Connect a device or system
Every machine has its own username and password, issued by your Kealink administrator. A machine can send readings over MQTT, which suits gateways and PLCs that stay connected, or over HTTP, which suits devices that wake up and post. Other software can read data back with an API key.
1. Send readings over MQTT
| Server | mqtt.kealink.co.nz |
|---|---|
| Port | 50607, TLS on. A standard Let's Encrypt certificate: no CA file needed. |
| WebSockets (optional) | wss://ws.kealink.co.nz on port 443 |
| Username and client ID | the machine id |
| Password | the machine's password |
| Topic | kealink/<machine-id>/data |
| QoS | 1, retain off, clean session, keepalive 60 s |
Payload
One JSON object per message, usually every 30 seconds. Keys are the point keys your administrator set up; values are numbers.
{"ts": 1790000000000, "spindle_temp": 41.2, "hydraulic_pressure": 118.5, "running": 1}tsis optional: Unix time in milliseconds. Without it, arrival time is used. A time more than 24 hours old or 5 minutes ahead is replaced by arrival time.- Keys are lowercase letters, numbers and underscores. Unknown keys are ignored. true and false are stored as 1 and 0.
- To send buffered readings after a connection drop, send an array of up to 200 such objects, each with its own ts.
- Up to 16 KB per message. A burst of up to 120 messages is accepted, then about one a second.
- A machine can only publish to its own topic.
Test from a terminal
mosquitto_pub -h mqtt.kealink.co.nz -p 50607 --capath /etc/ssl/certs -q 1 \
-i <machine-id> -u <machine-id> -P '<password>' \
-t kealink/<machine-id>/data -m '{"spindle_temp": 40.1}'Node-RED
Use an mqtt out node with the server and port above, Use TLS ticked with the default TLS configuration, and the username and password on the Security tab. Build the payload in a function node:
msg.topic = "kealink/<machine-id>/data";
msg.payload = { ts: Date.now(), spindle_temp: global.get("spindle_temp") };
return msg;2. Send readings over HTTP
The same payload, posted with the machine id and password as HTTP Basic authentication. The reply says what was accepted.
curl -u '<machine-id>:<password>' -H 'content-type: application/json' \
-d '{"spindle_temp": 40.1, "running": true}' \
https://app.kealink.co.nz/api/v1/machines/<machine-id>/data| 202 | Accepted. Body: {"accepted": 2, "unknownKeys": [], "nonNumericKeys": [], "timestampsReplaced": 0} |
|---|---|
| 400 | The body is not valid JSON, or is not an object or an array of objects |
| 401 | Wrong machine id or password |
| 413 | Larger than 16 KB |
| 422 | None of the keys are points of this machine; the reply lists them |
| 503 | Temporarily unable to accept; retry after a few seconds |
3. Read data with the API
Ask your Kealink administrator for an API key. It reads one company's machines and cannot send data. Send it on every request:
Authorization: Bearer kl_xxxxxxxx_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
| GET /api/v1/machines | Every machine with its status, points, limits and each point's latest reading |
|---|---|
| GET /api/v1/machines/{id}/readings | ?point=<key>&from=<ISO time>&to=<ISO time>&resolution=raw|hour|day. Raw covers up to 31 days per request, hour and day up to 400. Hourly and daily rows include min, max and count. |
| GET /api/v1/alerts | Alerts, active first. Add ?open=true for active ones only. |
curl -H 'Authorization: Bearer <api key>' \ 'https://app.kealink.co.nz/api/v1/machines/<machine-id>/readings?point=spindle_temp&resolution=hour&from=2026-09-01T00:00:00Z'
Times are UTC in ISO 8601. Responses are JSON. Up to 50,000 rows per request; a larger range says truncated: true.