Integration
Document management REST API
The REST API exposes documents, folders, metadata, versions, permissions, workflow instances, signature requests and audit events. It authenticates with scoped API keys, paginates consistently, and returns a documented error contract rather than a bare HTTP status code and an empty body.
What this connection does
The REST API covers documents, folders, metadata, versions, permissions, workflow instances, signature requests and audit events. It authenticates with scoped API keys, paginates consistently across every collection endpoint, and returns a documented error contract rather than a bare status code and an empty body.
The contract matters more than the coverage. An API that changes shape between releases costs more to depend on than one with fewer endpoints and a stable interface, so breaking changes are versioned rather than shipped in place.
What you need on your side
- An API key created in DocumentMS, scoped to the modules and permission levels the integration needs
- A decision about which system is authoritative for each field, made before writing code
- Somewhere to store the key securely — it carries the permissions you granted it
Setting it up
Step 1: Create a scoped key
Create a key limited to the modules and permission levels required. Avoid reusing a key across integrations; revocation should not be collateral.
Step 2: Authenticate
Pass the key on each request. Key creation, use and revocation are all recorded in the audit trail.
Step 3: Handle pagination and errors
Every collection endpoint paginates the same way, and errors return a machine-readable code rather than only a status.
Step 4: Move to webhooks for events
Do not poll for changes. Subscribe to webhooks so your system is told rather than asking.
Limits worth knowing before you rely on it
- Rate limits are 1,000 requests per minute per key with a 100 per second burst. Every response carries the limit, the remaining allowance and the reset time as headers, so backoff can be driven by the response rather than by guesswork
- Breaking changes ship as a new path version, and the previous version runs for 12 months from the deprecation notice. Deprecations are announced by email to every key owner and in the response headers of the affected version
- API keys carry the permissions granted at creation and do not inherit a user context — an over-scoped key is the most common integration security mistake we see
Última revisão: 2026-09-01