REST-API
Nova is driven end to end by its API: every platform function is available as a JSON endpoint, and the Nova UI itself uses exactly these endpoints. Anything you can do in the interface, you can do from a script or a neighboring system.
What the REST API does
- Manages users, roles, and assignments through the same JSON endpoints the Nova UI uses
- Triggers provisioning and reconciliation runs from scripts or neighboring systems
- Starts and monitors background jobs such as bulk imports and syncs
- Administers connected target and source systems, including their configuration
- Protects every mutating endpoint with admin permission checks
Technical integration
HTTP endpoints with JSON payloads; they are the same routes the Nova UI uses. All mutating routes are protected by admin permission checks. Hardening along OWASP ASVS L2 following an internal code assessment (06/2026); external review pending.
In the identity lifecycle
The API automates lifecycle operations: trigger HR imports and joiner, mover, and leaver runs, set assignments, and query the results. Request and recertification data is equally reachable for neighboring systems.
All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.