Each service retains its own authorization. An ERP API key does not automatically authenticate Documents, Chat, Academy or Collaborate. Start with a least-privilege integration user and the service-specific contract below.
ERP request
Use an API key and secret issued to an authorized ERP user. Treat them as credentials; never embed privileged keys in public pages.
curl 'https://enterprise.nexcommand.ai/api/method/frappe.auth.get_logged_user' \
-H 'Authorization: token YOUR_KEY:YOUR_SECRET'
Records & workflow
Record APIs cover all installed modules. Child tables belong to parent records; singletons and document actions use their native routes. Financial posting, payroll, approvals and deletion require the appropriate roles and validation.
Session writes require CSRF. Integration retries must respect rate limits and use business identifiers to avoid duplicate transactions.
Events & integration
ERP webhooks are configured by authorized administrators. Collaborate event queues and Chat webhook subscriptions use their own contracts. Internal bridge workers are not public endpoints.
SDK and extension messages are documented separately from HTTP APIs. Disabled and internal contracts do not become externally available because they appear here.