Pattern: host connector using api_in + event_out

Use this pattern when an ERP, e-commerce platform, or another business system consumes the Ormuz contract and receives platform events.

The pattern

Business system
api_in
event_out
Ormuz

The business system calls Ormuz through api_in; Ormuz returns authorized events through event_out.

In both directions, the transport contract is Ormuz-owned. The corresponding credentials are issued and managed by the platform, not by arbitrary plugin behavior.

Declare the inbound API

Declare this channel under spec.channels in extension.yaml :

YAML
spec:
channels:
  - kind: api_in
    permissions:
      - company:read
      - order:read

The permission is an explicit allowlist. A host connector extension must not request rights “just in case”: every addition expands the trust contract and must correspond to a concrete integration use case.

Declare outbound events

YAML
spec:
channels:
  - kind: event_out
    target_url_field: webhook_target_url
    event_types:
      - order.created
      - order.updated

event_types may contain only canonical events that can actually be delivered by webhook. The targeted URL field must be a configuration field of type url attached to the channel event_out.

Rester minimal

API permissions, mappings, and business authority are three different things. A permission order:write does not make every order mutation legitimate; authority rules still apply. See Business authority.