Skip to content
NEXBRAND

For developers · Chapter 24

API

Build scripts, tools and programs such as nexdeck or n8n can read a CI with a token: as JSON or as code, for any version and any day. Reading changes nothing.

Switching it on and creating a token

API tokens are off out of the box. The operator switches them on under Settings, Server, API with Accounts may create API tokens. Then every account creates its own, under My account, Connections, New token:

FieldValues
Name, so you know it againfree text, such as “Website build”
ClientsOnly these or Every client I may see, later ones too
Expiresin 30 days, in 90 days (default), in a year or never
What the token may doRead only or Read and propose drafts

Create shows the token exactly once, starting with nxb_; nexbrand keeps only a checksum. Below stand a line for the header in nexdeck or n8n and a curl call to try it. An account holds at most 20 tokens. The list shows when each was last used and when it expires, marked a week before.

My account
My account, tab Connections with two API tokens, their clients, level and expiry date
Two tokens under Connections.

What a token may do

A token reads what its account may read, limited to its clients. If somebody takes a right away from the account, that counts for the token at once. If the account is blocked or deleted, no token works any more. No token hands out in-house fonts as files.

The addresses

Every request carries Authorization: Bearer nxb_…. You name a client by its id or its name, a version by id or a name such as 2026.

AddressDelivers
GET /api/v1/mewhom the token speaks for
GET /api/v1/clientsthe clients it may read
GET /api/v1/clients/{client}the CI with files and checks; with ?version=, ?at= or ?project=
GET …/versionsevery version
GET …/code?format=css, tailwind, scss or json
POST …/auditcolours and CSS against the CI
POST …/draftswrites a draft back
GET /api/v1/contrastthe contrast of two colours
GET /api/v1/files/{id}a logo, a free font or an example

A token of the level Read and propose drafts writes a version back as a draft, such as a redesign from the code, where its account may write. It can never publish, and it creates no drafts for projects. What is under /api/v1 stays: new fields may come, nothing is renamed or taken away.

Safeguards

nexbrand refuses a request with an Origin header, that is one from a web page; the API is for programs. Each token may make 600 requests a minute. The operator sees every token in a list, never the token itself, and can block it for good.

Pavo saysGive a build script a token that only reads and sees only the one client. If it ever shows up somewhere, delete it and create a new one.