API เป็นสัญญาที่ต้องดูแล ไม่ใช่รายการ route ที่ค้นพบ
CuteERP ให้บริการ integration แบบ managed ระหว่างที่ public API contract ยังอยู่ในขั้นอนุมัติ ทีมจะกำหนด use case, tenant scope, auth, version, error และ support ก่อนเปิด endpoint
API acceptance path
- 1Use case & owner
- 2Data and tenant scope
- 3Auth & permissions
- 4Contract & examples
- 5Sandbox/UAT
- 6Versioned release
หมายเหตุสำคัญInternal Next.js handlers, proxy paths และ methods ภายในระบบไม่ใช่ public API โดยอัตโนมัติ ห้ามใช้ server secret ใน browser หรือผูกระบบภายนอกกับ route ภายในโดยไม่มี contract
สิ่งที่ Managed API ต้องกำหนด
- Authentication และ tenant/company scope
- Resource/method allowlist และ permission
- Schema, pagination, errors และ idempotency
- Rate/volume expectation และ timeout/retry
- Webhook signature และ replay protection
- Versioning, deprecation และ owner
เอกสารที่จะส่งมอบเมื่อ Contract ผ่าน
- Quickstart
- วิธีรับ credential และเรียก sandbox อย่างปลอดภัย
- OpenAPI reference
- Endpoint/schema ที่สร้างจาก contract ไม่ใช่ route inventory
- Examples
- ตัวอย่าง success, validation, permission และ retry
- Changelog
- Version, breaking change, migration window และ deprecation
- Support
- Owner, incident path และขอบเขต SLA ที่ลงนาม
เริ่มจากเหตุผลที่ต้องเชื่อม ไม่ใช่ endpoint ที่อยากเรียก
ส่งระบบต้นทาง/ปลายทาง เจ้าของข้อมูล ปริมาณ ความถี่ และ failure policy ทีมจะตอบว่าใช้ connector เดิม Managed API หรือยังไม่ควรเปิด contract