JSON API to Report: Reporting on Data From Any REST API
Turn a JSON API into a scheduled business report: find the records array, handle paging and auth, flatten nested fields and keep the data scoped and fresh.
· 4 min read · Summarix team
If a system can return its data as JSON over HTTPS, you can report on it without exporting spreadsheets. Point a REST/JSON connection at the endpoint, tell it where the list of records sits in the response and where to find the next page, add an authorization header if the API needs one, and the records become a dataset you can sync on a schedule and turn into a report.
When the REST/JSON source fits
It suits systems that have an API but no ready-made connector: an ERP or point-of-sale system, a booking platform, an in-house application, a government or industry data feed. The connection has four settings:
| Setting | Example | Notes |
|---|---|---|
| Endpoint URL (https) | https://api.example.com/v1/orders | Must be HTTPS and reachable from the internet |
| Authorization header | Bearer eyJ... | Optional; stored encrypted |
| Path to the records array | data.items | Blank if the response is the array itself |
| Path to next-page URL | links.next | Blank if everything comes in one response |
Finding the records array
Call the endpoint once yourself, in a browser or an API tool, and look at the shape of the response. Most APIs wrap the records in an object with paging information next to them:
{
"data": {
"items": [
{ "id": 1042, "date": "2026-09-01", "total": 1850.00,
"customer": { "name": "Acme Traders", "region": "Western Cape" },
"lines": [ { "sku": "A1" }, { "sku": "B7" } ] }
]
},
"links": { "next": "https://api.example.com/v1/orders?page=2" }
}Here the path to the records is `data.items` and the path to the next page is `links.next`. A relative next link, such as /v1/orders?page=2, works too. The connection follows next links page by page, so an API that pages with a link in each response is handled for you.
How nested JSON becomes columns
- Nested objects become dotted columns: `customer.name`, `customer.region`.
- Nesting is followed a few levels deep; anything deeper is kept as text in one column.
- A list of plain values, such as tags, becomes one comma-separated cell.
- A list of objects, such as order lines, becomes a count: `lines` would hold 2 for the order above.
- Up to 150 columns are kept, and very long text values are cut at 2,000 characters.
The count rule matters for order data: you get one row per order with the number of lines, not one row per line. If you need line-level detail, use an endpoint that returns lines as the records. Our data cleaning checklist covers what to check once the columns are in.
Security and scope
- Use a read-only API key or token, created only for reporting.
- Prefer an endpoint or query parameters that return only the fields you need. Summarix masks sensitive columns and values before any AI call, but the dataset itself still holds what the API returned.
- The endpoint must be reachable on the public internet over HTTPS; addresses on private networks are blocked.
- Scope the data with the URL: many APIs accept parameters such as ?from=2026-09-01 or ?status=paid, so the dataset holds the period or the records the report is about.
Syncing and scheduling
Choose how often the connection syncs: manually, every hour, daily or weekly. Each sync replaces the dataset with up to 200,000 records, so a scheduled report always uses the latest data. A fixed date in the URL, however, stays fixed: for 'the last seven days', the API needs a relative parameter, or an endpoint that returns recent records by default. Keeping report data fresh covers the timing in more detail.
When the API cannot be reached from outside
Systems on an internal network, or behind a firewall, cannot be polled from the internet. Turn the flow around: a script or an automation tool such as Zapier, Make, n8n or Power Automate sends rows to a private push URL, either adding to the dataset (append) or starting it over (replace), up to 10,000 rows per request. The developer docs on sending data in show the request format, and our guide to Zapier, Make and n8n reporting covers the no-code route. If you want reports inside your own product, see the reporting API and webhooks.
Point Summarix at your JSON API and get a scheduled report without exporting a single spreadsheet.
Free plan: 5 AI reports a month, no card needed.
Frequently asked questions
Which APIs work with the REST/JSON connection?
Any HTTPS endpoint that returns JSON and is reachable from the internet, with an optional authorization header. The records can be at the top level or inside the response, and paging works when each response includes a link to the next page.
Can the connection send a POST request or a request body?
No, it reads an endpoint with a GET request. If your API needs a request body to return data, use a push URL instead: a script or automation tool calls your API and sends the rows to the dataset.
What happens to nested arrays such as order lines?
A list of objects becomes a count in one column, so each order row shows how many lines it had. For line-level reporting, use an endpoint that returns the lines themselves as the records.
Is the authorization header kept secret?
Yes. Connection credentials are stored encrypted. Use a read-only key created for reporting, so you can revoke it on its own without affecting other integrations.