Référence API
API v3
Payment orchestration API of the Konnect Platform.
Version 0.1.089 opérationsGénéré depuis packages/sdk/openapi.json (sha256 68554b7af11c)
Les descriptions de la v3 sont générées depuis le code et restent en anglais.
URL de base
Développement local : http://localhost:3000. Les URL de sandbox et de production seront publiées avec les environnements.
Authentification
konnect_session(cookie)Session du tableau de bord : ces routes servent le tableau de bord, pas les intégrations marchandes.
x-api-key(header)Clé API de l'organisation,
<prefix>:<secret>(les nouvelles clés commencent parkpk_), créée dans le tableau de bord et affichée une seule fois. Côté serveur uniquement.
health
1 opérationauth
10 opérations- POSTLog in with email and password (and TOTP when enabled); sets the session cookie
- POSTEnd the current session and clear the cookie (Session du tableau de bord)
- GETCurrent user and memberships with role, permissions and scope (Session du tableau de bord)
- POSTRe-authenticate with the password or a TOTP code; valid for 10 minutes (Session du tableau de bord)
- POSTSend a one-time password reset link (always 202, whether the email exists or not)
- POSTSet a new password with a reset token; ends every session
- POSTStart TOTP enrolment (requires re-authentication) (Session du tableau de bord)
- POSTConfirm TOTP enrolment with a first code (Session du tableau de bord)
- POSTTurn TOTP off (requires re-authentication and a current code) (Session du tableau de bord)
- GETIdentity of the API key used for the request (Clé API)
api-keys
3 opérationsorganisations
6 opérations- GETOrganisations of the current user with role, permissions and scope (Session du tableau de bord)
- GETIdentity, status facts and the computed canCollect with its reasons (Session du tableau de bord)
- PATCHEdit address, phone, email and website (legal identity is read-only) (Session du tableau de bord)
- GETContract status (Documenso signing link: placeholder, always null) (Session du tableau de bord)
- POSTKonnect compliance: mark the KYB verified (audited) (Session du tableau de bord)
- POSTKonnect compliance: refuse the KYB with a reason (audited) (Session du tableau de bord)
members
6 opérations- GETMembers with role and scope, and pending invitations (Session du tableau de bord)
- POSTInvite by email with a role and a scope (link returned outside production) (Session du tableau de bord)
- PATCHChange the role or the scope of a member (not the owner) (Session du tableau de bord)
- DELETERemove a member (not the owner) (Session du tableau de bord)
- DELETECancel a pending invitation (Session du tableau de bord)
- POSTAccept an invitation: creates the account for a new email, or needs the session of the invited email
files
4 opérationsroles
8 opérations- GETPredefined and custom roles with their permissions (Session du tableau de bord)
- POSTCreate a custom role, or duplicate one with basedOnRoleId (Session du tableau de bord)
- PATCHEdit a custom role (predefined roles are fixed) (Session du tableau de bord)
- DELETEDelete a custom role that no member or pending invitation uses (Session du tableau de bord)
- GETThe pending ownership transfer, if any (Session du tableau de bord)
- POSTOwner only: offer ownership to a member (requires re-authentication) (Session du tableau de bord)
- POSTThe new owner accepts; the former owner becomes Administrator (Session du tableau de bord)
- DELETEThe owner withdraws, or the recipient declines, a pending transfer (Session du tableau de bord)
payment-accounts
7 opérations- GETPayment accounts within your scope, with routing and providers (Clé API)
- POSTCreate a payment account (a collection point of the organisation) (Session du tableau de bord)
- GETOne payment account (Clé API)
- PATCHEdit name, slug, branding, URLs; pause, resume or make default (Session du tableau de bord)
- POSTArchive a payment account (terminal; never the default account) (Session du tableau de bord)
- GETAffiliation used per provider, and the accepted providers (Clé API)
- PUTRoute providers to affiliations of this organisation (null removes a route); revoked affiliations and affiliations of another organisation are refused (Session du tableau de bord)
providers
3 opérationsaffiliations
9 opérations- GETAffiliations of the organisation with masked credentials (Clé API)
- POSTAdd provider credentials: validated, encrypted, then verified through the connector (Clé API)
- GETOne affiliation with masked credentials (Clé API)
- POSTRun the credential check again (Clé API)
- PUTReplace the credentials (rotation): the previous version stays until the new one verifies (Clé API)
- POSTSuspend an active affiliation (Clé API)
- POSTResume a suspended affiliation (Clé API)
- POSTRevoke (terminal): the row stays, the credentials and their data keys are destroyed (Clé API)
- GETAudit events of one affiliation, newest first (the owner and Konnect support) (Session du tableau de bord)
admin
11 opérations- GETKonnect admin and support: affiliations across organisations (Session du tableau de bord)
- GETOutbox events, newest first (Konnect support) (Session du tableau de bord)
- GETKonnect staff: every organisation with its status facts (Session du tableau de bord)
- GETKonnect staff: identity and status facts of one organisation (Session du tableau de bord)
- GETFull timeline of any payment, with raw provider payloads (admin) (Session du tableau de bord)
- GETEvery platform setting with its value or secret hint and source (Session du tableau de bord)
- POSTSend a test e-mail through the current e-mail settings (Session du tableau de bord)
- GETOne platform setting (Session du tableau de bord)
- PUTChange a platform setting (reason required); applies to every API process (Session du tableau de bord)
- POSTDelete the database value: the environment or code default applies (Session du tableau de bord)
- GETChanges of a setting, newest first (secrets masked) (Session du tableau de bord)
payments
6 opérations- GETPayments of the organisation, newest first, keyset paginated (Clé API)
- POSTCreate a payment and get its checkout URL (Clé API)
- GETOne payment by reference (Clé API)
- POSTCancel a pending payment (Clé API)
- GETFull timeline of a payment, oldest first (Clé API)
- GETAttempts of a payment, newest first, each with its timeline (Clé API)
checkout
6 opérations- GETWhat the checkout shows for a payment (public, no merchant data)
- GETSend the payer back to the merchant (public)
- GETLogo of the payment account of a payment (public, PNG or JPEG)
- GETPayment status for the result page polling (public)
- POSTOpen an attempt at a provider (public)
- GETAn attempt of a payment as the checkout shows it again (public)
webhooks
6 opérations- GETWebhook endpoints of the organisation (secret hints only) (Clé API)
- POSTRegister a webhook endpoint; the signing secret is returned once (Clé API)
- GETOne webhook endpoint (Clé API)
- DELETEDisable an endpoint (terminal; its delivery log stays) (Clé API)
- GETDelivery log of an endpoint, newest first (Clé API)
- POSTReplay a delivery once (manual try) (Clé API)