ITO360 monitoring JSON API
English guide for sending monitoring JSON events and payloads to ITO360.
Production target
POST https://ito360.top/api/monitoring
What to target
Use this exact endpoint for monitoring messages:
POST https://ito360.top/api/monitoring
Do not replace monitoring with a placeholder path.
What to POST
- Method:
POST - Content type: send
Content-Type: application/json. - Body: send valid JSON. No JSON schema or field names are currently enforced.
- Authentication: none is currently required.
Use this recommended JSON envelope to make messages clear and consistent. The fields are examples, not mandatory fields:
{
"event": "order.created",
"source": "your-system-name",
"occurredAt": "2026-08-16T12:34:56Z",
"data": {
"orderId": "12345",
"status": "new"
}
}
event: the event type, such asorder.created.source: the name of the system sending the message.occurredAt: the UTC event time in ISO 8601 format.data: the event-specific information.
Example
curl -i -X POST "https://ito360.top/api/monitoring" \
-H "Content-Type: application/json" \
--data "{\"event\":\"order.created\",\"source\":\"vendor-system\",\"occurredAt\":\"2026-08-16T12:34:56Z\",\"data\":{\"orderId\":\"12345\"}}"
Successful response
A successful request returns 202 Accepted:
HTTP/1.1 202 Accepted
Content-Type: application/json; charset=utf-8
{
"message": "POST accepted by ITO360.",
"id": 42,
"receivedAtUtc": "2026-08-16T12:34:56.789+00:00"
}
Important:
202 Accepted confirms that ITO360 saved the payload to its local SQLite database. The current receiver does not validate the JSON schema, forward, or otherwise process the body.
Notes for senders
- Use HTTPS and target
https://ito360.top/api/monitoring; do not send requests to the site home page. - The receiver currently accepts other content types too, but send JSON with
application/jsonfor this integration. - This endpoint is suited to server-to-server posts. Browser-based integrations may need a separate CORS configuration.
- Do not put credentials or other sensitive data in a URL path or query string.
- Request-size limits may be enforced by IIS or ASP.NET Core.
- Operators can view saved posts at
/monitoring/history. Restrict that page in IIS before exposing it publicly.