Ir para o conteúdo principal
DocumentMS

Integration

Document management REST API

The REST API exposes documents, folders, metadata, versions, permissions, workflow instances, signature requests and audit events. It authenticates with scoped API keys, paginates consistently, and returns a documented error contract rather than a bare HTTP status code and an empty body.

What this connection does

The REST API covers documents, folders, metadata, versions, permissions, workflow instances, signature requests and audit events. It authenticates with scoped API keys, paginates consistently across every collection endpoint, and returns a documented error contract rather than a bare status code and an empty body.

The contract matters more than the coverage. An API that changes shape between releases costs more to depend on than one with fewer endpoints and a stable interface, so breaking changes are versioned rather than shipped in place.

What you need on your side

Have these ready before you start; the configuration itself takes minutes.
  • An API key created in DocumentMS, scoped to the modules and permission levels the integration needs
  • A decision about which system is authoritative for each field, made before writing code
  • Somewhere to store the key securely — it carries the permissions you granted it

Setting it up

Test with one user and one document before rolling out. Connection events and permission changes appear in the audit trail.
  1. Step 1: Create a scoped key

    Create a key limited to the modules and permission levels required. Avoid reusing a key across integrations; revocation should not be collateral.

  2. Step 2: Authenticate

    Pass the key on each request. Key creation, use and revocation are all recorded in the audit trail.

  3. Step 3: Handle pagination and errors

    Every collection endpoint paginates the same way, and errors return a machine-readable code rather than only a status.

  4. Step 4: Move to webhooks for events

    Do not poll for changes. Subscribe to webhooks so your system is told rather than asking.

Limits worth knowing before you rely on it

Stated up front rather than discovered later. Every integration has boundaries, and a directory that hides them just moves the discovery to a support ticket.
  • Rate limits are 1,000 requests per minute per key with a 100 per second burst. Every response carries the limit, the remaining allowance and the reset time as headers, so backoff can be driven by the response rather than by guesswork
  • Breaking changes ship as a new path version, and the previous version runs for 12 months from the deprecation notice. Deprecations are announced by email to every key owner and in the response headers of the affected version
  • API keys carry the permissions granted at creation and do not inherit a user context — an over-scoped key is the most common integration security mistake we see
We can set the connection up against a sandbox tenant on a demo call so you can see the behaviour rather than read about it.