API Referencev1

API overview

Base URL, authentication, workspace selection, request conventions, pagination, idempotency and limits for the Nexra platform API.

Updated 07/10/2026

On this page

Base URL

text
https://ca-amakora-devportal-api-prod.salmonground-f19b34da.uksouth.azurecontainerapps.io

Every path in this reference is relative to that host. Paths are not versioned globally; versioned families carry their version in the path (/api/agentic-commerce/v1, /api/scim/v2). Breaking changes are announced in the changelog first.

API families

FamilyPrefixAuthReference
Public catalogue, docs, search and connectors/api/developer-portal/public, /api/public/connectNonePublic API
Health and status/health, /api/statusNonePublic API
Nexra Connect/api/console/connectSession tokenConnections, Integrations and flows, Runs, schedules and deployments
Approvals/api/console/approvalsSession tokenRuns, schedules and deployments
Developer portal/api/developer-portalSession tokenDeveloper portal API
Webhooks/api/developer-portal/apps/:appId/webhooksSession tokenWebhooks API
MCP runtime and console/mcp, /api/console/apps/:appId/mcpMCP token or session tokenMCP API

Authentication

http
Authorization: Bearer <access token>
X-Workspace-Id: <workspace id>

X-Workspace-Id is optional; without it the request uses your oldest active workspace. See Authentication.

Request conventions

Send and receive JSON (Content-Type: application/json). Unknown fields in validated bodies are ignored.

IDs are opaque strings; do not parse them.

Timestamps are ISO 8601 in UTC.

Optional X-Request-ID is echoed back on the response for tracing.

Responses include X-Content-Type-Options: nosniff, X-Frame-Options: DENY and Referrer-Policy: no-referrer.

Pagination

Most list endpoints return a plain array, newest first, with a fixed cap that each endpoint documents (for example the 50 most recent sync runs or 100 most recent deliveries). Exceptions:

EndpointParameters
GET /api/console/connect/executionspageSize 1–100 (default 50), plus flowId and status filters
GET /api/developer-portal/audit-eventslimit 1–100 (default 50) and cursor; the response includes nextCursor
GET /api/developer-portal/logs/*limit 1–100 (default 50)

Idempotency

Operations that start work take an idempotency key in the request body:

OperationFieldBehaviour on replay
Run a flow (POST …/flows/:flowId/executions)idempotencyKey, correlationIdReturns the original execution with replayed: true; 409 if the key was used for another flow or environment
Sync a connection (POST …/connections/:id/sync)idempotencyKey, correlationIdReturns the original run with replayed: true
Retry a dead letteridempotencyKey (optional)Defaults to dead-letter:<id>:<attempt>
Create an approval requestidempotencyKey409 if reused with a different payload
MCP trigger toolsidempotencyKey argumentReturns the original execution

Keys are 8–160 characters of letters, digits, ., _, : and -. The agentic commerce API uses an Idempotency-Key header instead.

Errors and limits

Errors use one envelope with a request ID: see Errors and request IDs.

Rate limits and their headers: see Rate limits.

Machine-readable specifications

Published API products have downloadable OpenAPI documents (see the API reference). The platform API itself is documented on these pages; an OpenAPI document for it is planned.

Need a hand?

Ask Nexra AI for implementation steps or error guidance.

Ask Nexra AI