Naar hoofdinhoud

Frontlink developer documentation

The Frontlink product API for developers and AI agents: API tokens, request scopes, error format, rate limits and reading the site as Markdown.

Start here

Frontlink provides a REST API. The authenticated production and warehouse API is at https://api.frontlink.nl/api/v1; the website itself has no public write API. Follow the product API reference for available operations. Frontlink does not publish a public GraphQL endpoint or a public MCP connection URL here; do not attempt GraphQL introspection or infer MCP URLs from product marketing.

Product API authentication

Use a revocable API token issued to a tenant-owned service account: Authorization: Bearer <api-token>. Role Templates grant the account its permissions. ERP and WMS operations require the authorized Exact Online division in X-Erp-Division-Scope. Side-effecting POST operations require an Idempotency-Key; reuse that key only for retries of the same request. Never embed production tokens in browser code or documentation. The product reference currently has generic response envelopes and incomplete operation input schemas; consult the operation documentation before generating production tools.

curl https://api.frontlink.nl/api/v1/warehouses \
  -H 'Authorization: Bearer <api-token>' \
  -H 'X-Erp-Division-Scope: <division-code>'

JSON errors and recovery

The product API normally returns errors as an error object with code, message and requestId; the general rate limiter retains its legacy string error and adds top-level code, message, hint and retryAfter. Include the request ID when contacting support. Fix invalid input before retrying, obtain valid credentials for 401, and the required permission and division access for 403. On the website, an unknown /api URL returns JSON 404 with code, message and hint.

Rate limits

The product API's general Redis-backed limiter allows 1000 requests per 60 seconds per IP in production. Responses that pass through that limiter expose RateLimit-Policy: "general";q=1000;w=60 and RateLimit: "general";r=<remaining>;t=<seconds>. On 429, wait at least the Retry-After delay in seconds. These fields follow draft-ietf-httpapi-ratelimit-headers-11, an IETF working draft, not a published RFC. Health, authentication, admin and WebSocket routes bypass this general limiter; development or unavailable Redis does not advertise a quota. Missing rate headers do not imply unlimited capacity. Use bounded retries with jitter.

Read the website as Markdown

Send Accept: text/markdown to a marketing page, including /en, /nl and /de pages. HTML remains available at the same URL. Negotiation honors quality weights and returns 406 when neither representation is acceptable. Markdown responses vary on Accept and Accept-Encoding. Negotiated responses are not stored in shared caches; Next.js manages the HTML Vary fields. Missing pages return HTTP 404; the Markdown response links to the sitemap, agent index and docs. Use the sitemap for localized canonical URLs and llms.txt for a compact resource index.

curl -i -H 'Accept: text/markdown' https://frontlink.nl/en/docs

hello@frontlink.nl · Frontlink · Contact · Privacy · API & docs · Frontlink product API reference · Product OpenAPI · llms.txt · Sitemap