API overview
Base URL, authentication, workspace selection, request conventions, pagination, idempotency and limits for the Nexra platform API.
Updated 07/10/2026
On this page
Base URL
https://ca-amakora-devportal-api-prod.salmonground-f19b34da.uksouth.azurecontainerapps.ioEvery path in this reference is relative to that host. Paths are not versioned globally; versioned families carry their version in the path (/api/agentic-commerce/v1, /api/scim/v2). Breaking changes are announced in the changelog first.
API families
| Family | Prefix | Auth | Reference |
|---|---|---|---|
| Public catalogue, docs, search and connectors | /api/developer-portal/public, /api/public/connect | None | Public API |
| Health and status | /health, /api/status | None | Public API |
| Nexra Connect | /api/console/connect | Session token | Connections, Integrations and flows, Runs, schedules and deployments |
| Approvals | /api/console/approvals | Session token | Runs, schedules and deployments |
| Developer portal | /api/developer-portal | Session token | Developer portal API |
| Webhooks | /api/developer-portal/apps/:appId/webhooks | Session token | Webhooks API |
| MCP runtime and console | /mcp, /api/console/apps/:appId/mcp | MCP token or session token | MCP API |
Authentication
Authorization: Bearer <access token>
X-Workspace-Id: <workspace id>X-Workspace-Id is optional; without it the request uses your oldest active workspace. See Authentication.
Request conventions
Send and receive JSON (Content-Type: application/json). Unknown fields in validated bodies are ignored.
IDs are opaque strings; do not parse them.
Timestamps are ISO 8601 in UTC.
Optional X-Request-ID is echoed back on the response for tracing.
Responses include X-Content-Type-Options: nosniff, X-Frame-Options: DENY and Referrer-Policy: no-referrer.
Pagination
Most list endpoints return a plain array, newest first, with a fixed cap that each endpoint documents (for example the 50 most recent sync runs or 100 most recent deliveries). Exceptions:
| Endpoint | Parameters |
|---|---|
GET /api/console/connect/executions | pageSize 1–100 (default 50), plus flowId and status filters |
GET /api/developer-portal/audit-events | limit 1–100 (default 50) and cursor; the response includes nextCursor |
GET /api/developer-portal/logs/* | limit 1–100 (default 50) |
Idempotency
Operations that start work take an idempotency key in the request body:
| Operation | Field | Behaviour on replay |
|---|---|---|
Run a flow (POST …/flows/:flowId/executions) | idempotencyKey, correlationId | Returns the original execution with replayed: true; 409 if the key was used for another flow or environment |
Sync a connection (POST …/connections/:id/sync) | idempotencyKey, correlationId | Returns the original run with replayed: true |
| Retry a dead letter | idempotencyKey (optional) | Defaults to dead-letter:<id>:<attempt> |
| Create an approval request | idempotencyKey | 409 if reused with a different payload |
| MCP trigger tools | idempotencyKey argument | Returns the original execution |
Keys are 8–160 characters of letters, digits, ., _, : and -. The agentic commerce API uses an Idempotency-Key header instead.
Errors and limits
Errors use one envelope with a request ID: see Errors and request IDs.
Rate limits and their headers: see Rate limits.
Machine-readable specifications
Published API products have downloadable OpenAPI documents (see the API reference). The platform API itself is documented on these pages; an OpenAPI document for it is planned.