Destinations & Activation → APIs & Webhooks

External Applications

A general-purpose, authenticated REST API surface for external and partner applications to read profile, propensity, and activation-relevant data on demand.

High-Level Design

External Applications is the on-demand pull counterpart to the push-based webhook path.

Data Source
Data Sources
Every touchpoint and business system
→
Ingestion
Ingestion Layer
SDKs, connectors, protocols
→
Processing
Transformation & Processing
Populates the profile/propensity data this API serves
→
Foundation
Profile API
Underlying data source for external reads
→
Intelligence
Propensity Scores
Also exposed for entitled external callers
→
Activation
External Applications
.NET Core public API behind Azure API Management

💼 Business Context

  • Some partner and internal applications need to pull data on demand rather than react to a push event — this is that path, distinct from Journeys & Automation's webhook model
  • Gives external application developers a self-service, documented API instead of a bespoke integration per partner
  • Owned by Platform Engineering

🔌 Technical Overview

External Applications is a .NET Core public API (Docker container on AKS) fronted by Azure API Management, applying OAuth 2.0 client-credentials authentication (Azure AD B2C for customer-facing partner apps, Azure AD/Entra ID app registrations for internal-partner service accounts) and per-application rate limiting. It wraps the same Profile API and Propensity Scores data already used internally, applying entitlement scoping per registered application so an external partner only ever sees the fields their integration agreement covers.

API Surface

REST + OAuth 2.0 Rate-limited per application Profile & propensity reads API key / client-credentials auth

💾 External API Request

POST /oauth/token  (client_credentials grant)

GET /external/v1/profile/cust_004821
Authorization: Bearer 

200 OK
{ "lifecycle_stage": "active", "ltv_band": "gold" }
-- only fields covered by this partner's integration agreement are returned

🔗 Integration Points

  • Azure API Management — gateway: OAuth validation, rate limiting
  • Azure AD B2C / Entra ID — identity providers for partner and internal-service authentication
  • Profile API, Propensity Scores — underlying data this surface wraps with external-appropriate scoping
  • Application Insights — per-partner usage and error tracking

🧰 Services Consumed

  • Owning microservice — Cxos.Activation.Api (see the Full Application Service Map)
  • Database — Azure Cosmos DB (dispatch log) + Azure Cache for Redis (frequency caps)

⚠️ Non-Functional Considerations

  • Scale: rate limits are set per registered application to prevent one partner's traffic from degrading service for others
  • Latency: p99 under 200ms, comparable to the internal Profile API since it wraps the same underlying data path
  • Reliability: circuit breakers protect the API if an underlying dependency (Profile API, propensity store) is degraded
  • Security/Privacy: every registered application has an explicit field-level entitlement scope reviewed at onboarding — no partner gets broader access than its integration agreement specifies

🎯 Enterprise Example

A loyalty-partner mobile app calls External Applications on login to fetch the customer's current LTV band and display tier-appropriate perks — a self-service integration the partner's own engineering team built from published API docs, without a CXOS engineer involved in the build.

← Back to APIs & Webhooks