For developers · Chapter 24
API
Build scripts, tools and programs such as nexdeck or n8n can read a CI with a token: as JSON or as code, for any version and any day. Reading changes nothing.
Switching it on and creating a token
API tokens are off out of the box. The operator switches them on under Settings, Server, API with Accounts may create API tokens. Then every account creates its own, under My account, Connections, New token:
| Field | Values |
|---|---|
| Name, so you know it again | free text, such as “Website build” |
| Clients | Only these or Every client I may see, later ones too |
| Expires | in 30 days, in 90 days (default), in a year or never |
| What the token may do | Read only or Read and propose drafts |
Create shows the token exactly once, starting with nxb_; nexbrand keeps only a checksum. Below stand a line for the header in nexdeck or n8n and a curl call to try it. An account holds at most 20 tokens. The list shows when each was last used and when it expires, marked a week before.
What a token may do
A token reads what its account may read, limited to its clients. If somebody takes a right away from the account, that counts for the token at once. If the account is blocked or deleted, no token works any more. No token hands out in-house fonts as files.
The addresses
Every request carries Authorization: Bearer nxb_…. You name a client by its id or its name, a version by id or a name such as 2026.
| Address | Delivers |
|---|---|
GET /api/v1/me | whom the token speaks for |
GET /api/v1/clients | the clients it may read |
GET /api/v1/clients/{client} | the CI with files and checks; with ?version=, ?at= or ?project= |
GET …/versions | every version |
GET …/code?format= | css, tailwind, scss or json |
POST …/audit | colours and CSS against the CI |
POST …/drafts | writes a draft back |
GET /api/v1/contrast | the contrast of two colours |
GET /api/v1/files/{id} | a logo, a free font or an example |
A token of the level Read and propose drafts writes a version back as a draft, such as a redesign from the code, where its account may write. It can never publish, and it creates no drafts for projects. What is under /api/v1 stays: new fields may come, nothing is renamed or taken away.
Safeguards
nexbrand refuses a request with an Origin header, that is one from a web page; the API is for programs. Each token may make 600 requests a minute. The operator sees every token in a list, never the token itself, and can block it for good.
Pavo saysGive a build script a token that only reads and sees only the one client. If it ever shows up somewhere, delete it and create a new one.