Skip to content
© 2026 The ThingsBoard Authors
Try for free

ThingsBoard Cloud

Choose your data region

Your data stays in the region you choose, for residency and compliance. No credit card required.

Rather run it yourself? Install on your own servers

Attributes

The HTTP Attributes API lets devices upload client-side attributes, request attribute values, and poll for shared attribute updates. For an explanation of attribute types, see Attributes.

See Getting Connected for authentication and connection details.

Upload client-side attributes with a POST request:

POST https://eu.thingsboard.cloud/api/v1/$ACCESS_TOKEN/attributes
{"attribute1": "value1", "attribute2": true, "attribute3": 42.0}
Terminal window
curl -s -X POST -H "Content-Type: application/json" -d '{"attribute1":"value1","attribute2":true,"attribute3":42.0}' "http://eu.thingsboard.cloud/api/v1/$ACCESS_TOKEN/attributes"

Send a GET request to the attributes endpoint to read client-side and/or shared attribute values. The response groups results by scope: {"client": {...}, "shared": {...}}.

Endpoint:

GET https://eu.thingsboard.cloud/api/v1/$ACCESS_TOKEN/attributes

Query parameters — choose which attributes to return:

Parameter Description
clientKeys Comma-separated list of client-side attribute keys to return
sharedKeys Comma-separated list of shared attribute keys to return
allClientKeys Set to true to return all client-side attributes (overrides clientKeys)
allSharedKeys Set to true to return all shared attributes (overrides sharedKeys)

Sending no query parameters at all returns all client-side and all shared attributes.

Example:

Terminal window
curl -s "http://eu.thingsboard.cloud/api/v1/$ACCESS_TOKEN/attributes?clientKeys=attribute1,attribute2&sharedKeys=shared1,shared2"

Response:

{"client": {"attribute1": "value1", "attribute2": true}, "shared": {"shared1": "value2", "shared2": false}}

The response includes a scope only if that scope returned at least one attribute. Ask for ?allClientKeys=true and the response has no shared object at all. The same happens to a scope you did ask for, if the device has no attributes in it.

Poll for shared attribute changes with a long-lived GET request:

GET https://eu.thingsboard.cloud/api/v1/$ACCESS_TOKEN/attributes/updates?timeout=20000
Terminal window
curl -s "http://eu.thingsboard.cloud/api/v1/$ACCESS_TOKEN/attributes/updates?timeout=20000"

The request blocks until a shared attribute changes or the timeout elapses. The timeout parameter is in milliseconds. When an update occurs, ThingsBoard returns the changed attributes:

{"shared": {"firmware_version": "2.1.0"}}