External Inquiry Integration Hub (ExternalApi)
Calls to banks, credit inquiries and external systems are defined, run, cached and audited from one point, instead of a separate client in each service.
- Domain
- Integration and external inquiries
- Target customers
- Technology managers, the integration team, banking and financial product managers
- Main capabilities
- Dynamic no-code creation of new connections, closed and secure catalog, cache and automatic fallback, encrypted credential vault
ExternalApi is the central point for managing and executing all of the organization's calls to external systems: banks, credit inquiry systems, government services or any other external partner. Instead of each platform service writing and maintaining a separate HTTP client for each external system, all of these connections are defined, run, cached, protected against outages of the target system, and audited from one point.
The distinguishing feature of this product is the dynamic creation of new integrations: a completely new connection to an external system can be created in the dashboard through configuration alone, without writing and deploying new code. The target path, parameters, request and response mapping, and result classification rules are all defined from one multi-step form, and before final publication they can be tested in a safe test environment.
From a security standpoint, this service permits calls only to systems predefined in the catalog, and it is never an open proxy to any arbitrary address. Each external system's credentials are stored encrypted and are never visible in raw form in system responses.
Key capabilities
Dynamic integration creation with no new code
Define a completely new connection to an external system through a multi-step configuration form (path, parameters, request and response mapping, result rules), with no development or code deployment.
Test environment before publishing
Before any connection is activated, a preview mode (an exact view of the outgoing request without a real call) and a real trial run (marked as a test) are mandatory, so that a configuration error is caught before production.
Closed, controlled catalog
Only systems predefined in the catalog can be called. No other arbitrary path or address can be contacted through this service.
Multi-system routing with automatic fallback
Several external systems can be defined for one logical service with priorities. If the primary system has a technical error, the request is automatically redirected to the backup system.
Configurable cache without service downtime
The cache duration of each service's result (seconds to days) can be changed without restarting the service, so that repeated calls are answered at lower cost.
Encrypted credential vault
Each external system's credentials are stored encrypted and are not shown in raw form in any system response.
Support for different outbound authentication methods
API key, Bearer, OAuth2 with automatic token renewal, request signing with HMAC, and basic authentication, according to the needs of each external system.
Complete audit record of every call
Every call and every retry is recorded in detail (with sensitive data automatically masked), for accountability and later review.
Multi-instance synchronization
When the service runs on several instances, every configuration change is propagated to all instances immediately, with no redeployment.
Business value
Every time an organization needs to connect to a new external system (a new bank, a new inquiry service), this usually requires a full development and deployment cycle. ExternalApi turns this into a configuration change that can be tested before activation, and it greatly shortens the time needed to set up a new connection. Concentrating all external calls in one point, along with caching, automatic fallback and unified auditing, protects against temporary outages of external systems and also provides a single, reviewable path for compliance and audit. Credential encryption and masking of sensitive data in event logs reduce the risk of exposing confidential information of external systems.
What sets it apart
- Building a new integration through configuration alone, with a mandatory test environment before publication.
- A closed catalog: no call to an arbitrary address is possible, only to defined systems.
- An encrypted credential vault and event logging with automatic masking of sensitive data, provided as standard and never as an option.
- Support for several outbound authentication methods (key, Bearer, OAuth2 with automatic renewal, HMAC signing) for each external system.
- Built-in cache and automatic fallback, with no separate engineering needed for each new connection.
- Instant propagation of configuration among all running instances.
See this module on demo data
In a demo session we walk through your organization's scenarios on Dara's demo environment and answer your technical and finance teams' questions.