Connect Apus to third-party systems via API
Apus exposes a REST API and webhooks so you can sync data both ways with external systems. This article covers authentication, the two integration patterns and good practice.
Get API credentials
- Go to Admin → API & integrations.
- Create an API client and scope it to the modules it needs.
- Store the client secret securely — it is shown once.
- Use the secret to request an access token for each call.
Pull data (REST)
Call the REST endpoints to read or write records — invoices, products, partners and more. Requests are scoped to your client's permissions, so an integration only ever sees what its role allows.
Push events (webhooks)
Register a webhook URL to receive events (e.g. an invoice posted, an order created) the moment they happen, instead of polling. Apus signs each payload so you can verify it came from your tenant.
Good practice
Use least-privilege scopes per integration, rotate secrets periodically, and verify webhook signatures. Every API client's activity is visible in the audit log.
Create one API client per external system so you can revoke or rotate access without affecting the others.