.png)
Zip Integration Guide
Connect Zip procurement workflows with enterprise applications through REST APIs, selected webhook events, scheduled synchronization, and secure API-key authentication.
Zip integration options at a glance
Zip’s primary integration mechanism is its REST API, which supports access to procurement Requests, Approvals, Purchase Orders, Vendors, Invoices, and Users. Zip also supports webhook-style notifications for selected objects or lifecycle events, although coverage must be confirmed for each tenant and use case. API-key authentication is documented for programmatic access. Where webhooks are unavailable, Martini can run scheduled workflows that retrieve paginated data, maintain synchronization checkpoints, apply validation and business rules, and map Zip payloads to ERP, HR, finance, identity, or collaboration applications. Bulk, general-purpose attachment, GraphQL, SOAP, and direct database interfaces were not confirmed.
Common Zip integration patterns
Common Zip data objects used in integrations
Authentication and security considerations
API-key authentication
Zip documents API-key-based authentication for programmatic access, generally using a bearer token or API key in the HTTP authorization headers. Confirm the exact header format, permissions, and key lifecycle for the target tenant.
Credential protection
Store Zip credentials in Martini Secrets Management rather than embedding them in workflows, mappings, scripts, or source control. Use environment-specific credentials and rotate them according to organizational policy.
Least privilege
Use a dedicated integration identity with only the access required for the Zip objects and actions involved. Procurement data may be subject to approval, supplier, accounting, and organizational access controls.
OAuth considerations
OAuth 2.0 may apply to some Zip-managed application or partner authorization flows, but a general-purpose OAuth flow for all Zip API resources was not verified. Do not assume OAuth is available for direct API access.
Operational considerations for Zip integrations
Rate limits and pagination
Confirm Zip request limits, page-size constraints, cursor behavior, and ordering guarantees. Use bounded concurrency, exponential backoff for transient responses, and durable checkpoints for scheduled synchronization.
Idempotency and ordering
Use stable external identifiers for Requests, Vendors, Purchase Orders, and Invoices. Treat webhook delivery as potentially duplicated or out of order, and reconcile a timed-out create request before issuing another create operation.
Approval and schema changes
Model approval state separately from downstream processing state. Zip fields and status values can depend on tenant configuration, custom forms, accounting dimensions, approval rules, and enabled modules, so test configuration changes before production rollout.
Webhook reliability
Validate webhook authenticity using the tenant’s documented mechanism, acknowledge promptly, process asynchronously where appropriate, and retain periodic reconciliation because event coverage and delivery may be limited.
Observability
Log correlation IDs, Zip object IDs, source identifiers, endpoint names, HTTP status codes, and retry counts without exposing API keys or sensitive procurement data. Monitor both transport failures and business exceptions.
Why use Martini instead of scripts or point-to-point integrations?
Reusable orchestration
Martini centralizes Zip API calls, webhook intake, scheduled polling, validation, mapping, target updates, and exception handling in maintainable workflows rather than scattering logic across scripts.
Adaptable integration logic
Zip procurement fields and approval structures can vary by tenant. Martini lets developers apply explicit mappings, transformations, and business rules while retaining the option to extend workflows with custom JVM-compatible logic when necessary.
Reliable synchronization
Checkpointing, pagination, idempotency, bounded retries, and reconciliation workflows provide stronger operational controls than a one-off point-to-point script.
Controlled APIs
Martini can expose an internal API façade that gives downstream applications a stable contract while isolating Zip-specific authentication, object models, lifecycle rules, and API changes.