ERP API Integration Explained: REST, Webhooks, Auth and Idempotency
A plain-English explanation of ERP API integration: REST APIs, webhooks, authentication methods, idempotency, pagination, rate limits and error handling.
“API integration” gets used loosely. This article explains the concepts that matter when connecting an ERP to other systems, without assuming a developer background.
APIs: asking for data
An API (application programming interface) lets one system request data or actions from another. Most modern systems offer REST APIs: you send an HTTP request (GET to read, POST to create, PUT/PATCH to update) and receive structured data, usually JSON.
Older systems may use SOAP or XML-RPC; many ERPs also offer JSON-RPC. The principles are the same.
Webhooks: being told
Polling an API every minute to check for new orders is wasteful. Webhooks reverse the direction: the other system sends an HTTP request to your endpoint when an event happens — an order is placed, a payment succeeds.
Webhooks reduce latency and load, but your endpoint must be reliable, secure and quick to respond. The usual pattern is to verify, store and acknowledge immediately, then process asynchronously.
Authentication
How systems prove who they are:
- API keys — a secret token sent with each request. Simple; must be protected.
- OAuth 2.0 — tokens issued through an authorisation flow, often with refresh tokens. Common for SaaS platforms.
- HMAC signatures — requests signed with a shared secret so the receiver can verify authenticity and integrity.
- Mutual TLS — both sides present certificates. Used in high-security contexts.
Always use dedicated credentials for integrations with the minimum permissions required.
Idempotency
Networks are unreliable. A request may succeed but the response gets lost, so the sender retries. Without protection, you get duplicate orders or double payments.
Idempotency keys solve this: each request carries a unique key, and the receiver ignores repeats. If the API doesn't support keys, store the external ID and check before creating.
Pagination and incremental sync
APIs return large datasets in pages. Integrations should page through results and, for ongoing sync, request only records changed since the last run (using timestamps or change tokens).
Rate limits
APIs limit how many requests you can make per period. Exceeding limits returns errors (often HTTP 429). Good integrations batch requests, respect “retry-after” headers and spread load.
Error handling
Distinguish two kinds of error:
- Retryable — timeouts, rate limits, temporary server errors. Retry with exponential backoff.
- Permanent — validation errors, missing records, permission denied. Don't retry; send to an exception queue for a person to fix.
Versioning
APIs change. Pin to a version where possible, monitor deprecation notices and test integrations when either system upgrades.
Putting it together
A reliable ERP integration typically: receives webhooks, verifies signatures, queues events, processes them idempotently, calls the ERP API with dedicated credentials, retries transient failures, parks permanent failures, logs everything and alerts an owner.
For architecture and data ownership, read the ERP integration guide. For delivery, see ERP API integration.
Frequently asked questions
What is the difference between an API and a webhook?
With an API, your system asks for data. With a webhook, the other system tells you when something happens.
What is idempotency?
It means repeating the same request has the same effect as making it once — essential for safe retries.
ERP Builders Architecture Group
The engineers responsible for integration design, data migration tooling and performance work across ERP Builders projects.
Related articles
ERP Integration Guide: Patterns, Data Ownership and Reliability
How to integrate an ERP with eCommerce, CRM, payments and other systems: data ownership, integration patterns, middleware, error handling, monitoring and common failure modes.
RFID Integration with Odoo: A Practical Architecture
How to integrate RFID readers with Odoo inventory: middleware design, mapping EPCs to products and serials, receiving and counting flows, performance and what to build vs buy.
Odoo eCommerce vs Shopify + Odoo: Which Setup Fits?
Should you run your online store on Odoo eCommerce or keep Shopify or WooCommerce and integrate with Odoo? A practical comparison of features, SEO, costs and operations.
Next step
Turn the plan into a working system.
Book a consultation with an ERP consultant. No sales script — just an honest look at your situation.