Skip to main content

Kisi

Kisi is a cloud-based physical access control platform that manages locks, users, members, and permissions across facilities. Its REST API exposes endpoints for user and member management, access and login logs, reports, and facility administration, letting you sync access-control data into Nexla and push provisioning changes back to Kisi.

Kisi icon

Power end-to-end data operations for your Kisi API with Nexla. Our bi-directional Kisi connector is purpose-built for Kisi, making it simple to ingest data, sync it across systems, and deliver it anywhere — all with no coding required. Nexla turns API-sourced data into ready-to-use, reusable data products and makes it easy to send data to Kisi or any other destination. With comprehensive monitoring, lineage tracking, and access controls, Nexla keeps your Kisi workflows fast, secure, and fully governed.

Features

Type: API

SourceDestination

  • Seamless API Integration: Connect to any endpoint as source or destination without coding, with automatic data product creation
  • Visual Composition & Chaining: Build complex integrations using visual templates, chain API calls, and compose workflows with data validation and filtering
  • API Proxy: Expose curated slices of your data securely with a secure and customizable API proxy that validates and transforms data on the fly
  • Request optimization with intelligent batching, retry, and caching to minimize API calls and costs

Prerequisites

Before creating a Kisi credential, you need a Kisi API key. Kisi authenticates every API request with an API key (also called a login secret) sent in the Authorization header using the format KISI-LOGIN <your-api-key>. You need organization administrator or organization owner rights to create an API key, and Kisi recommends generating it from the organization owner's account so the key is not invalidated if an admin later loses their permissions.

To generate a Kisi API key, follow these steps:

  1. Sign in to your Kisi web dashboard at https://web.kisi.io with an account that has organization administrator or owner rights.

  2. Click your name in the top right corner and select My Account.

  3. Open the API tab and click Add API Key.

  4. Enter a name for the key (for example, "Nexla Integration"), enter your Kisi password to confirm, and click Add.

  5. Copy the displayed API key immediately and store it securely, then click Close. The key is shown only once.

By default, Kisi API keys expire after 6 months of inactivity. Each user can hold up to 40 API keys. You will also need the base URL for the Kisi API, which is https://api.kisi.io. For more detail, see the Kisi API documentation and the Generate an API key guide.

Authenticate

Credentials required

Kisi API Key authentication using KISI-LOGIN token in Authorization header. Obtain your API key from the Kisi dashboard.

FieldRequiredSecretDescription
API Key ValueYesYesAn encoded string value used as a secret token to authenticate API requests
Base URLYesNoThe base URL for the Kisi API.

Create a credential in Nexla

  1. After selecting the data source/destination type, click the Add Credential tile to open the Add New Credential overlay.

  2. Enter a name for the credential in the Credential Name field and a short, meaningful description in the Credential Description field.

  3. Enter your Kisi API key in the API Key Value field. This is the key you generated in Prerequisites; Nexla sends it in the Authorization header as KISI-LOGIN <your-api-key> for all API requests. This value is stored securely and must be kept confidential.

  4. Enter the Kisi API base URL in the Base URL field. In most cases this is https://api.kisi.io.

    If your API key is compromised, revoke it from the API tab under My Account in the Kisi dashboard and generate a new one. API keys grant access to your Kisi access-control data and should be treated as sensitive information.

  5. Click the Save button at the bottom of the overlay. The newly added credential will now appear in a tile on the Authenticate screen during data source/destination creation.

Use as a data source

To create a new data flow, navigate to the Integrate section, and click the New Data Flow button. Select the Kisi connector tile, then select the credential that will be used to connect to the Kisi instance, and click Next; or, create a new Kisi credential for use in this flow.

Endpoint templates

Nexla provides pre-built templates that can be used to rapidly configure data sources to ingest data from common Kisi endpoints. Select the endpoint from which this source will fetch data from the Endpoint pulldown menu. Available endpoint templates are listed in the expandable boxes below.

[Rest API] List Users

Returns a list of all users in the Kisi account.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List User Export Reporters

Returns a list of users configured as export reporters in the account.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List Scheduled Reports

Returns a list of all scheduled reports in the account.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List Role Assignments

Returns a list of all role assignments in the account.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List Places

Returns a list of all places (locations) in the account.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List Reports

Returns a list of all reports in the account.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List Organizations

Returns a list of all organizations in the account.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List Members

Returns a list of all members in the account.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List Logins

Returns a list of all login records in the account.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List Locks

Returns a list of all locks in the account.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List Groups

Returns a list of all groups in the Kisi access control system.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List Floors

Returns a list of all floors in the Kisi access control system.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List Elevators

Returns a list of all elevators in the Kisi access control system.

This endpoint is paginated. Nexla automatically iterates through pages using an incrementing offset until all records have been retrieved.

[Rest API] List Cards

List physical access cards registered in the organization.

This endpoint returns the full set of registered cards in a single request. Card records are read from the cards array in the API response.

Once the selected endpoint template has been configured, click the Test button to the right of the endpoint selection menu to retrieve a sample of the data that will be fetched. Sample data will be displayed in the Endpoint Test Result panel on the right, allowing you to verify that the source is configured correctly before saving.

Manual configuration

Kisi data sources can also be manually configured to ingest data from any valid Kisi API endpoint, including endpoints not covered by the pre-built templates, chained API calls, or custom request parameters. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, endpoint URL, date/time and lookup macros, path to data, metadata, and request headers.

Once all of the relevant settings have been configured, click the Create button in the upper right corner of the screen to save and create the new Kisi data source. Nexla will now begin ingesting data from the configured endpoint and will organize any data that it finds into one or more Nexsets.

Use as a destination

Click the + icon on the Nexset that will be sent to the Kisi destination, and select the Send to Destination option from the menu. Select the Kisi connector from the list of available destination connectors, then select the credential that will be used to connect to the Kisi organization, and click Next; or, create a new Kisi credential for use in this flow.

Endpoint templates

Nexla provides pre-built templates that can be used to rapidly configure destinations to send data to common Kisi endpoints. Select the endpoint to which data will be sent from the Endpoint pulldown menu. Then, click on the template in the list below to expand it, and follow the instructions to configure additional endpoint settings.

[Rest API] Create a lock

Create a new lock (door) in a Kisi place. Each record from your Nexset is sent as a separate request to add a lock.

[Rest API] Create a member

Invite or add a member to a place. Each record from your Nexset is sent as a separate request to provision a member.

[Rest API] Create a card assignment

Assign a physical card to a user. Each record from your Nexset is sent as a separate request to create a card assignment.

[Rest API] Create a group

Create an access group. Each record from your Nexset is sent as a separate request to add a group.

[Rest API] Unlock a lock

Trigger an unlock action on a specific lock by ID. This endpoint requires the target lock's unique identifier, which is configured as an endpoint parameter.

[Rest API] Create a place

Create a new place (facility/building) in an organization. Each record from your Nexset is sent as a separate request to add a place.

[Rest API] Update a group

Update an access group's settings or membership. This endpoint allows you to modify group configurations and manage group memberships, and requires the target group's unique identifier.

[Rest API] Update a lock

Update an existing lock's settings or metadata by providing the lock ID and updated configuration parameters.

[Rest API] Delete a group

Delete an access group by its unique identifier from the Kisi access control system.

[Rest API] Delete a lock

Remove a lock from a place by its ID.

[Rest API] Delete a member

Remove a member from a place (de-provisioning). This endpoint deletes a member record by their unique identifier.

Manual configuration

Kisi destinations can also be manually configured to send data to any valid Kisi API endpoint. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, data format, endpoint URL, request headers, attribute exclusions, record batching, and response webhooks.

Kisi write endpoints expect JSON payloads. For update and delete operations, include the ID of the target object in the endpoint parameter so it can be appended to the request URL.

Save & activate

Once all endpoint settings have been configured, click the Done button in the upper right corner of the screen to save and create the destination. To send the data to the configured Kisi endpoint, open the destination resource menu, and select Activate.

The Nexset data will not be sent to the Kisi endpoint until the destination is activated. Destinations can be activated immediately or at a later time, providing full control over data movement.