Custom API integrations: define a safe contract
An API connection is an operating agreement between systems. It should say which system owns a record, what event sends it, who may read or change it and how disagreement is resolved. Datrylo's Manager and Odoo runtime have separate trust boundaries; customer-private data and privileged tenant credentials must not be stored in the public WordPress site.
What is available for this connection
| Current status | Custom integration |
|---|---|
| Operation | One agreed business event and its receiving record |
| Implementation | Define the sender, external record ID, recipient and allowed action. If the same confirmed order arrives twice, create one receiving record; if its quantity changes, route the conflict to the named owner. A general API is not a released connector for every system. |
Design the first transaction
Choose one event, such as a confirmed order. Define the payload, stable external ID, validation rules and expected response. Include duplicate delivery, delay, timeout and an invalid field. Decide whether the receiving system retries, rejects or places the event in a review queue. A successful HTTP response alone does not prove the business record was correct.
Keep authority on the server
Authenticate every call, scope credentials to the minimum resource and rotate them. Make writes idempotent. Preserve an audit trail without logging secrets or full sensitive payloads. If the integration changes prices, subscriptions or eligibility, the Datrylo backend must recalculate and authorise the result.
Prove the lifecycle
Define the sender, external record ID, recipient and allowed action. If the same confirmed order arrives twice, create one receiving record; if its quantity changes, route the conflict to the named owner. A general API is not a released connector for every system.
Ready for your
next big move?
See what a more connected business could look like. Start with a conversation about yours.