API platform
Stable contracts for every Nasak service.
Versioned APIs, scoped OAuth clients, signed webhooks, and migration notices in one place.
API domains
LibraryBooks, requests, uploads, secure files, reader and moderation
CommerceCatalog, orders, payments
HROrganizations, workforce, recruitment, performance, learning and employee lifecycle
HSESafety, health, environment, compliance, AI, BI and integrations
MessagingSMS and notifications
SupportTickets, messages, private attachments
FeedbackIdeas, follow-ups, moderation
BoardProjects, tasks, members, reports, mind maps
Content & SEOBook pages, blog, metadata, SEO, Search Console
PlatformClients and operations
Platform AdminStores, users, monitoring, logs
Security
OAuth by default
- Authorization Code with PKCE for browser applications.
- Client credentials and dedicated audiences for services.
- Ten-minute user access tokens and five-minute service tokens.
- Service-owned tenant and record authorization.
Client onboarding
Access is reviewed before credentials are issued.
Provide the owner, exact scopes, HTTPS origins, quota requirements, and intended data use.
Compatibility
Legacy routes remain observable for 90 days.
Deprecation, Sunset, and Link headers announce replacements. Removal occurs only after confirmed usage reaches zero.