Get On Board Company shells API

Post jobs under your client companies' brands from a single account. A company shell is a lightweight public company profile (name, logo, description, its own `/companies/` page) owned by your partner account. Create shells for the companies you recruit for, then pass a shell's slug as `company_shell_id` when creating or updating a job: the public job page, company profile, feeds, and public API all show the client's brand, while applications, hiring processes, and billing stay on your account. Built for ATS integrations and agencies managing many client companies. Available to authorized partner accounts only — other API keys receive 403; contact Get on Board to become a partner. Not related to the public Companies endpoints.

Operations 4

GET /api/v0/company_shells List company shells #
POST /api/v0/company_shells List company shells #
GET /api/v0/company_shells/{id} List company shells #
PUT /api/v0/company_shells/{id} List company shells #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/get-on-board-company-shells-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

get-on-board-company-shells-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Get on Board Company shells API
  version: 0.1.0
  description: The Get on Board API provides access to the data inside Get on Board, the leading recruitment platform for tech professionals in Latin America.
servers:
- url: https://www.getonbrd.com
  description: Production
- url: https://sandbox.getonbrd.dev
  description: Sandbox
tags:
- name: Company shells
  description: Post jobs under your client companies' brands from a single account.
paths:
  /api/v0/company_shells:
    get:
      summary: List company shells
      tags:
      - Company shells
      security:
      - ApiKeyAuth: []
      parameters:
      - name: Authorization
        in: header
        required: true
        schema:
          type: string
        example: Bearer YOUR_API_KEY
        description: Bearer credential for the authentication scheme required by this endpoint.
      responses:
        '200':
          description: 'Returns the partner-owned company shells available for shell-branded job posting. Partner-only: requires an authorized partner account; standard company API keys receive 403.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                        type:
                          type: string
                        attributes:
                          type: object
                          properties:
                            name:
                              type: string
                            description:
                              type: string
                            web:
                              type: string
                            logo:
                              type: string
                          required:
                          - name
                          - description
                          - web
                          - logo
                      required:
                      - id
                      - type
                      - attributes
                  meta:
                    type: object
                    properties:
                      page:
                        type: integer
                      per_page:
                        type: integer
                      total_pages:
                        type: integer
                    required:
                    - page
                    - per_page
                    - total_pages
                required:
                - data
                - meta
              example:
                data:
                - id: '1'
                  type: company_shell
                  attributes:
                    name: Alpha Client
                    description: Client company 17 builds software products for distributed teams.
                    web: https://client-company-16.example.com
                    logo: /uploads/company_shells/logo/19/logo.jpg
                meta:
                  page: 1
                  per_page: 120
                  total_pages: 1
        '401':
          description: 'Returns the partner-owned company shells available for shell-branded job posting. Partner-only: requires an authorized partner account; standard company API keys receive 403.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                  code:
                    type: string
                required:
                - message
                - code
              example:
                message: (Status 401) Unauthorized access.
                code: unauthorized
        '403':
          description: 'Returns the partner-owned company shells available for shell-branded job posting. Partner-only: requires an authorized partner account; standard company API keys receive 403.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                  code:
                    type: string
                required:
                - message
                - code
              example:
                message: (Status 403) Partner company shells are not enabled for this account
                code: forbidden
      operationId: listCompanyShells
    post:
      summary: List company shells
      tags:
      - Company shells
      security:
      - ApiKeyAuth: []
      parameters:
      - name: Authorization
        in: header
        required: true
        schema:
          type: string
        example: Bearer YOUR_API_KEY
        description: Bearer credential for the authentication scheme required by this endpoint.
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                company_shell:
                  type: object
                  properties:
                    name:
                      type: string
                    description:
                      type: string
                    web:
                      type: string
                    remote_logo_url:
                      type: string
                  required:
                  - name
                  - description
                  - web
                  - remote_logo_url
              required:
              - company_shell
            example:
              company_shell:
                name: Client Beta
                description: Client Beta builds internal tooling for distributed engineering teams.
                web: https://client-beta.example.com
                remote_logo_url: https://cdn.client-beta.example.com/logo.jpg
          multipart/form-data:
            schema:
              type: object
              properties:
                company_shell:
                  type: object
                  properties:
                    name:
                      type: string
                    description:
                      type: string
                    web:
                      type: string
                    logo:
                      type: string
                      format: binary
                  required:
                  - name
                  - description
                  - web
                  - logo
              required:
              - company_shell
            example:
              company_shell:
                name: Client Gamma
                description: Client Gamma builds internal tooling for distributed engineering teams.
                web: https://client-gamma.example.com
                logo: logo.jpg
      responses:
        '201':
          description: 'Creates a partner-owned public shell profile that can later be referenced as `company_shell_id` on job create/update requests. A logo is required: send either a multipart `logo` file or a `remote_logo_url`; requests without one fail with 422 `logo can''t be blank`. `remote_logo_url` must be a publicly reachable https URL — private or internal hosts are rejected with `could not download logo`. Partner-only: requires an authorized partner account; standard company API keys receive 403.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                      type:
                        type: string
                      attributes:
                        type: object
                        properties:
                          name:
                            type: string
                          description:
                            type: string
                          web:
                            type: string
                          logo:
                            type: string
                        required:
                        - name
                        - description
                        - web
                        - logo
                    required:
                    - id
                    - type
                    - attributes
                required:
                - data
              example:
                data:
                  id: client-gamma
                  type: company_shell
                  attributes:
                    name: Client Gamma
                    description: Client Gamma builds internal tooling for distributed engineering teams.
                    web: https://client-gamma.example.com
                    logo: /uploads/company_shells/logo/18/logo.jpg
        '403':
          description: 'Returns the partner-owned company shells available for shell-branded job posting. Partner-only: requires an authorized partner account; standard company API keys receive 403.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                  code:
                    type: string
                required:
                - message
                - code
              example:
                message: (Status 403) Partner company shells are not enabled for this account
                code: forbidden
        '422':
          description: 'Creates a partner-owned public shell profile that can later be referenced as `company_shell_id` on job create/update requests. A logo is required: send either a multipart `logo` file or a `remote_logo_url`; requests without one fail with 422 `logo can''t be blank`. `remote_logo_url` must be a publicly reachable https URL — private or internal hosts are rejected with `could not download logo`. Partner-only: requires an authorized partner account; standard company API keys receive 403.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: object
                    properties:
                      slug:
                        type: array
                        items:
                          type: string
                      logo:
                        type: array
                        items:
                          type: string
                    required:
                    - slug
                    - logo
                  code:
                    type: string
                required:
                - message
                - code
              example:
                message:
                  slug:
                  - is in use on another record
                  - is in use on another record
                  logo:
                  - can't be blank
                code: unprocessable_content
      operationId: createCompanyShell
  /api/v0/company_shells/{id}:
    get:
      summary: List company shells
      tags:
      - Company shells
      security:
      - ApiKeyAuth: []
      parameters:
      - name: Authorization
        in: header
        required: true
        schema:
          type: string
        example: Bearer YOUR_API_KEY
        description: Bearer credential for the authentication scheme required by this endpoint.
      - name: id
        in: path
        required: true
        schema:
          type: string
        example: client-beta
        description: Company shell slug from `GET /api/v0/company_shells`.
      responses:
        '200':
          description: 'Reads or updates one partner-owned company shell by slug. Updatable fields are `name`, `description`, and `web`; a logo is required on create (multipart `logo` or `remote_logo_url`), where `remote_logo_url` must be a publicly reachable https URL — private or internal hosts are rejected with `could not download logo`. Partner-only: requires an authorized partner account; standard company API keys receive 403.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                      type:
                        type: string
                      attributes:
                        type: object
                        properties:
                          name:
                            type: string
                          description:
                            type: string
                          web:
                            type: string
                          logo:
                            type: string
                        required:
                        - name
                        - description
                        - web
                        - logo
                    required:
                    - id
                    - type
                    - attributes
                required:
                - data
              example:
                data:
                  id: client-beta
                  type: company_shell
                  attributes:
                    name: Client Beta
                    description: Client company 22 builds software products for distributed teams.
                    web: https://client-company-21.example.com
                    logo: /uploads/company_shells/logo/24/logo.jpg
        '403':
          description: 'Returns the partner-owned company shells available for shell-branded job posting. Partner-only: requires an authorized partner account; standard company API keys receive 403.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                  code:
                    type: string
                required:
                - message
                - code
              example:
                message: (Status 403) Partner company shells are not enabled for this account
                code: forbidden
        '404':
          description: 'Reads or updates one partner-owned company shell by slug. Updatable fields are `name`, `description`, and `web`; a logo is required on create (multipart `logo` or `remote_logo_url`), where `remote_logo_url` must be a publicly reachable https URL — private or internal hosts are rejected with `could not download logo`. Partner-only: requires an authorized partner account; standard company API keys receive 403.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                  code:
                    type: string
                required:
                - message
                - code
              example:
                message: Record not found
                code: not_found
      operationId: retrieveCompanyShell
    put:
      summary: List company shells
      tags:
      - Company shells
      security:
      - ApiKeyAuth: []
      parameters:
      - name: Authorization
        in: header
        required: true
        schema:
          type: string
        example: Bearer YOUR_API_KEY
        description: Bearer credential for the authentication scheme required by this endpoint.
      - name: id
        in: path
        required: true
        schema:
          type: string
        example: client-beta
        description: Company shell slug from `GET /api/v0/company_shells`.
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                company_shell:
                  type: object
                  properties:
                    description:
                      type: string
                    name:
                      type: string
                    web:
                      type: string
                  required:
                  - description
              required:
              - company_shell
            example:
              company_shell:
                description: Updated shell profile description for the partner-managed client.
                name: Client Beta Renamed
                web: https://client-beta-renamed.example.com
      responses:
        '200':
          description: 'Reads or updates one partner-owned company shell by slug. Updatable fields are `name`, `description`, and `web`; a logo is required on create (multipart `logo` or `remote_logo_url`), where `remote_logo_url` must be a publicly reachable https URL — private or internal hosts are rejected with `could not download logo`. Partner-only: requires an authorized partner account; standard company API keys receive 403.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                      type:
                        type: string
                      attributes:
                        type: object
                        properties:
                          name:
                            type: string
                          description:
                            type: string
                          web:
                            type: string
                          logo:
                            type: string
                        required:
                        - name
                        - description
                        - web
                        - logo
                    required:
                    - id
                    - type
                    - attributes
                required:
                - data
              example:
                data:
                  id: client-beta
                  type: company_shell
                  attributes:
                    name: Client Beta Renamed
                    description: Updated shell profile description for the partner-managed client.
                    web: https://client-beta-renamed.example.com
                    logo: /uploads/company_shells/logo/21/logo.jpg
        '403':
          description: 'Returns the partner-owned company shells available for shell-branded job posting. Partner-only: requires an authorized partner account; standard company API keys receive 403.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                  code:
                    type: string
                required:
                - message
                - code
              example:
                message: (Status 403) Partner company shells are not enabled for this account
                code: forbidden
        '404':
          description: 'Reads or updates one partner-owned company shell by slug. Updatable fields are `name`, `description`, and `web`; a logo is required on create (multipart `logo` or `remote_logo_url`), where `remote_logo_url` must be a publicly reachable https URL — private or internal hosts are rejected with `could not download logo`. Partner-only: requires an authorized partner account; standard company API keys receive 403.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                  code:
                    type: string
                required:
                - message
                - code
              example:
                message: Record not found
                code: not_found
      operationId: updateCompanyShell
components:
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: API key
      description: 'Company authentication for private endpoints. Send `Authorization: Bearer <api_key>`.'
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Professional JWT token obtained via /api/v0/auth_tokens
    BoardSecretKey:
      type: http
      scheme: bearer
      bearerFormat: Board secret
      description: 'Board+ HMAC secret key. Send `Authorization: Bearer <board_secret_key>`. The legacy query-string form (`?secret_key=...`) is still accepted by the server but is discouraged because secrets leak into logs, browser history, and referrers.'
x-tagGroups:
- name: Public
  tags:
  - Categories
  - Companies
  - Countries
  - Headcounts
  - Industries
  - Insights
  - Modalities
  - Perks
  - Regions
  - Search
  - Seniorities
  - Tags
  - Tenant Cities
- name: Private
  tags:
  - Applications
  - Company shells
  - Jobs
  - Matching
  - Processes
  - Professionals
  - Webhooks
- name: Authentication
  tags:
  - Authentication
- name: Board+
  tags:
  - Board+