.png)
Mendix Integration Guide
Integrate Mendix Platform APIs and application-specific REST, SOAP, OData, and callback interfaces with enterprise workflows and systems.
Mendix integration options at a glance
Mendix supports Platform and Developer Portal REST APIs, as well as REST, SOAP, and OData services published by individual applications. A Mendix application can also consume external services and implement selected callback or webhook-style behaviors, although event coverage and payload contracts are application-specific. Platform deployment operations may be asynchronous and require status polling. Martini can consume these APIs, authenticate with OAuth 2.0 or application-configured methods, transform JSON and XML, orchestrate scheduled or event-driven workflows, and expose REST APIs for Mendix applications to call. File-document exchanges are possible through application-specific endpoints, while direct database access is not the default integration boundary.
Common Mendix integration patterns
Common Mendix data objects used in integrations
Authentication and security considerations
Interface-specific authentication
Mendix Platform APIs use OAuth 2.0-based authorization patterns with permissions scoped to organizations, projects, applications, and environments. A deployed Mendix application may instead use Basic Authentication, tokens, OAuth 2.0, Mendix users and roles, or custom authentication logic.
Least privilege and secrets
- Obtain the application API contract and security configuration before implementation.
- Use separate credentials for development, test, and production.
- Store client secrets, access tokens, and certificates in Martini secrets management.
- Apply entity access rules and service-account permissions appropriate to the data being exchanged.
Inbound protection
When Mendix calls a Martini API, validate authentication, authorization, request structure, event identifiers, and any agreed signature or replay controls. Avoid credentials in query parameters and validate TLS certificates.
Operational considerations for Mendix integrations
Pagination and incremental synchronization
Confirm pagination, continuation, sorting, and filtering for every REST or OData service. Do not assume that custom Mendix REST services follow OData conventions. Use a reliable timestamp, sequence, status marker, or application-provided change mechanism for incremental synchronization.
Asynchronous operations
Deployment requests may return before completion. Persist the external operation identifier, poll with bounded retries and backoff, and distinguish submitted, completed, failed, and canceled states.
Reliability and idempotency
- Use event identifiers, business keys, or request fingerprints to prevent duplicate processing.
- Apply controlled concurrency and exponential backoff for throttling and transient server errors.
- Separate transport failures from validation and terminal business failures.
- Record Mendix request identifiers, operation identifiers, checkpoints, and target identifiers.
Schema and document changes
Mendix domain models and generated API schemas are application-specific and can change with deployments. Test against each target environment, validate required fields and enumerations, and agree on versioning. For FileDocument exchanges, define file size, MIME type, naming, retention, authorization, and retry rules.
Why use Martini instead of scripts or point-to-point integrations?
Reusable orchestration
Martini provides a maintainable workflow layer for Mendix API calls, callbacks, deployment polling, downstream writes, and operational notifications instead of scattering logic across scripts or point-to-point mappings.
Controlled transformation
Because Mendix business objects are application-specific, Martini can centralize mappings from published REST, OData, SOAP, or file contracts into canonical and target-system models. Validation and business rules remain visible and reusable.
Operational reliability
- Use secure environment configuration and secrets management.
- Apply retries, backoff, idempotency, and asynchronous status handling consistently.
- Expose controlled APIs for Mendix callbacks and enterprise consumers.
- Preserve logs, correlation identifiers, checkpoints, and failure context for support and audit.