.png)
inriver Integration Guide
Integrate inriver PIM with enterprise systems through REST APIs, selected webhook-style notifications, scheduled workflows, and controlled data synchronization.
inriver integration options at a glance
inriver’s primary integration mechanism is its REST API, which can be used to retrieve and update entities, fields, links, controlled vocabulary values, and channel-related configuration where exposed by the applicable tenant and API version. inriver also supports webhook-style notifications for selected events, although coverage and delivery behavior should be verified for each environment. API-key authentication is the confirmed primary security pattern. Martini can consume these APIs, receive selected notifications, orchestrate scheduled catalog synchronization, map localized and structured product data, apply validation and business rules, and expose controlled REST endpoints for downstream applications. Large catalogs can be processed with pagination, checkpoints, throttling, and retry handling.
Common inriver integration patterns
Common inriver data objects used in integrations
Authentication and security considerations
API-key authentication
API-key authentication is the primary confirmed authentication pattern for the inriver REST API. The exact header name, API base URL, and permission model should be verified for the target tenant.
- Store API keys in Martini secrets management rather than workflow definitions.
- Use separate credentials for development, testing, and production where supported.
- Restrict key permissions to the operations required by the integration.
- Rotate keys according to organizational policy and prevent credentials from appearing in logs or error payloads.
Webhook security
For selected inriver notifications, validate the incoming request and record event identifiers for replay protection. Retrieve authoritative resource state through the REST API before distributing changes.
Operational considerations for inriver integrations
Tenant-specific schemas
Entity types, Field names, Link types, Channels, Controlled Vocabulary Lists, permissions, and API behavior can vary between inriver tenants. Externalize configuration and avoid hard-coding assumptions into reusable workflows.
Pagination and rate limits
Large catalogs should be processed page by page with checkpoints, controlled concurrency, throttling, and appropriate backoff for rate-limit or temporary server responses.
Idempotency and ordering
Use stable inriver identifiers or agreed external identifiers for upserts. Webhook notifications may be duplicated or arrive out of order, so retrieve current state and make processing replay-safe.
Data quality and dependencies
Validate localized and structured Fields, Links, Channels, and CVL values before writes. Distinguish null from empty values and resolve dependencies in a defined order.
Testing and observability
Test representative entity types, locales, relationships, permissions, and failure responses in a non-production environment. Monitor request outcomes, checkpoints, retry counts, source identifiers, and downstream responses without logging credentials.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration beyond point-to-point scripts
Martini provides a maintainable workflow layer for coordinating inriver API calls, webhook intake, validation, transformation, target delivery, and operational handling. This avoids duplicating synchronization logic across individual scripts and applications.
Reusable integration assets
Teams can separate tenant configuration, mappings, validation, and business rules from workflow orchestration. Martini can also expose controlled REST APIs that provide an application-specific façade over inriver.
Operational control
- Use schedules, event-driven workflows, pagination, checkpoints, and controlled retries.
- Apply consistent mapping, localization, vocabulary, channel, and ownership rules.
- Centralize secrets and distinguish retryable failures from data-quality or authorization errors.
- Monitor workflow outcomes and support replay without creating duplicate target updates.