Get BOM
GET/api/manufacturing/boms/:id
Get a single BOM with its product, component lines, output lines, operations (with work centers), and creator, plus manufacturing_orders_count.
manufacturing:readGrant this scope to your token under Settings → Developer → Personal Access Tokens.
The BOM carries default_consumption_method (forward_flush | backflush | null) — the default inherited by component lines that don't set their own — and each component_lines[] row carries its effective consumption_method. forward_flush components are issued explicitly by the operator when production is recorded; backflush components are auto-consumed from the produced output quantity multiplied by the BOM per-unit usage.
Auth: requires Bearer token.
Lot traceability. The response carries lot_traceability_gap: null when there is no gap, otherwise {output_sku, components:[{id, sku, name}]} naming the components that are not lot-tracked while the output is. Their consumption will not appear in the finished lot's genealogy, so a recall cannot trace them. Non-blocking — the recipe is valid — but worth surfacing wherever the recipe is shown.
Contractor-supplied components: set component_lines[].is_contractor_supplied to true when the contract manufacturer provides that component from their own stock. It stays in the recipe and in lot genealogy, but is never allocated from your inventory, never reported as short, and never costed into the finished good — its cost is already inside the contractor's price on the purchase order. Defaults to false; omit the key on an update and the stored value is left unchanged.
Request
Responses
- 200
- 401
- 403
- 404
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.