POST
Sheets.List
Return sheets the logged-in user can open. Same data as dashboard Sheets listing. Owner and managers see all org sheets. Other users see only sheets shared with them. Page size is capped at 25.
Permissions
- User must be logged in with a valid bearer token.
- The user must be from the same company domain as the request Host (call the API on that account subdomain or allowed custom domain). A token from another company returns success=0, error user_not_in_company.
- Returned or changed records are limited by the user permissions, team access, folder access, and account settings.
Action
- Returns Sheets rows as JSON.
- Supports the documented filters and paging fields.
- List responses are capped at 25 rows per call.
Push Service
No push is sent because this function only reads data or returns helper information.
Automation
No automation is run for this function.
Special Instructions
- On a company subdomain (e.g. https://{user_domain}.bull36.com) the user must match that Host — Login and protected APIs reject another company with success=0, error user_not_in_company. On a main brand host (bull36.com, biz1.co.il, mastrocrm.com, …) the company domain gate is skipped.
- Mirrors dashboard Sheets module (Sheets::app_list / sheets_list_for_user).
- Open a sheet in the UI at /dashboard/sheets/view/{id}.
- Use Sheets.Get with the returned id for tables + shares.
- Only owners/managers can create (see can_create on this response).
Required Parameters
No body parameters are required for this function.
Optional Parameters
| Name | Type | Sample | What it gives |
|---|---|---|---|
limitpost | int | 25 | Limits returned sheets. Values above 25 are capped. |
offsetpost | int | 0 | Skips rows for paging. |
lengthpost | int | 25 | Alternative page size. Values above 25 are capped. |
startpost | int | 0 | Alternative offset for paging. |
Authentication
Send the bearer token returned by Login in the request header. The user must be from the same company domain as this Host — a token from another company is rejected (user_not_in_company).
Authorization: Bearer YOUR TOKEN
Sample Request
{
"url": "\/app\/Sheets.List",
"method": "POST",
"headers": {
"Authorization": "Bearer YOUR TOKEN"
},
"body": {
"limit": "25"
},
"url_user": "https:\/\/{user}.bull36.com\/app\/Sheets.List",
"url_domain": "https:\/\/{domain}\/app\/Sheets.List"
}Endpoint
POST /app/Sheets.List
POST https://{user}.bull36.com/app/Sheets.List
POST https://{domain}/app/Sheets.ListSample Output
{
"success": 1,
"data": [
{
"id": 1,
"org_id": 1,
"user_id": 47,
"created_by": 47,
"name": "Test",
"name_en": "Test",
"name_he": "Test",
"status": 1,
"table_count": 4,
"can_edit": 1,
"can_manage": 1,
"date_created": "2026-09-21 07:06:04",
"updated_at": "2026-09-21 09:12:32"
}
],
"total": 1,
"recordsTotal": 1,
"can_create": 1
}Count Only
Use the matching count route with the same filters when the UI only needs total rows for paging.
{
"url": "\/app\/Sheets.Count",
"url_user": "https:\/\/{user}.bull36.com\/app\/Sheets.Count",
"url_domain": "https:\/\/{domain}\/app\/Sheets.Count",
"method": "POST",
"headers": {
"Authorization": "Bearer YOUR TOKEN"
},
"body": [],
"sample_output": {
"success": 1,
"count": 123
},
"notes": {
"total": "Use total or recordsTotal."
}
}Count JavaScript
const token = 'YOUR TOKEN';
const body = new URLSearchParams();
const res = await fetch('https://{domain}/app/Sheets.Count', {
method: 'POST',
headers: { Authorization: `Bearer ${token}` },
body
});
const data = await res.json();
console.log(data.count);JavaScript Example
const token = 'YOUR TOKEN';
const body = new URLSearchParams();
body.set('limit', '25');
const res = await fetch('/app/Sheets.List', {
method: 'POST',
headers: { Authorization: `Bearer ${token}` },
body
});
const data = await res.json();
console.log(data);Error Example
{
"success": "0",
"error": "bearer_token_required",
"message": "Authorization bearer token is required. Send header: Authorization: Bearer YOUR TOKEN"
}