API Support
Overview
CRM M2M API 1.1.0
Section titled “CRM M2M API 1.1.0”Machine-to-Machine (M2M) API for the CRM system using OAuth 2.0.
Overview
This is the integrator-facing surface of the CRM. It is read-oriented for catalog data: with an OAuth 2.0 client-credentials access token your integration can read Products and Brands (list, get-by-id, search). It also covers the admin endpoints used to create and manage M2M OAuth clients, and the Cognito token endpoint.
Client (customer) data is not exposed by this API. clients is not a
grantable scope — no M2M token can be issued with
clients.read/clients.write, and every /clients* route returns 403
regardless of scope.
Authentication
- Catalog endpoints (Products, Brands) require an OAuth 2.0 access
token from the client-credentials flow, with the matching
crm-api/<resource>.readscope. - Client-management endpoints (
/oauth/clients) require a Cognito ID token with Admin group membership — these are not callable with an M2M client-credentials token. /oauth2/tokenis the Cognito token endpoint (different host).
Scopes
M2M clients can be granted products and brands read/write scopes only.
Quote and template workflows are part of the web application and are not
exposed to the M2M API; client (customer) data is likewise not exposed (see
above).
Field Policy
The Product and Brand schemas below describe the exact external
contract an M2M caller receives — every field either schema documents is
everything that endpoint can ever return to this caller class. Cost and
margin fields other than supplierCost are never returned, and the
caller cannot widen the field set. Any field not in the documented
schema is never included, regardless of any fields= query
parameter — requesting one (e.g. fields=brandId) silently omits it
rather than widening the response, and increments an internal
M2MDeniedField metric. GET /brands/overview is not part of this API
— it is an internal pricelist-import operational surface and returns 403
to every M2M token, even one holding brands.read.
Authentication
Section titled “ Authentication ”M2MAuth
Section titled “M2MAuth ”OAuth 2.0 client-credentials access token (Bearer). Obtain via
/oauth2/token. Used for all catalog (Products/Brands) endpoints
with the matching crm-api/<resource>.read scope. clients is not a
grantable resource — see the Field Policy note above.
Security scheme type: oauth2
Flow type: clientCredentials
Token URL: https://your-cognito-domain.example.com/oauth2/token
Scopes:
- crm-api/products.read - Read products
- crm-api/products.write - Write products (e.g. catalog sync)
- crm-api/brands.read - Read brands
- crm-api/brands.write - Write brands
CognitoAuth
Section titled “CognitoAuth ”Cognito ID token with Admin group membership. Required for the
client-management endpoints (/oauth/clients). Obtained via Cognito user
authentication — not the M2M client-credentials flow.
Security scheme type: http
Bearer format: JWT