Each account-management key can export a Postman collection and MCP schema definitions. Both exports contain only the resource operations currently available to that key. They include no secret.
Download from API settings
- Open Settings → API Keys for the key's company.
- Find the key and review its available / assigned permission count.
- Select Export Postman or Export MCP schemas.
An assigned permission is exported only if the key is usable and its owner still has access to that operation. For example, a key with only contacts:browse and contacts:edit exports the contacts list and update endpoints, plus browse_contacts and edit_contacts tools. It includes no contacts Read, Add, or Delete operation.
The same filtering applies when the owner's company membership, role permissions, or subscription access changes. An expired, revoked, or unassigned key can be reviewed in settings, but its definition export contains no resource operations. A key with no resource grants also produces an empty collection/tool list.
Use a Postman collection
The downloaded JSON is a Postman Collection v2.1 with requests grouped by resource scope. Import the JSON collection into Postman and configure its variables for your installation:
| Collection variable | Exported value | Set it to |
|---|---|---|
base_url |
The configured API server, normally https://api.nviti.ng. |
Your API server origin, with no /api/v1/account suffix. |
api_key |
Empty string. | The key's secret in local credential storage. |
resource_id |
1, a placeholder. |
An actual ID from a Browse or Add response for the request's resource scope. |
Requests inherit Bearer authentication using {{api_key}}. Browse requests include example pagination, and Add/Edit requests include example JSON bodies. Replace example fields and IDs before sending requests. A collection-wide resource_id does not guarantee that the same ID exists in every scope.
Save the collection after configuring its local variables. Send Browse first, select an ID from its response, and send Read if granted. For Add, keep the new ID returned by that request and use it for the subsequent Edit, Read, and Delete requests. Wait for each new response to finish before copying an ID.
Add, Edit, and Delete requests act on your company resources. Start with Browse, then Read if granted, to check an intended resource. Keep the secret out of collections you share.
An export is a snapshot. Re-export and import the replacement after permissions change. Removing a permission takes effect immediately on the server even if an old collection still contains its request.
Use MCP schema definitions
The MCP JSON contains connection metadata and a tools array:
| Field | Meaning |
|---|---|
name, version |
Server definition identity. |
endpoint |
Remote account-management MCP URL. |
transport |
streamable-http. |
authentication |
Bearer header instructions with the placeholder Bearer <API_KEY>. |
tools[].name |
Tool name, such as edit_contacts. |
tools[].description |
Operation purpose and company context. |
tools[].inputSchema |
Accepted arguments, required fields, types, and validation constraints. |
tools[].annotations |
Hints identifying read-only, destructive, and idempotent operations. |
This file is Nviti's definition snapshot, rather than a universal client configuration file. Use its endpoint and authentication instructions to connect your MCP client, or use the schemas when developing a custom integration. Configure the secret separately in your client.
The export includes the full permitted tool list. Live tools/list discovery is paginated and can change after export. Reconnect or refresh discovery to pick up permission changes.
Download through REST
Use a valid key with company assignment and API integration access. These downloads do not require a separate resource BREAD grant.
export NVITI_API_BASE_URL='https://api.nviti.ng'
export NVITI_API_KEY='<YOUR_API_KEY>'
curl --fail-with-body --silent --show-error \
"$NVITI_API_BASE_URL/api/v1/account/exports/postman" \
-H "Authorization: Bearer $NVITI_API_KEY" \
-H 'Accept: application/json' \
--output nviti-postman.json
curl --fail-with-body --silent --show-error \
"$NVITI_API_BASE_URL/api/v1/account/exports/mcp" \
-H "Authorization: Bearer $NVITI_API_KEY" \
-H 'Accept: application/json' \
--output nviti-mcp.json
Check that each command succeeded before importing its file; an error response is not a definition export. REST downloads return 401 for expired, revoked, or unassigned credentials, whereas an authorized settings-page export for such a key contains an empty operation list. Definitions downloaded through a derived token are additionally limited by that token's issued permissions.
Keep definitions current
- Added grant: re-export or refresh MCP discovery. A derived token issued earlier cannot gain that new permission; exchange a new token if your integration uses token exchange.
- Removed grant or owner access: requests lose access immediately. Refresh the collection or tool definitions to remove unavailable operations.
- Rotated secret: replace the secret in Postman or the MCP client. The schema needs another export only if permissions or connection details also changed.
- Revoked or expired key: use a usable key. Exports do not bypass key status or authorization.
Use API Settings for lifecycle controls, the REST guide for request behavior, and the scope reference for resource fields.