Skip to content

Overview

Machine-to-Machine (M2M) API for the CRM system using OAuth 2.0.

Overview

This is the integrator-facing surface of the CRM. It is read-oriented for catalog data: with an OAuth 2.0 client-credentials access token your integration can read Products and Brands (list, get-by-id, search). It also covers the admin endpoints used to create and manage M2M OAuth clients, and the Cognito token endpoint.

Client (customer) data is not exposed by this API. clients is not a grantable scope — no M2M token can be issued with clients.read/clients.write, and every /clients* route returns 403 regardless of scope.

Authentication

  • Catalog endpoints (Products, Brands) require an OAuth 2.0 access token from the client-credentials flow, with the matching crm-api/<resource>.read scope.
  • Client-management endpoints (/oauth/clients) require a Cognito ID token with Admin group membership — these are not callable with an M2M client-credentials token.
  • /oauth2/token is the Cognito token endpoint (different host).

Scopes

M2M clients can be granted products and brands read/write scopes only. Quote and template workflows are part of the web application and are not exposed to the M2M API; client (customer) data is likewise not exposed (see above).

Field Policy

The Product and Brand schemas below describe the exact external contract an M2M caller receives — every field either schema documents is everything that endpoint can ever return to this caller class. Cost and margin fields other than supplierCost are never returned, and the caller cannot widen the field set. Any field not in the documented schema is never included, regardless of any fields= query parameter — requesting one (e.g. fields=brandId) silently omits it rather than widening the response, and increments an internal M2MDeniedField metric. GET /brands/overview is not part of this API — it is an internal pricelist-import operational surface and returns 403 to every M2M token, even one holding brands.read.

Information

  • License: Proprietary
  • OpenAPI version: 3.1.0

OAuth 2.0 client-credentials access token (Bearer). Obtain via /oauth2/token. Used for all catalog (Products/Brands) endpoints with the matching crm-api/<resource>.read scope. clients is not a grantable resource — see the Field Policy note above.

Security scheme type: oauth2

Flow type: clientCredentials

Token URL: https://your-cognito-domain.example.com/oauth2/token

Scopes:

  • crm-api/products.read - Read products
  • crm-api/products.write - Write products (e.g. catalog sync)
  • crm-api/brands.read - Read brands
  • crm-api/brands.write - Write brands

Cognito ID token with Admin group membership. Required for the client-management endpoints (/oauth/clients). Obtained via Cognito user authentication — not the M2M client-credentials flow.

Security scheme type: http

Bearer format: JWT