API reference
API v3
Payment orchestration API of the Konnect Platform.
Version 0.1.089 operationsGenerated from packages/sdk/openapi.json (sha256 68554b7af11c)
Base URLs
Local development: http://localhost:3000. Sandbox and production URLs will be published with the environments.
Authentication
konnect_session(cookie)Dashboard session: these routes serve the dashboard, not merchant integrations.
x-api-key(header)Organisation API key,
<prefix>:<secret>(new keys start withkpk_), created in the dashboard and shown once. Server side only.
health
1 operationauth
10 operations- POSTLog in with email and password (and TOTP when enabled); sets the session cookie
- POSTEnd the current session and clear the cookie (Dashboard session)
- GETCurrent user and memberships with role, permissions and scope (Dashboard session)
- POSTRe-authenticate with the password or a TOTP code; valid for 10 minutes (Dashboard session)
- POSTSend a one-time password reset link (always 202, whether the email exists or not)
- POSTSet a new password with a reset token; ends every session
- POSTStart TOTP enrolment (requires re-authentication) (Dashboard session)
- POSTConfirm TOTP enrolment with a first code (Dashboard session)
- POSTTurn TOTP off (requires re-authentication and a current code) (Dashboard session)
- GETIdentity of the API key used for the request (API key)
api-keys
3 operationsorganisations
6 operations- GETOrganisations of the current user with role, permissions and scope (Dashboard session)
- GETIdentity, status facts and the computed canCollect with its reasons (Dashboard session)
- PATCHEdit address, phone, email and website (legal identity is read-only) (Dashboard session)
- GETContract status (Documenso signing link: placeholder, always null) (Dashboard session)
- POSTKonnect compliance: mark the KYB verified (audited) (Dashboard session)
- POSTKonnect compliance: refuse the KYB with a reason (audited) (Dashboard session)
members
6 operations- GETMembers with role and scope, and pending invitations (Dashboard session)
- POSTInvite by email with a role and a scope (link returned outside production) (Dashboard session)
- PATCHChange the role or the scope of a member (not the owner) (Dashboard session)
- DELETERemove a member (not the owner) (Dashboard session)
- DELETECancel a pending invitation (Dashboard session)
- POSTAccept an invitation: creates the account for a new email, or needs the session of the invited email
files
4 operationsroles
8 operations- GETPredefined and custom roles with their permissions (Dashboard session)
- POSTCreate a custom role, or duplicate one with basedOnRoleId (Dashboard session)
- PATCHEdit a custom role (predefined roles are fixed) (Dashboard session)
- DELETEDelete a custom role that no member or pending invitation uses (Dashboard session)
- GETThe pending ownership transfer, if any (Dashboard session)
- POSTOwner only: offer ownership to a member (requires re-authentication) (Dashboard session)
- POSTThe new owner accepts; the former owner becomes Administrator (Dashboard session)
- DELETEThe owner withdraws, or the recipient declines, a pending transfer (Dashboard session)
payment-accounts
7 operations- GETPayment accounts within your scope, with routing and providers (API key)
- POSTCreate a payment account (a collection point of the organisation) (Dashboard session)
- GETOne payment account (API key)
- PATCHEdit name, slug, branding, URLs; pause, resume or make default (Dashboard session)
- POSTArchive a payment account (terminal; never the default account) (Dashboard session)
- GETAffiliation used per provider, and the accepted providers (API key)
- PUTRoute providers to affiliations of this organisation (null removes a route); revoked affiliations and affiliations of another organisation are refused (Dashboard session)
providers
3 operationsaffiliations
9 operations- GETAffiliations of the organisation with masked credentials (API key)
- POSTAdd provider credentials: validated, encrypted, then verified through the connector (API key)
- GETOne affiliation with masked credentials (API key)
- POSTRun the credential check again (API key)
- PUTReplace the credentials (rotation): the previous version stays until the new one verifies (API key)
- POSTSuspend an active affiliation (API key)
- POSTResume a suspended affiliation (API key)
- POSTRevoke (terminal): the row stays, the credentials and their data keys are destroyed (API key)
- GETAudit events of one affiliation, newest first (the owner and Konnect support) (Dashboard session)
admin
11 operations- GETKonnect admin and support: affiliations across organisations (Dashboard session)
- GETOutbox events, newest first (Konnect support) (Dashboard session)
- GETKonnect staff: every organisation with its status facts (Dashboard session)
- GETKonnect staff: identity and status facts of one organisation (Dashboard session)
- GETFull timeline of any payment, with raw provider payloads (admin) (Dashboard session)
- GETEvery platform setting with its value or secret hint and source (Dashboard session)
- POSTSend a test e-mail through the current e-mail settings (Dashboard session)
- GETOne platform setting (Dashboard session)
- PUTChange a platform setting (reason required); applies to every API process (Dashboard session)
- POSTDelete the database value: the environment or code default applies (Dashboard session)
- GETChanges of a setting, newest first (secrets masked) (Dashboard session)
payments
6 operations- GETPayments of the organisation, newest first, keyset paginated (API key)
- POSTCreate a payment and get its checkout URL (API key)
- GETOne payment by reference (API key)
- POSTCancel a pending payment (API key)
- GETFull timeline of a payment, oldest first (API key)
- GETAttempts of a payment, newest first, each with its timeline (API key)
checkout
6 operations- GETWhat the checkout shows for a payment (public, no merchant data)
- GETSend the payer back to the merchant (public)
- GETLogo of the payment account of a payment (public, PNG or JPEG)
- GETPayment status for the result page polling (public)
- POSTOpen an attempt at a provider (public)
- GETAn attempt of a payment as the checkout shows it again (public)
webhooks
6 operations- GETWebhook endpoints of the organisation (secret hints only) (API key)
- POSTRegister a webhook endpoint; the signing secret is returned once (API key)
- GETOne webhook endpoint (API key)
- DELETEDisable an endpoint (terminal; its delivery log stays) (API key)
- GETDelivery log of an endpoint, newest first (API key)
- POSTReplay a delivery once (manual try) (API key)