Authentication & Access
Business API access is controlled by API key, client status/validity, company assignments and scopes.
API key header
X-IMS-API-Key: YOUR_API_KEY
The complete key is shown only when it is generated or rotated. Existing keys cannot be recovered. Store the key in an appropriate secret store rather than source code or configuration committed to version control.
Access checks
- The key must exist and be active.
- The API client must be active and within its Valid From / Valid Until window.
- The requested company must be assigned to the client.
- The client must have the scope required by the endpoint.
- The client must remain within its minute/day request limits.
Scope-to-resource map
| Scope | Resources |
|---|---|
stores.read | /stores |
items.read | /items |
sales.read | /sales |
inventory.read | /inventory, /inventory/movements |
purchases.read | /suppliers, /purchases |
transfers.read | /transfers |
adjustments.read | /stock-adjustments, /stock-depreciations |
promotions.read | /markdowns, /promotions and promotion relations, /discount-coupon-events |
Company confidentiality
When the caller does not have access to a company, the API returns the same 404 company_not_found response used when the company is unavailable. This avoids disclosing company existence to unauthorized clients.
Key lifecycle
Keys may be generated, rotated or revoked by authorized IMS administrators. Rotation creates a replacement key and invalidates the old key. Revocation is immediate; subsequent calls with the revoked key return 401 unauthorized.