at, and updated_at. Requires team.name. Required: team.
- **get_single_kisi_team_by_id** — Get a single Kisi team by id. Returns the team including id, resource_type, name, created_at, and updated_at. Required: id.
- **update_a_kisi_team_by_id** — Update a Kisi team by id, e.g. to rename it. Returns an empty 204 response on success. Required: id, team.
- **delete_a_kisi_team_by_id** — Delete a Kisi team by id. Returns an empty 204 response on success. Required: id.
- **list_all_kisi_terminals** — List Kisi terminals. Returns each terminal's id, resource_type, name, description, place_id, place, marketplace_installation_id, created_at, and updated_at. Max 250 per page.
- **create_a_kisi_terminal** — Create a terminal in Kisi. Returns the created terminal including its id, name, description, place_id, place, and marketplace_installation_id.name and terminal.place_id. Required: terminal.
- **get_single_kisi_terminal_by_id** — Get a single Kisi terminal by id. Returns the terminal including its id, resource_type, name, description, place_id, place, marketplace_installation_id, created_at, and updated_at. Required: id.
- **update_a_kisi_terminal_by_id** — Update a Kisi terminal by id, setting terminal.name, terminal.description, or terminal.marketplace_installation_id. Returns an empty 204 response on success. Required: id, terminal.
- **delete_a_kisi_terminal_by_id** — Delete a Kisi terminal by id. Returns an empty 204 response on success. Required: id.
- **kisi_terminals_trigger** — Trigger a Kisi terminal by id. Returns an empty 204 response on success. Required: terminal_id.
- **list_all_kisi_users** — List Kisi users, filterable by email, group, place, freetext query, or user ID, with sorting by name, last unlock, or access status. Returns: id, resource_type, name, email, created_at, updated_at, metadata, image, otp_required_for_login, password_flow_enabled, access_enabled, last_accessed_at, scim_access_enabled, notes, organization_id, confirmed, groups_count, in, schema. Max 100 per page.
- **create_a_kisi_user** — Create a Kisi user. Returns the created user object including id, name, email, created_at, access_enabled, and organization_id. Required: user.
- **get_single_kisi_user_by_id** — Get a single Kisi user by id. Returns the full user object including id, name, email, created_at, access_enabled, and organization_id. Required: id.
- **update_a_kisi_user_by_id** — Update a Kisi user by id, e.g. to change name, image, notes, metadata, or access flags. Returns an empty 204 response on success. Required: id, user.
- **delete_a_kisi_user_by_id** — Delete a Kisi user by id. Returns an empty 204 response on success. Required: id.
- **create_a_kisi_2_fa_otp_secret** — Fetch a new two-factor OTP secret for the authenticated Kisi user. Returns: otp_secret, uri. Only available when the organization has sso flow disabled.
- **create_a_kisi_2_fa_activate** — Activate 2FA for a kisi user by confirming the six-digit token from the reset password email. Returns an empty 204 response on success. The user object must include the six-digit otp_attempt code; only available when the organization has the SSO flow disabled. Required: user.
- **create_a_kisi_2_fa_deactivate** — Deactivate 2FA for a user in Kisi by submitting the 6-digit token provided in the reset password email. Returns an empty 204 response on success.otp_attempt. Only available when the organization has SSO flow disabled. Required: user.
- **create_a_kisi_2_fa_backup_code** — Generate 2FA backup codes for the authenticated Kisi user. Returns: backup_codes. Only available when the user's organization has sso flow disabled.
- **create_a_kisi_users_password** — Request a password reset for a Kisi user, which emails the user a reset-password token.email and user.domain. Only available when the organization has SSO flow disabled. Returns an empty 204 response on success. Required: user.
- **kisi_users_passwords_bulk_update** — Reset a Kisi user's password by submitting the token from the reset-password email together with the new password.password, user.password_confirmation, and user.reset_password_token. Only available when the organization has SSO flow disabled. Returns an empty 204 response on success. Required: user.
- **create_a_kisi_users_sign_up** — Register a new user (self sign-up) in Kisi. Returns the created user object including id, name, email, locale, otp_required_for_login, created_at, updated_at, and the user's organization. Required: user, token.
- **list_all_kisi_wireless_locks** — List wireless locks in Kisi. Returns each lock's id, name, online status, unlocked and opened state, battery_level, firmware_version, and created_at. Max 250 per page.
- **list_all_kisi_current_user** — Get the current user in Kisi. Returns the full user record including id, name, email, locale, notifications_unread_count, organization_id, and the organization object.
- **kisi_current_user_bulk_update** — Update the current user's profile or settings in Kisi. Returns an empty 204 response on success. Requires a user object with the fields to update; current_password is required when changing password. Required: user.
- **kisi_current_user_bulk_delete** — Delete the current user's Kisi account. Returns an empty 204 response on success.
- **list_all_kisi_current_login** — Fetch the current login in Kisi. Returns the login object including its id, type (api or device), name, primary, expire, last_used_at, device_brand, device_model, os_name, user_id, and the associated user.
- **create_a_kisi_current_login** — Promote the current login in Kisi to the primary login. Returns an empty 204 response on success.
- **kisi_current_login_bulk_update** — Update the current login in Kisi. Returns an empty 204 response on success. Required: login.
- **kisi_current_login_bulk_delete** — Delete the current login in Kisi. Returns an empty 204 response on success.
- **list_all_kisi_current_organization** — Fetch the current organization in Kisi, resolved from the authenticated credentials. Returns the organization record including id, resource_type, name, domain, address, description, time_zone, places_count, and created_at.
- **kisi_current_organization_bulk_update** — Update the current organization in Kisi by submitting an organization object with fields such as name, address, description, time_zone, and device_logins_expire_after. Returns an empty 204 response on success. Required: organization.

## How it works

1. **Link your customer's Kisi account.** Use Truto's frontend SDK; we handle every OAuth and API key flow so you don't need to create the OAuth app.
2. **Authentication is automatic.** Truto refreshes tokens, stores credentials securely, and injects them into every API request.
3. **Call Truto's API to reach Kisi.** The Proxy API is a 1-to-1 mapping of the Kisi API.
4. **Get a unified response format.** Every response uses a single shape, with cursor-based pagination and data in the `result` field.

## Use cases

- **Automate employee onboarding and offboarding** — HRIS and IT platforms can provision Kisi users and credentials the moment someone is hired, and revoke all mobile and card access instantly on termination across every office location.
- **Tie physical access to subscription or booking state** — Coworking, gym, and studio management SaaS can automatically add or remove members from Kisi groups based on payment status, membership tier, or active bookings — enforcing access rules without manual IT work.
- **Enable remote unlock from your own product** — Visitor management, property management, and workplace apps can embed a 'Buzz In' or 'Open Door' button that triggers Kisi locks and elevators in real time, without sending users to a separate app.
- **Correlate access events with your product data** — Video surveillance, workplace analytics, and security platforms can ingest Kisi events and presence data to clip relevant camera footage, measure office occupancy, or feed time-and-attendance reports.
- **Issue time-boxed guest and visitor access** — Visitor management and event platforms can generate shareable access links for delivery drivers, contractors, or one-off guests that expire automatically after the visit window.

## What you can build

- **User lifecycle sync to Kisi** — Create, update, and delete Kisi users directly from your product so credentials match the state of your source of truth at all times.
- **Group-based access provisioning** — Programmatically create Kisi groups, link them to locks and elevator stops, and move users between groups to grant or revoke door access by role, plan, or booking.
- **Remote door and elevator control** — Ship an in-app unlock button backed by the Kisi lock unlock endpoint, plus elevator stop triggers for multi-floor buildings.
- **Schedule-driven access windows** — Create Kisi schedules from your calendar or booking data so a room, floor, or door is only accessible during the exact reserved time slot.
- **Card and credential management** — Register physical RFID/NFC cards, assign or deassign them to users, and activate or deactivate credentials when devices are lost or returned.
- **Access events and presence dashboards** — Pull Kisi event sets and presence data to power audit logs, occupancy views, and attendance reports natively inside your product.
- **Emergency lockdown controls** — Trigger lockdowns on individual locks, elevator stops, or entire places from your security console, and cancel them when the all-clear is given.

## FAQs

### How does authentication to Kisi work through Truto?

Your end users connect their Kisi account through a Truto-managed auth flow. Truto stores and refreshes the credentials, so your product calls a single Truto endpoint and we attach the correct Kisi authorization header on every request.

### Which Kisi resources can we read and write?

The integration covers users, members, logins, cards and card assignments, groups and group links, locks, elevators and elevator stops, places, floors, schedules, roles and role assignments, teams, controllers, readers, cameras, events, presences, reports, and organization settings — including create, read, update, and delete where Kisi exposes them.

### Can we unlock doors or trigger hardware in real time?

Yes. The integration exposes action endpoints for unlocking locks, triggering terminals, rebooting controllers and readers, locking down locks, elevator stops, and places, and canceling those lockdowns.

### How do we pull access logs and occupancy data?

Use the event set endpoints to create and fetch paginated audit logs of Kisi events, and the presences endpoint to see who was physically present at a place along with first and last unlock times.

### How fresh is the data from Kisi?

All calls are made live against the Kisi API at request time, so reads reflect the current state of the account. Truto handles pagination and normalization so you can iterate over large result sets without writing Kisi-specific logic.

### Can we issue temporary access for visitors or guests?

Yes. You can create guests and generate group links that provide time-boxed, shareable access to specific doors or elevator stops, which is ideal for deliveries, contractors, and one-off visitors.

### What if we need a Kisi endpoint that isn't listed?

Truto builds integration coverage on request. If Kisi exposes the endpoint in their API, we can add it to your integration without you needing to maintain Kisi-specific client code.
