Buki
Business API access
Build approved business connections with scoped access to the supported API.
Start with a defined use case
Decide which business workflow needs a connection before creating credentials. API access is subject to the account’s entitlement and permissions.
Keep credentials on your server
Do not publish API secrets in browser code, mobile bundles or shared documents. Use the minimum permissions required by the integration.
Handle failures explicitly
Plan for expired credentials, rejected requests and unavailable services. A failed API request must not be shown as a successful booking or payment.
Frequently asked questions
Can I access another business’s records?
No. Access is scoped to the permissions and organisation attached to the credentials.

