# API integrations

Expose, call and orchestrate APIs across business and technical systems from Python services.

## Get started

Build your first REST API in Python and call external APIs from it, with no restarts.

[REST tutorial](https://zato.io/tutorials/rest-api/python.html)

```yaml
name: REST channel
actors:
  - id: client
    label: API client
  - id: channel
    label: REST channel
  - id: service
    label: Your service
  - id: backend
    label: Backend system
steps:
  - from: client
    to: channel
    label: A client calls your endpoint
    align: left
    items:
      - The channel authenticates the caller first
      - JSON maps to typed Python objects
  - from: channel
    to: service
    label: The channel invokes your service
  - from: service
    to: backend
    label: The service calls the backend
  - from: backend
    to: service
    kind: return
    label: The backend replies
  - from: service
    to: client
    kind: return
    label: The client receives the response
    align: left
    items:
      - The response is JSON again
      - Every exchange can be audited
```

```yaml
name: Orchestration
actors:
  - id: service
    label: Your service
  - id: crm
    label: CRM
  - id: erp
    label: ERP
  - id: queue
    label: Message queue
steps:
  - from: service
    to: crm
    label: The service reads the customer
    align: left
    items:
      - One service calls many systems
      - Each connection is configuration
  - from: crm
    to: service
    kind: return
    label: The CRM returns the record
  - from: service
    to: erp
    label: The service updates the order
  - from: erp
    to: service
    kind: return
    label: The ERP confirms
  - from: service
    to: queue
    label: The service publishes the outcome
    align: left
    items:
      - Subscribers receive it from the topic
      - The caller receives one combined reply
```

## Expose and call REST APIs

[REST overview Expose services as REST endpoints and call external APIs, all from Python.](https://zato.io/docs/dev/rest/index.html) [Channels Expose a service as a REST endpoint - the channel authenticates each caller and maps JSON to Python objects.](https://zato.io/docs/dev/rest/channels.html) [Outgoing connections Call external REST APIs through named connections - pooling and TLS included.](https://zato.io/docs/dev/rest/outconns.html) [Authentication Secure channels with Basic Auth, API keys and bearer tokens - rejected callers never reach your service.](https://zato.io/docs/dev/rest/authentication.html)

## Popular technologies

[Microsoft Send Teams messages, drive Power Automate flows and work with Microsoft 365 data from your services.](https://zato.io/docs/dev/microsoft/index.html) [Message queues Built-in pub/sub plus AMQP, Kafka, IBM MQ and Azure Service Bus.](https://zato.io/docs/dev/message-queues/index.html) [Databases Query PostgreSQL, Oracle, SQL Server and other SQL and NoSQL databases from your services.](https://zato.io/docs/dev/databases/index.html) [AWS Store files in S3, send SQS messages and invoke Lambda functions from your services.](https://zato.io/docs/dev/examples/cloud/aws/index.html)

## Write your services

[Workflow Write, deploy and update services in a cycle with no restarts.](https://zato.io/docs/dev/workflow/index.html) [Request and response Read each request's input and build its response through typed objects.](https://zato.io/docs/dev/request-response/index.html) [Data models Define typed input and output once - validation and OpenAPI schemas follow from it.](https://zato.io/docs/dev/model/index.html) [Configuration Keep configuration outside code - services read it from files you edit in the Dashboard.](https://zato.io/docs/dev/config/index.html)

## Business systems

[SAP Read and write S/4HANA and SuccessFactors business data from your services.](https://zato.io/docs/dev/sap/index.html) [Odoo Create, read and update Odoo records, and let Odoo call your services.](https://zato.io/docs/dev/odoo/index.html) [Salesforce Query, create and update Salesforce records, and keep CRMs in sync on a schedule.](https://zato.io/docs/dev/salesforce/index.html) [Shopify Manage Shopify products, receive webhooks and keep ERP inventory in sync.](https://zato.io/docs/dev/shopify/index.html) [OData Query OData systems such as SAP and Microsoft with a typed Python API.](https://zato.io/docs/dev/odata/index.html)

## Rule engine

[Rule engine Keep business rules outside code and evaluate them from your services at runtime.](https://zato.io/docs/rule-engine/index.html) [Tutorial Business rules in plain English - the zrules syntax and how services match rules.](https://zato.io/docs/rule-engine/tutorial.html) [Reference Every operator, block and literal of the rule language in one place.](https://zato.io/docs/rule-engine/reference.html)

## File transfer

[File transfer Receive and send files over SFTP, SMB and local directories, with schedules and feeds.](https://zato.io/docs/dev/file-transfer/index.html) [Receiving files What each file transfer item contains and what happens when your service refuses a file.](https://zato.io/docs/dev/file-transfer/receiving-files.html) [SFTP Server address, username and password, private key authentication and host key checking.](https://zato.io/docs/dev/file-transfer/sftp.html) [Schedules Watching a directory, deciding when a file has finished uploading and invoking a service once per file.](https://zato.io/docs/dev/file-transfer/schedules.html)

## SOAP and B2B

[SOAP Call and receive SOAP as plain Python objects - no XML, schemas or WSDL compilation.](https://zato.io/docs/dev/soap/index.html) [SOAP mandates Meet the SOAP requirements of healthcare, immunization and national networks.](https://zato.io/docs/dev/soap/mandates/index.html)

## Secure your APIs

[Bearer tokens Protect channels with OAuth-style bearer tokens and attach them to outgoing calls.](https://zato.io/docs/security/bearer-tokens/index.html) [mTLS Require client certificates on your APIs with mutual TLS.](https://zato.io/docs/security/mtls/index.html) [Kerberos Authenticate callers with Kerberos and SPNEGO in Windows environments.](https://zato.io/docs/security/kerberos/index.html) [Cryptography Generate secrets, encrypt data and hash passwords with the platform's crypto API.](https://zato.io/docs/dev/crypto/index.html)

## Test and automate

[API testing Test REST, SQL, LDAP and business systems in plain English - no code required.](https://zato.io/docs/api-testing/index.html) [CI/CD test pipelines Run API tests in GitHub Actions, GitLab CI, Azure DevOps and Jenkins.](https://zato.io/docs/api-testing/ci-cd.html) [Connector SDK Build your own outgoing connection types on top of any client library.](https://zato.io/docs/sdk/index.html)

## More resources

[Programming examples Ready-to-use examples for every connection type the platform ships with.](https://zato.io/docs/dev/examples/index.html) [Architecture Servers, load balancers, the message broker and the scheduler - what runs where and how the parts fit together.](https://zato.io/docs/arch/index.html) [API Management Publish, secure and version your APIs, with quotas and usage analytics.](https://zato.io/docs/api-management/index.html)
