Authentication and security
All requests to the Nexus MFT API require authentication. The API uses Bearer token authentication to verify your identity and authorize access to resources.
Authenticate your requests
Include your API key in the Authorization header of every request.
Authorization: Bearer YOUR_API_KEY
Generate an API key
To generate a new API key:
- Sign in to the Nexus MFT Admin Console.
- Go to Settings > API Keys.
- Select Create API Key.
- Enter a descriptive name for the key, for example "Production - Transfer Service".
- Select the permissions you want to assign to the key.
- Select Generate.
Important
Copy and store your API key immediately after you generate it. For security reasons, the full key is shown only once. If you lose it, you must generate a new key.
API key permissions
You can scope each API key to specific permissions. Assign only the permissions that your integration requires.
| Permission | Scope | Description |
|---|---|---|
transfers:read |
Read | List and view transfer details. |
transfers:write |
Write | Create and cancel transfers. |
webhooks:manage |
Admin | Create, update and delete webhook subscriptions. |
endpoints:manage |
Admin | Configure source and destination endpoints. |
audit:read |
Read | View audit logs and transfer history. |
Rotate your API keys
To maintain security, rotate your API keys regularly. When you rotate a key, the old key remains active for 24 hours so you have time to update your integrations.
To rotate an API key:
- Go to Settings > API Keys in the Admin Console.
- Find the key you want to rotate and select Rotate.
- Copy the new key and update your integration.
- Verify that your integration works with the new key.
The old key is revoked automatically after 24 hours.
Security best practices
- Never expose API keys in client-side code or public repositories.
- Use environment variables or a secrets manager to store your keys.
- Assign the minimum permissions required for each integration.
- Monitor the audit log for unexpected API activity.
- Rotate keys every 90 days, or immediately if you suspect a compromise.
IP allowlisting
For additional security, you can restrict API access to specific IP addresses. When you turn on IP allowlisting, the API rejects requests from IP addresses that aren't on your list.
{
"allowed_ips": [
"203.0.113.10",
"198.51.100.0/24"
],
"enforce": true
}
To configure IP allowlisting, go to Settings > Security > IP Allowlist in the Admin Console.