.png)
Storyblok Integration Guide
Integrate Storyblok content with enterprise applications through REST and GraphQL APIs, asset management endpoints, and selected webhook notifications.
Storyblok integration options at a glance
Storyblok provides REST APIs for content delivery and management, a GraphQL Content Delivery API for tailored queries, asset upload and management operations, and configurable webhooks for selected content and space events. Content Delivery API requests use space access tokens, while Management API integrations can use personal access tokens or OAuth 2.0. Martini can consume these APIs, expose a REST endpoint for Storyblok webhook calls, and orchestrate scheduled reconciliation when notifications are incomplete. Workflows can map nested Stories and Components, handle Assets separately, apply publication-state rules, and synchronize normalized content with downstream applications.
Common Storyblok integration patterns
Common Storyblok data objects used in integrations
Authentication and security considerations
Credential types
Storyblok Content Delivery and GraphQL requests use space access tokens. Management API integrations can use personal access tokens or OAuth 2.0, with access governed by user, organization, and space permissions.
Secret handling
Store Storyblok tokens, OAuth credentials, and webhook verification values in Martini secrets or environment-specific configuration rather than workflow payloads, mappings, or source code.
Webhook protection
Validate the authentication, secret, custom header, signature, or other mechanism configured for the Storyblok webhook. Keep webhook processing scoped to the expected space and event types.
Environment separation
Use separate credentials and explicit API modes for draft, preview, and published content so preview data is not accidentally synchronized to production systems.
Operational considerations for Storyblok integrations
Pagination and checkpoints
Use the pagination and filtering parameters documented for each Storyblok API. Do not assume Content Delivery API and Management API pagination behave identically. Store checkpoints based on supported modification or publication fields where available.
Rate limits and retries
Confirm applicable limits for the Storyblok plan and endpoint. Use controlled concurrency, retry backoff, and classification of transient versus permanent failures.
Webhooks and idempotency
Webhook notifications may be retried or delivered more than once. Use the Story identifier, event type, version or update timestamp, and a stored processing key to prevent duplicate downstream updates.
Nested content and schemas
Stories can contain nested Components and blocks. Mappings should tolerate optional fields and unknown properties while monitoring for new component types and schema changes.
Asset processing
Handle asset uploads separately from Story updates. Consider file size, MIME type, duplicate uploads, returned identifiers, and association of the resulting URL with the correct Story.
Testing and reconciliation
Test draft and published paths, webhook failures, pagination, rate limiting, schema changes, and partial target outages. Use scheduled reconciliation to detect changes missed while a receiver or downstream system was unavailable.
Why use Martini instead of scripts or point-to-point integrations?
Reusable orchestration
Martini coordinates Storyblok API calls, webhook receipt, asset processing, downstream writes, validation, and reconciliation in maintainable workflows rather than embedding all behavior in a single script.
Flexible integration models
Teams can combine REST, GraphQL, webhook, scheduled, file, and database-facing integration steps where required. Martini can also expose controlled APIs for normalized content or integration operations.
Consistent transformation
Mappings and business rules provide a repeatable way to convert nested Storyblok Stories and Components into commerce, search, mobile, portal, or migration models.
Operational control
Centralized error handling, retries, checkpoints, logging, environment configuration, and secret management make integrations easier to monitor and evolve than isolated point-to-point scripts.