/v1 API: every route, with its fields, roles and refusals. Generate a client from it in your own stack, for a core system, a connector or a back office, and have the client follow the rules below.
The OpenAPI document
Every deployment serves it atGET /v1/openapi.json, with no sign-in, and each release ships it as nodeasset-v1-<version>.yaml (Downloads). Take it from the release your deployment runs, so the client matches the API it calls.
Generate a client
Each route’s page in the API reference shows the call in curl, then through a client that OpenAPI Generator 7.25.0 makes from the document: TypeScript, Python, and Java on the JDK’s own HTTP client. Make the same client, and the samples run as they are:What a client must handle
- Decimals are plain JSON numbers with every digit. Have the generated code read
numberfields as an exact decimal type, never a float, or send and read them as strings. - Every write has one answer,
WriteAnswer, a single type with astate: branch onawaiting, and otherwise follow the operation by itsoperationId. - A refusal’s body is
application/problem+json: branch on the slug that ends itstypeand on itscheck, and show itsdetailandrecovery. - Each operation’s roles (
x-roles), its four-eyes rule (x-four-eyes) and the webhook bodies (x-webhooks) are vendor extensions most generators skip; read them from the document. - Send an
Idempotency-Keywith every write, built from your own id for the action, so a retry after a timeout or a lost answer is the same request (idempotency and retries). - Follow each operation to its end: read
GET /v1/operations/{operationId}until itsstateissucceededorfailed. A failed one carries itsproblem. - Page a list by sending each page’s
nextback asafter, untilnextis null; the event feed’s and the audit log’snextis never null, so poll them with the last one (pagination). - A service client signs each request with the HMAC key the engine holds for it, beside its bearer (request signing).
- Verify each webhook delivery’s signature and timestamp before you act on it, and drop one you have already handled (verify a delivery).

