On this page

Each account-management key can export a Postman collection and MCP schema definitions. Both exports contain only the resource operations currently available to that key. They include no secret.

Export only the endpoints and MCP tools available to this key Watch on YouTube from 02:04

Download from API settings

  1. Open Settings → API Keys for the key's company.
  2. Find the key and review its available / assigned permission count.
  3. Select Export Postman or Export MCP schemas.

An assigned permission is exported only if the key is usable and its owner still has access to that operation. For example, a key with only contacts:browse and contacts:edit exports the contacts list and update endpoints, plus browse_contacts and edit_contacts tools. It includes no contacts Read, Add, or Delete operation.

The same filtering applies when the owner's company membership, role permissions, or subscription access changes. An expired, revoked, or unassigned key can be reviewed in settings, but its definition export contains no resource operations. A key with no resource grants also produces an empty collection/tool list.

Use a Postman collection

The downloaded JSON is a Postman Collection v2.1 with requests grouped by resource scope. Import the JSON collection into Postman and configure its variables for your installation:

Collection variable Exported value Set it to
base_url The configured API server, normally https://api.nviti.ng. Your API server origin, with no /api/v1/account suffix.
api_key Empty string. The key's secret in local credential storage.
resource_id 1, a placeholder. An actual ID from a Browse or Add response for the request's resource scope.

Requests inherit Bearer authentication using {{api_key}}. Browse requests include example pagination, and Add/Edit requests include example JSON bodies. Replace example fields and IDs before sending requests. A collection-wide resource_id does not guarantee that the same ID exists in every scope.

Save the collection after configuring its local variables. Send Browse first, select an ID from its response, and send Read if granted. For Add, keep the new ID returned by that request and use it for the subsequent Edit, Read, and Delete requests. Wait for each new response to finish before copying an ID.

Add, Edit, and Delete requests act on your company resources. Start with Browse, then Read if granted, to check an intended resource. Keep the secret out of collections you share.

An export is a snapshot. Re-export and import the replacement after permissions change. Removing a permission takes effect immediately on the server even if an old collection still contains its request.

Use MCP schema definitions

The MCP JSON contains connection metadata and a tools array:

Field Meaning
name, version Server definition identity.
endpoint Remote account-management MCP URL.
transport streamable-http.
authentication Bearer header instructions with the placeholder Bearer <API_KEY>.
tools[].name Tool name, such as edit_contacts.
tools[].description Operation purpose and company context.
tools[].inputSchema Accepted arguments, required fields, types, and validation constraints.
tools[].annotations Hints identifying read-only, destructive, and idempotent operations.

This file is Nviti's definition snapshot, rather than a universal client configuration file. Use its endpoint and authentication instructions to connect your MCP client, or use the schemas when developing a custom integration. Configure the secret separately in your client.

The export includes the full permitted tool list. Live tools/list discovery is paginated and can change after export. Reconnect or refresh discovery to pick up permission changes.

Download through REST

Use a valid key with company assignment and API integration access. These downloads do not require a separate resource BREAD grant.

bash
export NVITI_API_BASE_URL='https://api.nviti.ng'
export NVITI_API_KEY='<YOUR_API_KEY>'

curl --fail-with-body --silent --show-error \
  "$NVITI_API_BASE_URL/api/v1/account/exports/postman" \
  -H "Authorization: Bearer $NVITI_API_KEY" \
  -H 'Accept: application/json' \
  --output nviti-postman.json

curl --fail-with-body --silent --show-error \
  "$NVITI_API_BASE_URL/api/v1/account/exports/mcp" \
  -H "Authorization: Bearer $NVITI_API_KEY" \
  -H 'Accept: application/json' \
  --output nviti-mcp.json

Check that each command succeeded before importing its file; an error response is not a definition export. REST downloads return 401 for expired, revoked, or unassigned credentials, whereas an authorized settings-page export for such a key contains an empty operation list. Definitions downloaded through a derived token are additionally limited by that token's issued permissions.

Keep definitions current

  • Added grant: re-export or refresh MCP discovery. A derived token issued earlier cannot gain that new permission; exchange a new token if your integration uses token exchange.
  • Removed grant or owner access: requests lose access immediately. Refresh the collection or tool definitions to remove unavailable operations.
  • Rotated secret: replace the secret in Postman or the MCP client. The schema needs another export only if permissions or connection details also changed.
  • Revoked or expired key: use a usable key. Exports do not bypass key status or authorization.

Use API Settings for lifecycle controls, the REST guide for request behavior, and the scope reference for resource fields.