IMS Documentation
IMS Business API v1

Authentication & Access

Business API access is controlled by API key, client status/validity, company assignments and scopes.

API key header

X-IMS-API-Key: YOUR_API_KEY

The complete key is shown only when it is generated or rotated. Existing keys cannot be recovered. Store the key in an appropriate secret store rather than source code or configuration committed to version control.

Access checks

  1. The key must exist and be active.
  2. The API client must be active and within its Valid From / Valid Until window.
  3. The requested company must be assigned to the client.
  4. The client must have the scope required by the endpoint.
  5. The client must remain within its minute/day request limits.

Scope-to-resource map

ScopeResources
stores.read/stores
items.read/items
sales.read/sales
inventory.read/inventory, /inventory/movements
purchases.read/suppliers, /purchases
transfers.read/transfers
adjustments.read/stock-adjustments, /stock-depreciations
promotions.read/markdowns, /promotions and promotion relations, /discount-coupon-events

Company confidentiality

When the caller does not have access to a company, the API returns the same 404 company_not_found response used when the company is unavailable. This avoids disclosing company existence to unauthorized clients.

Key lifecycle

Keys may be generated, rotated or revoked by authorized IMS administrators. Rotation creates a replacement key and invalidates the old key. Revocation is immediate; subsequent calls with the revoked key return 401 unauthorized.