> ## Documentation Index
> Fetch the complete documentation index at: https://docs.arcuserp.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect an integration

> Configures and activates a connector for the entity, validating provider-specific settings such as a Shopify store URL or an AvaTax company code before saving; for Shopify, the response returns an OAuth URL to complete instead of activating immediately. Credentials are stored only in AWS Secrets Manager, never in the database; use the update operation if the connector already exists.



## OpenAPI

````yaml /openapi.yaml post /integrations/{connector_type}
openapi: 3.1.0
info:
  title: Arcus ERP Public API
  version: 1.0.0
  description: >
    Arcus ERP public REST API. Designed for external integrations and data
    migration.


    **Authentication.** Bearer token (API key) via the `Authorization` header.

    Format: `Authorization: Bearer ark_live_ent_<code>_<random>` (or
    `ark_test_*` for sandbox).

    API keys are issued per-entity in **Settings > Developers > API Keys**.


    **Entity scoping.** The entity is encoded in the API key prefix; routes are
    flat

    (e.g. `/v1/accounts`, `/v1/orders`, `/v1/products`). A small set of platform
    endpoints

    (migration, reconciliation, events, webhook endpoints, API keys) use the

    `/v1/entities/{entity_id}/...` form -- those are noted in their tags.


    **Key capabilities.**
      - Related-resource hydration via `?expand[]=` (see `x-arcus-expand` on each resource).
      - Cursor-based pagination (`starting_after` / `ending_before` / `limit`).
      - Idempotency via the `Idempotency-Key` header.
      - Webhook events for asynchronous notification.
      - Conditional requests / ETag for cache validation.

    **Changelog.** Entries are dated and name every published contract whose
    MEANING moved, not

    only the ones whose field names changed. The narrative version of the same
    entries, written

    for integrators, is published at https://arcuserp.mintlify.app/changelog.


    **2026-09-22 (planned 2026-09-21), REORDER-BUYER-TRUTH: demand changed what
    it MEANS on three

    published contracts, with no field renamed.** An integrator that pins field
    names sees no

    breakage and different numbers, which is why this entry exists.

      - **Demand now counts build consumption.** `demand_avg_per_day` on the public product, kit
        and inventory-balance objects, and `daily_demand` / `demand_basis` / `net_suggested_qty`
        on `GET /v1/purchasing/reorder-report`, are composed from fulfilled sales lines PLUS
        posted `build_consume` inventory draws: each physical decrement of a product counts
        exactly once. The previous rule adopted an internal-consumption basis only when the sales
        blend was exactly zero, so a product both sold AND consumed into work orders planned as
        if the build draws did not exist. Products drawn into work orders move; on one
        production-shaped dataset five did, the largest from 0.05/day to 14.95/day.
      - **`demand_basis` now carries four values, not two:** `sales`, `sales_and_builds`,
        `builds` and `consumption`. A consumer with a two-branch reader (anything that is not
        `consumption` is `sales`) silently hides the two new ones.
      - **`current_demand_units` on `GET /v1/inventory/balances/:id` moved, by a second rule.**
        It counts committed-but-unshipped CUSTOMER demand, and it now counts a kit component's
        own line rather than its parent kit line, and excludes non-sales documents. On one
        production dataset 269 of 1,043 balance rows changed, 227 of them downward; the largest
        single move was 1,941 to 25, on a product whose open PURCHASE order line had been
        reported as customer demand. Re-baseline anything that alerts or reorders off this field.
      - `run_rate_30/90/180/365` and `blended_daily` on the same balance object move for the
        first reason above.
      - **Added, not changed:** `GET /v1/purchasing/reorder-report` accepts `demand_window` and
        returns the unit, cover-through and reorder-point-provenance fields documented on that
        operation; `order_multiple` is accepted and returned on the product-vendor doors.
      - **Volume note.** The `inventory.low_stock`, `inventory.out_of_stock` and
        `inventory.back_in_stock` webhook events are population-gated on
        `on_hand <= reorder_point`, and reorder points move with the demand above, so
        subscribers should expect a one-time step change in event volume around the release.
servers:
  - url: https://api.arcuserp.com/v1
    description: Arcus ERP API (accepts both live `ark_live_*` and test `ark_test_*` keys)
  - url: https://dev-api.arcuserp.com/v1
    description: >-
      Dev sandbox API (test-only data, accepts `ark_test_*` keys against dev
      RDS)
security: []
paths:
  /integrations/{connector_type}:
    parameters:
      - name: connector_type
        in: path
        required: true
        description: >-
          Connector type. Enum: stripe, avatax, shippo, printnode, postmark,
          shopify, mapquest, google, openai, plaid, ups, fedex, usps, amazon,
          ebay, wwex
        schema:
          type: string
          enum:
            - stripe
            - avatax
            - shippo
            - printnode
            - postmark
            - shopify
            - mapquest
            - google
            - openai
            - plaid
            - ups
            - fedex
            - usps
            - amazon
            - ebay
            - wwex
    post:
      tags:
        - Integrations
      summary: Connect an integration
      description: >-
        Configures and activates a connector for the entity, validating
        provider-specific settings such as a Shopify store URL or an AvaTax
        company code before saving; for Shopify, the response returns an OAuth
        URL to complete instead of activating immediately. Credentials are
        stored only in AWS Secrets Manager, never in the database; use the
        update operation if the connector already exists.
      operationId: createIntegrationV1
      parameters:
        - $ref: '#/components/parameters/Idempotency'
      requestBody:
        required: false
        description: >
          Config-only body for Mode A connectors (most connectors).

          Body may NOT contain: credentials, secret, api_key, access_token,
          refresh_token,

          webhook_secret, credentials_secret_arn (422 returned if present).

          entity_id MUST NOT be in the body (derived from API key; 422 if
          present).


          Shopify (Mode B, OAuth): provide { shop: "mystore.myshopify.com",
          mode: "live" }.

          Response is 200 { object: "integration_oauth_required", oauth_url,
          expires_at }.

          Follow the oauth_url; poll GET /v1/integrations/shopify until
          is_active=true.


          7-day deletion-recovery: re-POST within 7 days of DELETE silently
          restores

          the prior credential blob from Secrets Manager (per
          project_shopify_expiring_tokens_contract).
        content:
          application/json:
            schema:
              type: object
              additionalProperties: false
              properties:
                mode:
                  type: string
                  enum:
                    - sandbox
                    - live
                display_name:
                  type: string
                config:
                  type: object
                  description: Provider-specific configuration JSON
                shop:
                  type: string
                  description: >-
                    Shopify only: merchant myshopify.com domain (e.g.
                    mystore.myshopify.com)
                ship_from_name:
                  type: string
                ship_from_address1:
                  type: string
                ship_from_city:
                  type: string
                ship_from_state:
                  type: string
                ship_from_zip:
                  type: string
                seller_id:
                  type: string
                  description: Amazon/eBay marketplace seller ID
                bank_account_id:
                  type: string
                  description: 'Plaid: bank account UUID to link'
      responses:
        '200':
          description: >
            Config-only (Mode A): created connector row.

            Shopify/OAuth (Mode B): { object: "integration_oauth_required",
            oauth_url, expires_at, hint }.
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/ConnectorRow'
                  - $ref: '#/components/schemas/IntegrationOAuthRequired'
        '400':
          $ref: '#/components/responses/Error'
        '401':
          $ref: '#/components/responses/Error'
        '403':
          $ref: '#/components/responses/Error'
        '422':
          description: 'forbidden_field: credentials or entity_id in request body'
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    example: forbidden_field
                  code:
                    type: string
                    example: forbidden_field
                  param:
                    type: string
                    description: The forbidden field name
                  hint:
                    type: string
      security:
        - ApiKeyAuth: []
components:
  parameters:
    Idempotency:
      name: Idempotency-Key
      in: header
      required: false
      description: >
        Client-generated unique key for idempotent POST/PATCH/DELETE operations.

        Max 255 chars. On retry with the same key, the original response is
        returned

        without re-executing the operation. Keys expire after 24 hours.

        Pattern: <random-uuid> or <client-prefix>-<operation>-<resource-id>.
      schema:
        type: string
        maxLength: 255
  schemas:
    ConnectorRow:
      type: object
      description: >
        A configured connector row from entity_connectors.

        SECURITY: credentials, webhook_secret, and credentials_secret_arn RAW
        VALUES

        are NEVER returned. has_credentials_secret_arn (boolean) indicates if

        credentials are stored. credentials_masked returns key names only (no
        values).

        These invariants are enforced by the canonical
        listConnectors/getConnectorByType

        handler projection and cannot be overridden by callers.
      properties:
        id:
          type: string
          format: uuid
        entity_id:
          type: string
          format: uuid
        connector_type:
          type: string
          enum:
            - stripe
            - avatax
            - shippo
            - printnode
            - postmark
            - shopify
            - mapquest
            - google
            - openai
            - plaid
            - ups
            - fedex
            - usps
            - amazon
            - ebay
            - wwex
        display_name:
          type: string
        mode:
          type: string
          enum:
            - sandbox
            - live
        is_active:
          type: boolean
        config:
          type: object
          description: Provider-specific configuration (opaque JSON)
        has_webhook_secret:
          type: boolean
          description: >-
            True if a webhook signing secret is configured (value never
            returned)
        has_credentials_secret_arn:
          type: boolean
          description: >-
            True if credentials are stored in AWS Secrets Manager (ARN never
            returned)
        last_sync_at:
          type: string
          format: date-time
          nullable: true
        sync_status:
          type: string
          nullable: true
        sync_error:
          type: string
          nullable: true
        ship_from_name:
          type: string
          nullable: true
        ship_from_address1:
          type: string
          nullable: true
        ship_from_city:
          type: string
          nullable: true
        ship_from_state:
          type: string
          nullable: true
        ship_from_zip:
          type: string
          nullable: true
        seller_id:
          type: string
          nullable: true
        bank_account_id:
          type: string
          format: uuid
          nullable: true
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    IntegrationOAuthRequired:
      type: object
      description: >
        Returned by POST /v1/integrations/{connector_type} when the connector

        requires OAuth (e.g. Shopify). The caller must redirect the user's
        browser

        to oauth_url to complete the connection. Poll GET /v1/integrations/:type

        until is_active=true after the user completes the OAuth flow.

        7-day deletion-recovery: if re-connecting within 7 days of a DELETE,

        the prior credential blob is restored from Secrets Manager
        automatically.
      required:
        - object
        - connector_type
        - oauth_url
        - expires_at
      properties:
        object:
          type: string
          enum:
            - integration_oauth_required
        connector_type:
          type: string
        oauth_url:
          type: string
          format: uri
          description: OAuth consent URL. Redirect the user's browser here.
        expires_at:
          type: string
          format: date-time
          description: When the OAuth state token expires (10 minutes from now)
        hint:
          type: string
          description: Human-readable instructions for the caller
    ErrorEnvelope:
      type: object
      description: |
        Canonical error response envelope. All API errors use this shape.
      required:
        - error
        - code
      properties:
        error:
          type: string
          description: Machine-readable error key
          example: not_found
        code:
          type: string
          description: Machine-readable error code (often same as error)
          example: not_found
        type:
          type: string
          enum:
            - validation_error
            - permission_error
            - not_found
            - conflict
            - rate_limit
            - internal
            - expand_error
            - not_implemented
          example: not_found
        hint:
          type: string
          description: Human-readable one-sentence explanation (English)
          example: >-
            The requested order does not exist or does not belong to this
            entity.
        param:
          type: string
          description: The parameter that caused the error, if applicable
          example: expand[0]
        required:
          type: string
          description: The scope required (only on insufficient_scope errors)
          example: accounts:read
        request_id:
          type: string
          description: >-
            Unique request ID for support tracing (maps to CloudWatch log
            stream)
          example: req_abc123
  responses:
    Error:
      description: Error response (400/401/403/404/409/422/429/500)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      description: |
        API key issued per entity via Settings > Developers > API Keys.
        Each key carries scopes (e.g. orders:read, products:write).
        Bearer token format: Authorization: Bearer ark_live_ent_<code>_<random>
        Test keys use ark_test_ent_<code>_<random>. Both are issued per entity
        via Settings > Developers > API Keys.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.