# Repository · History

Part of AppEngine API Documentation. Full index: https://appengine.appmint.io/documentation.md
## GET /repository/history/{datatype}/{id}

**Get a record's history**

`operationId: RepositoryController_history`

The revision history for a record — what changed, when and by whom. The basis for restoring an earlier version.

#### Signature

```http
GET /repository/history/{datatype}/{id} (datatype: string, id: string) -> The record's revisions
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`). Required role(s): `content:read`.

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `POST /repository/history/{restore}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `datatype` | path | string | yes | The collection to act on, e.g. `sf_product`, `customer`, `category`. Determines the shape of `data`. |
| `id` | path | string | yes | Record `sk`. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | The record's revisions |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /repository/history/{restore}

**Restore a record revision**

`operationId: RepositoryController_historyRestore`

Restores a record to an earlier revision.

The `{restore}` path segment is part of the route but the work is driven by the body — pass the record and the revision to restore there.

#### Signature

```http
POST /repository/history/{restore} (restore: string, body) -> The restored record
```

#### Access

Requires a bearer JWT (`Authorization: Bearer <token>`). Required role(s): `content:create`, `content:update`.

#### Notes

- Restoring overwrites the current version — take the current state from `history` first if you may need it back.

#### Errors

Plus the standard platform errors: `401`, `403`, `429`, `500`.

#### See also

- `GET /repository/history/{datatype}/{id}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `restore` | path | string | yes | Path segment required by the route; the body carries the actual instruction. |

### Request body

Which record and revision to restore.

```json
{
  "datatype": "sf_product",
  "id": "66f1a2b3c4d5e6f708192a3b",
  "version": 3
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | The restored record |
| `401` | Authentication failed: Invalid or expired token — The `Authorization` header is missing, malformed, or the JWT has expired. |
| `403` | You do not have permission to perform this action — The caller is authenticated but lacks the role required by the endpoint, or is acting on another org. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

