IMS API
Central service layer used by IMS for secure bootstrap, Global administration and the read-only External Business API v1 through route-separated security boundaries.
Current responsibilities
IMS.Api is the trusted service boundary used by the client/administration applications for workstation checks, global authentication, company authorization/routing, Global Administrator sessions, company/user/workstation administration, system version management and protected secret access.
Global administration
IMS Global does not write global administration data by opening ims_global directly. Its Companies, Users, Workstations and System Version operations are mediated through authenticated Global Admin API calls. Database runtime/provisioning information is also requested through that authorized service boundary.
Business API v1
The External Business API v1 is a live, read-only contract separate from Bootstrap and Global administration. External clients authenticate with X-IMS-API-Key, are restricted to assigned companies/scopes and read approved business data through /api/v1/companies/{companyId}/... routes.
The business contract covers stores, items, suppliers, sales, purchases, inventory/balances/movements, transfers, adjustments/depreciation, markdowns, promotions and discount-coupon event metadata. External clients do not receive direct PostgreSQL access.