Skip to main content

API keys

An API key connects your own system, or the system of an agency or technology partner you work with, to Nasam through the Nasam developer API (MM-API), so it can read and act on your orders, stock and sales from there.

What a key is​

A key acts with your access: the brands you can reach and the permissions your account holds. Nasam reads your permissions on every request, so when your access changes, the key's access changes with it. If your account is deactivated or leaves the organization, its keys stop working.

Who creates keys​

Every user on a brand account creates their own keys and sees only their own. Each user can hold up to two active keys.

Create a key​

  1. In the app's sidebar, under Connections, open API keys.
  2. Click Create key.
  3. Name the key after the system that will use it, such as "ERP sync", so you can tell it apart when you revoke it.
  4. Click Create key.

Copy the key​

The full key is shown once, right after you create it.

  1. Click Copy key.
  2. Store it somewhere safe, such as your system's secrets manager, or hand it to the developer building the integration.
  3. Tick "I've copied the key and stored it safely", then click Done.

From then on the page shows only the first characters of the key, with the date it was created and when it was last used. If you lose it, revoke it and create another.

Rotate a key​

With two active keys you can swap a key while the integration keeps running:

  1. Create the new key and copy it.
  2. Put it in your system in place of the old one, and check the integration works.
  3. Revoke the old key.

If you already hold two active keys, revoke one first, then create its replacement.

Revoke a key​

  1. On the API keys page, click Revoke next to the key.
  2. Check when it was last used in the confirmation, then click Revoke key.

Every system using the key stops immediately. A revoked key stays on the list with the status Revoked for your records, and revoking is final. To reconnect, create a new key.

What a partner can do with your key​

A partner holding your key acts with your access:

  • It reads what you can read in Nasam: products and listings, orders, inventory, sales, profitability and settlements, purchase orders, brand health and sync status.
  • It takes the actions your permissions allow, such as order fulfillment actions and price and quantity updates.
  • It receives instant notifications (webhooks) when an order, return, purchase order or brand's health changes.

Its reach is your reach: only the brands you can access, and only the permissions your account holds. Creating and revoking keys stays with you, in the app.

Give each system or partner its own key, so you can revoke one while the other keeps working.

For developers​

The developer guide, the API reference and a sandbox with demo data are at developer.nasam.co. Share the link with whoever builds the integration.

Your next step​

Need a hand?

The Nasam team is with you, whatever the question: WhatsApp +966 55 009 0039 or general@nasam.co. And we set up your marketplace accounts with you, step by step. The consultation is free.