Cypher developer platform · v1

Connect your systems.
Keep the warehouse in sync.

One tenant-scoped API for product master data, sales and purchase orders, stock visibility, tracking and warehouse events.

Versioned contractsScoped accessAuditable operations
● ● ●First requestHTTPS
# Validate your tenant and credential
curl -i "https://YOUR_API_HOST/api/public/v1/FLSA/ping" \
  -H "X-API-Key: YOUR_KEY"

# 200 OK · API-Version: v1
{ "tenantCode": "FLSA", ... }
Built for server-to-server integrations
01 / GET STARTED

From access to first order.

Use the authenticated Cypher developer portal to create an application and issue a display-once UAT key. Keep credentials on your server, choose the scopes and client/site boundary you need, then confirm access with GET /ping.

01

Create an application

A tenant integration administrator sets scopes, rate limit and optional client/site restrictions.

02

Issue a UAT key

Copy the display-once key into a secure secret store. UAT and production credentials are separate.

03

Make a request

Call the versioned tenant path over HTTPS and retain the correlation ID from responses.

BASE PATH/api/public/v1/{tenantCode}Replace YOUR_API_HOST with the API host supplied for your environment.
02 / SECURITY

Access with boundaries built in.

Send the display-once credential as X-API-Key. Alternatively, a configured Microsoft Entra client-credentials application can use Authorization: Bearer. Both modes are tenant-bound; scopes and optional client/site restrictions are enforced by the API.

Never expose keys

Do not put credentials in browser code, mobile packages, repositories, logs or support tickets.

Choose least privilege

Grant only the resource scopes and client/site access that your integration requires.

03 / REFERENCE

Explore the API surface.

The catalogue below is an orientation, not a replacement for the live OpenAPI 3.1 contract at /developers/openapi/v1.json on your API host. Paths shown here are relative to the tenant base path.

Products & catalogue

Keep SKU master data in sync with the warehouse.

5 endpoints
GET/productsSearch and page products
GET/products/{sku}Retrieve a SKU
POST/productsCreate a product
PUT/products/{sku}Update a product
DELETE/products/{sku}Archive a product

Orders

Submit and follow both sides of the fulfilment flow.

6 endpoints
GET/sales-ordersList sales orders
POST/sales-ordersCreate a sales order
GET/sales-orders/{reference}Retrieve an order
GET/purchase-ordersList purchase orders
POST/purchase-ordersCreate a purchase order
GET/purchase-orders/{reference}Retrieve a purchase order

Inventory & visibility

Query stock and the evidence behind an order.

6 endpoints
GET/inventoryStock position
GET/inventory/availabilityAvailable-to-sell position
GET/sales-orders/{reference}/statusSales order progress
GET/purchase-orders/{reference}/statusPurchase order progress
GET/sales-orders/{reference}/trackingConsignments and tracking
GET/audit/{documentType}/{reference}Document audit history

Webhooks & bulk

Move from polling to events, and validate batches before submission.

7 endpoints
GET/webhooks/eventsSupported event types
GET/webhooksList subscriptions
POST/webhooksCreate a subscription
GET/webhooks/{id}/deliveriesDelivery history
POST/bulk-imports/orders/previewValidate an order batch
POST/bulk-imports/ordersSubmit an order batch
GET/integration-monitor/summaryIntegration health
04 / OPERATIONS

Design for safe retries.

01

Idempotency

Every POST, PUT, PATCH and DELETE needs an Idempotency-Key of 8–128 characters. Reuse the same key for retries of the same operation; retained results last 24 hours.

02

Rate limiting

Limits are set per API application. On HTTP 429, honour Retry-After and back off with jitter.

03

Errors & tracing

Errors use application/problem+json. Keep X-Correlation-ID for investigation and ignore additive response fields within v1.

05 / EVENTS

Let the warehouse tell you what changed.

Subscribe an HTTPS destination to supported events, verify the X-Cypher-Signature-256 HMAC-SHA256 signature, and inspect durable delivery history when a receiver is unavailable. Failed deliveries can be retried.

DISCOVER EVENT TYPESGET /webhooks/eventsRequest the current event list rather than hard-coding assumptions.
06 / GO LIVE

Prove the integration before production.

Test in UAT, including secure secret storage, idempotent retries, error handling and an end-to-end order/inventory flow. Production access requires a separate application and credential; where certification is enabled, an independent platform administrator reviews UAT evidence before approval.