Pattern: host connector using api_in + event_out
Use this pattern when an ERP, e-commerce platform, or another business system consumes the Ormuz contract and receives platform events.
The pattern
The business system calls Ormuz through api_in; Ormuz returns authorized events through event_out.
In both directions, the transport contract is Ormuz-owned. The corresponding credentials are issued and managed by the platform, not by arbitrary plugin behavior.
Declare the inbound API
Declare this channel under spec.channels in extension.yaml :
spec:
channels:
- kind: api_in
permissions:
- company:read
- order:readThe permission is an explicit allowlist. A host connector extension must not request rights “just in case”: every addition expands the trust contract and must correspond to a concrete integration use case.
Declare outbound events
spec:
channels:
- kind: event_out
target_url_field: webhook_target_url
event_types:
- order.created
- order.updatedevent_types may contain only canonical events that can actually be delivered by webhook. The targeted URL field must be a configuration field of type url attached to the channel event_out.
Rester minimal
API permissions, mappings, and business authority are three different things. A permission order:write does not make every order mutation legitimate; authority rules still apply. See Business authority.