Call preparation: address, identity, and data formats
API integration does not require a source development environment. Use a backend capable of HTTPS, secret storage, JSON, streaming responses, and WebSocket when needed.
flowchart LR
A[Pin server version] --> B[Save matching OpenAPI]
B --> C[Create least-privilege API Token]
C --> D[Call health and read-only APIs first]
D --> E[Then integrate async workflows]
1. Pin the deployed version
Record the deployed version and keep its matching OpenAPI and Postman assets. Paths, fields, and enums evolve; never call an older service with a newer website contract.
2. Confirm the base address
For https://vms.example.com, business APIs start at https://vms.example.com/api/v2/, while secure RTC APIs may use /api/v2/rtc/session/. Reverse proxies must preserve HTTPS, WebSocket upgrades, request-size limits, Range, and real client address semantics.
3. Choose the correct identity
| Situation | Identity to use |
|---|---|
| A person operates the administration UI | Interactive sign-in session |
| A backend service calls APIs continuously | Dedicated least-privilege API token |
| A browser joins an RTC meeting | One-time invitation and short-lived device token |
| Node, Agent, or internal callback | Trusted product identity; third parties do not use it |
Create a separate token for each application. Record its purpose, owner, expiration, and allowed IP range. Do not share an administrator token across teams.
4. Apply consistent request rules
- Send UTF-8 JSON and timezone-aware ISO 8601 timestamps.
- Missing fields, empty strings, and
nullhave different meanings. - Follow declared paging defaults and never assume one call returns all records.
- Ignore newly added response fields and provide a fallback for unknown enum values.
- For non-2xx responses, keep the raw body, Content-Type, HTTP status, and TraceId.
5. Run the minimum connectivity check
Call these in order:
/healthto confirm the network and process./api/v2/system/versionto confirm the deployed contract version./api/v2/auth/meto confirm the caller, roles, and permissions.- One read-only business API to confirm access to the intended domain.
Stop and correct the URL, certificate, proxy, or permission at the first failing step. Do not proceed directly to device controls or recording jobs.