> ## Documentation Index
> Fetch the complete documentation index at: https://docs.telemax.com.au/llms.txt
> Use this file to discover all available pages before exploring further.

# List companies

> Returns a paginated list of companies accessible to the authenticated token.

### Overview

Returns companies in the caller's accessible hierarchy. The token's `CompanyId` claim is the root; sub-companies are included where the caller has access.

<Note>This endpoint replaces V1 [Company tree](/v1/api-reference/post-get-companies).</Note>

<Note>**Rate limit:** 4 req/s · 30/min · 600/hr · 14,400/day</Note>

### Endpoint

`GET /v2/api/companies`

### Query parameters

<ParamField query="page" type="integer" default="1">
  Page number (1-based).
</ParamField>

<ParamField query="pageSize" type="integer" default="50">
  Records per page.
</ParamField>

### Response

**200 OK** — `CompaniesPagedResultDto` (extends `PagedListResult<CompanyDto>`)

`CompanyDto` fields:

| Field        | Type            | Description                                                          |
| ------------ | --------------- | -------------------------------------------------------------------- |
| id           | integer         | Company ID                                                           |
| name         | string          | Company display name                                                 |
| parentId     | integer \| null | Parent company ID (`null` for root)                                  |
| showCommands | boolean         | Whether command actions are shown for this company                   |
| level        | integer         | Company hierarchy depth (0 = root)                                   |
| apiKey       | string \| null  | Company API key. `null` if no API key is configured for this company |

The response envelope adds these locale fields alongside the standard pagination fields:

| Field          | Type   | Description                                                                                                                                                     |
| -------------- | ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| dateTimeFormat | string | Authenticated user's preferred date/time format (e.g. `"dd/MM/yyyy HH:mm"`)                                                                                     |
| timezone       | string | Authenticated user's IANA timezone identifier (e.g. `"Australia/Brisbane"`)                                                                                     |
| utcOffset      | string | UTC offset for the user's timezone at request time. Positive offsets have no sign prefix (e.g. `"10:00:00"`); negative offsets include `-` (e.g. `"-05:00:00"`) |

### Example response

```json theme={null}
{
  "items": [
    { "id": 12, "name": "Acme Fleet", "parentId": null, "showCommands": false, "level": 0, "apiKey": null },
    { "id": 34, "name": "Acme Sydney", "parentId": 12, "showCommands": false, "level": 1, "apiKey": null }
  ],
  "currentPage": 1,
  "numberOfPages": 1,
  "totalResults": 2,
  "lastResultIndex": 1,
  "dateTimeFormat": "dd/MM/yyyy",
  "timezone": "Australia/Brisbane",
  "utcOffset": "10:00:00"
}
```

### Error responses

| Status | Meaning                  |
| ------ | ------------------------ |
| 401    | Missing or invalid token |

```bash theme={null}
curl "https://api.telemax.com.au/v2/api/companies" \
  -H "Authorization: Bearer <token>"
```


## OpenAPI

````yaml openapi.yaml GET /v2/api/companies
openapi: 3.1.0
info:
  title: Telemax External API (V2)
  version: '2026-04-14'
  description: >
    Telemax External API — fleet telemetry, vehicle commands, and integrations.


    **Base URL:** `https://api.telemax.com.au`


    **Authentication:** All routes require a `Bearer` JWT unless marked
    `[AllowAnonymous]`.

    Obtain tokens via `POST /v2/api/authentication/token/api-key`.


    **RESTful architecture:** V2 uses standard HTTP methods (GET, POST, PUT,
    DELETE) with

    resource-based routes and consistent pagination via `page` and `pageSize`
    query parameters.


    **API versioning:** All responses will include an `X-API-Version` header
    containing the

    date-based version string (e.g. `2026-04-28`). See the
    [Changelog](/v2/changelog) for

    the deprecation policy and version history.


    For full documentation including error handling, pagination, and known field
    quirks, see [docs.telemax.com.au](https://docs.telemax.com.au).
servers:
  - url: https://api.telemax.com.au
security:
  - BearerAuth: []
paths:
  /v2/api/companies:
    get:
      summary: List companies (V2)
      description: >-
        Returns a paginated list of companies accessible to the authenticated
        token. The `utcOffset` field is a .NET TimeSpan string — positive
        offsets have no sign prefix (e.g. `"10:00:00"` for UTC+10), negative
        offsets include a `-` prefix (e.g. `"-05:00:00"` for UTC-5).
      parameters:
        - name: page
          in: query
          schema:
            type: integer
            default: 1
        - name: pageSize
          in: query
          schema:
            type: integer
            default: 50
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              example:
                dateTimeFormat: dd/MM/yyyy
                timezone: Australia/Brisbane
                utcOffset: '10:00:00'
                items:
                  - id: 12
                    name: Acme Fleet
                    parentId: null
                    showCommands: false
                    level: 0
                    apiKey: null
                  - id: 34
                    name: Acme Sydney
                    parentId: 12
                    showCommands: false
                    level: 1
                    apiKey: null
                totalResults: 2
                lastResultIndex: 2
                currentPage: 1
                numberOfPages: 1
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  responses:
    Unauthorized:
      description: >
        **401 Unauthorized** — JWT is missing, expired, or malformed.

        The JWT bearer middleware rejects the request before it reaches the
        controller.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: AUTHENTICATION
            code: INVALID_CREDENTIALS
            description: The provided API key is invalid or does not exist.
            requestId: 0HNLTALNU4DCO:00000004
            docUrl: https://docs.telemax.com.au/errors/invalid-credentials
    Forbidden:
      description: >
        **403 Forbidden** — Token is valid but the caller does not have access
        to the requested company or vehicle.

        Tokens issued for one company cannot access resources scoped to a
        different company in the hierarchy.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: AUTHORIZATION
            code: INVALID_SCOPE
            description: >-
              The provided token does not have permission to access this
              resource.
            requestId: 50e5c5f7-ccae-4ab6-b070-56d6645ceb1e
            docUrl: https://docs.telemax.com.au/errors/invalid-scope
    TooManyRequests:
      description: >
        **429 Too Many Requests** — Rate limit exceeded. Check the Retry-After
        header for the number of seconds to wait before retrying.

        Use exponential backoff: wait Retry-After seconds, then double the
        interval on each subsequent 429.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
        Retry-After:
          $ref: '#/components/headers/Retry-After'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: RATE_LIMIT
            code: RATE_LIMIT_EXCEEDED
            description: Too many requests. Please slow down.
            requestId: req_6d2f8b4a
            docUrl: https://docs.telemax.com.au/errors/rate-limit-exceeded
    InternalServerError:
      description: >
        **500 Internal Server Error** — An unexpected error occurred. Include
        the requestId when contacting support.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: SERVER_ERROR
            code: INTERNAL_SERVER_ERROR
            description: An unexpected error occurred. Please try again later.
            requestId: req_1e5a3c7d
            docUrl: https://docs.telemax.com.au/errors/internal-server-error
  headers:
    X-RateLimit-Limit:
      description: >-
        Maximum number of requests allowed per minute for this token. **Not yet
        active** — this header will be added once the rate-limit middleware is
        deployed. See the [Changelog](/v2/changelog) for the rollout date.
      schema:
        type: integer
        example: 60
    X-RateLimit-Remaining:
      description: >-
        Number of requests remaining in the current rate limit window. **Not yet
        active** — see `X-RateLimit-Limit`.
      schema:
        type: integer
        example: 47
    X-RateLimit-Reset:
      description: >-
        Unix timestamp (seconds) at which the current rate limit window resets.
        **Not yet active** — see `X-RateLimit-Limit`.
      schema:
        type: integer
        example: 1746000060
    Retry-After:
      description: Number of seconds to wait before retrying after a 429 response.
      schema:
        type: integer
        example: 30
  schemas:
    ApiError:
      type: object
      description: Standard error response returned by all API endpoints.
      properties:
        type:
          type: string
          description: >-
            Error category (e.g. AUTHENTICATION, AUTHORIZATION, RESOURCE,
            VALIDATION_ERROR, RATE_LIMIT, SERVER_ERROR).
          example: AUTHENTICATION
        code:
          type: string
          description: Machine-readable error code within the category.
          example: INVALID_CREDENTIALS
        description:
          type: string
          description: Human-readable explanation of the error and how to resolve it.
          example: The provided API key is invalid or does not exist.
        requestId:
          type: string
          description: Unique request identifier for support correlation.
          example: req_7f3a2b1c
        docUrl:
          type: string
          format: uri
          description: Link to the relevant error documentation page.
          example: https://docs.telemax.com.au/errors/invalid-credentials
      required:
        - type
        - code
        - description
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        JWT Bearer token obtained from `POST
        /v2/api/authentication/token/api-key`.


        **Lifetime:** ~24 hours (86,399 seconds). Cache the token and reuse it.
        Re-authenticate 5 minutes before expiry.


        **Scoping:** API key tokens are scoped to the company the key belongs to
        and may restrict

        access to a vehicle allowlist and/or action set (see token claims).


        **No refresh endpoint** — re-authenticate with your API key when the
        token expires.

````