Connect your systems.
Keep the warehouse in sync.
One tenant-scoped API for product master data, sales and purchase orders, stock visibility, tracking and warehouse events.
# Validate your tenant and credential
curl -i "https://YOUR_API_HOST/api/public/v1/FLSA/ping" \
-H "X-API-Key: YOUR_KEY"
# 200 OK · API-Version: v1
{ "tenantCode": "FLSA", ... }From access to first order.
Use the authenticated Cypher developer portal to create an application and issue a display-once UAT key. Keep credentials on your server, choose the scopes and client/site boundary you need, then confirm access with GET /ping.
Create an application
A tenant integration administrator sets scopes, rate limit and optional client/site restrictions.
Issue a UAT key
Copy the display-once key into a secure secret store. UAT and production credentials are separate.
Make a request
Call the versioned tenant path over HTTPS and retain the correlation ID from responses.
/api/public/v1/{tenantCode}Replace YOUR_API_HOST with the API host supplied for your environment.Access with boundaries built in.
Send the display-once credential as X-API-Key. Alternatively, a configured Microsoft Entra client-credentials application can use Authorization: Bearer. Both modes are tenant-bound; scopes and optional client/site restrictions are enforced by the API.
Do not put credentials in browser code, mobile packages, repositories, logs or support tickets.
Grant only the resource scopes and client/site access that your integration requires.
Explore the API surface.
The catalogue below is an orientation, not a replacement for the live OpenAPI 3.1 contract at /developers/openapi/v1.json on your API host. Paths shown here are relative to the tenant base path.
Products & catalogue
Keep SKU master data in sync with the warehouse.
/productsSearch and page products/products/{sku}Retrieve a SKU/productsCreate a product/products/{sku}Update a product/products/{sku}Archive a productOrders
Submit and follow both sides of the fulfilment flow.
/sales-ordersList sales orders/sales-ordersCreate a sales order/sales-orders/{reference}Retrieve an order/purchase-ordersList purchase orders/purchase-ordersCreate a purchase order/purchase-orders/{reference}Retrieve a purchase orderInventory & visibility
Query stock and the evidence behind an order.
/inventoryStock position/inventory/availabilityAvailable-to-sell position/sales-orders/{reference}/statusSales order progress/purchase-orders/{reference}/statusPurchase order progress/sales-orders/{reference}/trackingConsignments and tracking/audit/{documentType}/{reference}Document audit historyWebhooks & bulk
Move from polling to events, and validate batches before submission.
/webhooks/eventsSupported event types/webhooksList subscriptions/webhooksCreate a subscription/webhooks/{id}/deliveriesDelivery history/bulk-imports/orders/previewValidate an order batch/bulk-imports/ordersSubmit an order batch/integration-monitor/summaryIntegration healthDesign for safe retries.
Idempotency
Every POST, PUT, PATCH and DELETE needs an Idempotency-Key of 8–128 characters. Reuse the same key for retries of the same operation; retained results last 24 hours.
Rate limiting
Limits are set per API application. On HTTP 429, honour Retry-After and back off with jitter.
Errors & tracing
Errors use application/problem+json. Keep X-Correlation-ID for investigation and ignore additive response fields within v1.
Let the warehouse tell you what changed.
Subscribe an HTTPS destination to supported events, verify the X-Cypher-Signature-256 HMAC-SHA256 signature, and inspect durable delivery history when a receiver is unavailable. Failed deliveries can be retried.
GET /webhooks/eventsRequest the current event list rather than hard-coding assumptions.Prove the integration before production.
Test in UAT, including secure secret storage, idempotent retries, error handling and an end-to-end order/inventory flow. Production access requires a separate application and credential; where certification is enabled, an independent platform administrator reviews UAT evidence before approval.