POST

Sheets.List

Return sheets the logged-in user can open. Same data as dashboard Sheets listing. Owner and managers see all org sheets. Other users see only sheets shared with them. Page size is capped at 25.

Permissions

  • User must be logged in with a valid bearer token.
  • The user must be from the same company domain as the request Host (call the API on that account subdomain or allowed custom domain). A token from another company returns success=0, error user_not_in_company.
  • Returned or changed records are limited by the user permissions, team access, folder access, and account settings.

Action

  • Returns Sheets rows as JSON.
  • Supports the documented filters and paging fields.
  • List responses are capped at 25 rows per call.

Push Service

No push is sent because this function only reads data or returns helper information.

Automation

No automation is run for this function.

Special Instructions

  • On a company subdomain (e.g. https://{user_domain}.bull36.com) the user must match that Host — Login and protected APIs reject another company with success=0, error user_not_in_company. On a main brand host (bull36.com, biz1.co.il, mastrocrm.com, …) the company domain gate is skipped.
  • Mirrors dashboard Sheets module (Sheets::app_list / sheets_list_for_user).
  • Open a sheet in the UI at /dashboard/sheets/view/{id}.
  • Use Sheets.Get with the returned id for tables + shares.
  • Only owners/managers can create (see can_create on this response).

Required Parameters

No body parameters are required for this function.

Optional Parameters

NameTypeSampleWhat it gives
limit
post
int25Limits returned sheets. Values above 25 are capped.
offset
post
int0Skips rows for paging.
length
post
int25Alternative page size. Values above 25 are capped.
start
post
int0Alternative offset for paging.

Authentication

Send the bearer token returned by Login in the request header. The user must be from the same company domain as this Host — a token from another company is rejected (user_not_in_company).

Authorization: Bearer YOUR TOKEN

Sample Request

{
    "url": "\/app\/Sheets.List",
    "method": "POST",
    "headers": {
        "Authorization": "Bearer YOUR TOKEN"
    },
    "body": {
        "limit": "25"
    },
    "url_user": "https:\/\/{user}.bull36.com\/app\/Sheets.List",
    "url_domain": "https:\/\/{domain}\/app\/Sheets.List"
}

Endpoint

POST /app/Sheets.List
POST https://{user}.bull36.com/app/Sheets.List
POST https://{domain}/app/Sheets.List

Sample Output

{
    "success": 1,
    "data": [
        {
            "id": 1,
            "org_id": 1,
            "user_id": 47,
            "created_by": 47,
            "name": "Test",
            "name_en": "Test",
            "name_he": "Test",
            "status": 1,
            "table_count": 4,
            "can_edit": 1,
            "can_manage": 1,
            "date_created": "2026-09-21 07:06:04",
            "updated_at": "2026-09-21 09:12:32"
        }
    ],
    "total": 1,
    "recordsTotal": 1,
    "can_create": 1
}

Count Only

Use the matching count route with the same filters when the UI only needs total rows for paging.

{
    "url": "\/app\/Sheets.Count",
    "url_user": "https:\/\/{user}.bull36.com\/app\/Sheets.Count",
    "url_domain": "https:\/\/{domain}\/app\/Sheets.Count",
    "method": "POST",
    "headers": {
        "Authorization": "Bearer YOUR TOKEN"
    },
    "body": [],
    "sample_output": {
        "success": 1,
        "count": 123
    },
    "notes": {
        "total": "Use total or recordsTotal."
    }
}

Count JavaScript

const token = 'YOUR TOKEN';
const body = new URLSearchParams();

const res = await fetch('https://{domain}/app/Sheets.Count', {
  method: 'POST',
  headers: { Authorization: `Bearer ${token}` },
  body
});
const data = await res.json();
console.log(data.count);

JavaScript Example

const token = 'YOUR TOKEN';
const body = new URLSearchParams();
body.set('limit', '25');

const res = await fetch('/app/Sheets.List', {
  method: 'POST',
  headers: { Authorization: `Bearer ${token}` },
  body
});
const data = await res.json();
console.log(data);

Error Example

{
    "success": "0",
    "error": "bearer_token_required",
    "message": "Authorization bearer token is required. Send header: Authorization: Bearer YOUR TOKEN"
}