affiliations
Version 0.1.09 opérations
Affiliations of the organisation with masked credentials
GET/organisations/{organisationId}/affiliationsClé API
Paramètres
organisationIdstringpathobligatoire
Réponses
200
idstring (uuid)obligatoireorganisationIdstring (uuid)obligatoireproviderstringobligatoire- enum: "clictopay", "flouci", "izi", "mpgs_poste", "pluxee", "kashy", "enda_tao"
providerNamestringobligatoirelabelstringobligatoireenvironmentstringobligatoire- enum: "sandbox", "production"
statusstringobligatoire- enum: "draft", "verifying", "active", "suspended", "revoked"
publicIdentifierstring | nullobligatoireNever a secret
credentialsobjectobligatoireNon-secret fields in full, secret fields as **** plus their last four characters; never a value usable at the provider
credentialVersionnumberobligatoireCurrent credential version, 1 for the first credentials
verifiedAtstring (date-time) | nullobligatoirelastUsedAtstring (date-time) | nullobligatoirelastVerificationErrorstring | nullobligatoireReadable, never a secret
revokedAtstring (date-time) | nullobligatoirepaymentAccountsRoutedPaymentAccountDto[]obligatoirePayment accounts whose routing uses this affiliation; they lose it on revoke
idstring (uuid)obligatoirenamestringobligatoirestatusstringobligatoire- enum: "active", "paused", "archived"
createdAtstring (date-time)obligatoireupdatedAtstring (date-time)obligatoire
Exemples de code
curl -X GET "$KONNECT_API_URL/organisations/org_01J9Z3K4EXAMPLE0000000000/affiliations" \
-H "x-api-key: $KONNECT_API_KEY"Exemple : 200
[
{
"id": "id",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"provider": "clictopay",
"providerName": "ClicToPay",
"label": "default",
"environment": "sandbox",
"status": "draft",
"publicIdentifier": "publicIdentifier",
"credentials": {},
"credentialVersion": 1,
"verifiedAt": "2026-10-01T09:30:00.000Z",
"lastUsedAt": "2026-10-01T09:30:00.000Z",
"lastVerificationError": "lastVerificationError",
"revokedAt": "2026-10-01T09:30:00.000Z",
"paymentAccounts": [
{
"id": "id",
"name": "name",
"status": "active"
}
],
"createdAt": "2026-10-01T09:30:00.000Z",
"updatedAt": "2026-10-01T09:30:00.000Z"
}
]Add provider credentials: validated, encrypted, then verified through the connector
POST/organisations/{organisationId}/affiliationsClé API
Ends active with a publicIdentifier when the provider accepts the credentials, stays verifying with a readable lastVerificationError otherwise. Sessions need a re-authentication in the last 10 minutes (403 reauth_required).
Paramètres
organisationIdstringpathobligatoire
Corps de la requête application/json
providerstringobligatoire- enum: "clictopay", "flouci", "izi", "mpgs_poste", "pluxee", "kashy", "enda_tao"
labelstringLowercase letters, digits, - and _; unique per organisation and provider
environmentstringobligatoire- enum: "sandbox", "production"
credentialsobjectobligatoireOne value per field of the provider credentialSchema (GET /providers/:code)
Réponses
201
idstring (uuid)obligatoireorganisationIdstring (uuid)obligatoireproviderstringobligatoire- enum: "clictopay", "flouci", "izi", "mpgs_poste", "pluxee", "kashy", "enda_tao"
providerNamestringobligatoirelabelstringobligatoireenvironmentstringobligatoire- enum: "sandbox", "production"
statusstringobligatoire- enum: "draft", "verifying", "active", "suspended", "revoked"
publicIdentifierstring | nullobligatoireNever a secret
credentialsobjectobligatoireNon-secret fields in full, secret fields as **** plus their last four characters; never a value usable at the provider
credentialVersionnumberobligatoireCurrent credential version, 1 for the first credentials
verifiedAtstring (date-time) | nullobligatoirelastUsedAtstring (date-time) | nullobligatoirelastVerificationErrorstring | nullobligatoireReadable, never a secret
revokedAtstring (date-time) | nullobligatoirepaymentAccountsRoutedPaymentAccountDto[]obligatoirePayment accounts whose routing uses this affiliation; they lose it on revoke
idstring (uuid)obligatoirenamestringobligatoirestatusstringobligatoire- enum: "active", "paused", "archived"
createdAtstring (date-time)obligatoireupdatedAtstring (date-time)obligatoire
400invalid_credentials (with the field names) or provider_not_available
403reauth_required or permission_denied
409affiliation_label_taken
Exemples de code
curl -X POST "$KONNECT_API_URL/organisations/org_01J9Z3K4EXAMPLE0000000000/affiliations" \
-H "x-api-key: $KONNECT_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"provider": "clictopay",
"label": "default",
"environment": "sandbox",
"credentials": {}
}'Exemple : corps de la requête
{
"provider": "clictopay",
"label": "default",
"environment": "sandbox",
"credentials": {}
}Exemple : 201
{
"id": "id",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"provider": "clictopay",
"providerName": "ClicToPay",
"label": "default",
"environment": "sandbox",
"status": "draft",
"publicIdentifier": "publicIdentifier",
"credentials": {},
"credentialVersion": 1,
"verifiedAt": "2026-10-01T09:30:00.000Z",
"lastUsedAt": "2026-10-01T09:30:00.000Z",
"lastVerificationError": "lastVerificationError",
"revokedAt": "2026-10-01T09:30:00.000Z",
"paymentAccounts": [
{
"id": "id",
"name": "name",
"status": "active"
}
],
"createdAt": "2026-10-01T09:30:00.000Z",
"updatedAt": "2026-10-01T09:30:00.000Z"
}One affiliation with masked credentials
GET/organisations/{organisationId}/affiliations/{affiliationId}Clé API
Paramètres
organisationIdstringpathobligatoireaffiliationIdstringpathobligatoire
Réponses
200
idstring (uuid)obligatoireorganisationIdstring (uuid)obligatoireproviderstringobligatoire- enum: "clictopay", "flouci", "izi", "mpgs_poste", "pluxee", "kashy", "enda_tao"
providerNamestringobligatoirelabelstringobligatoireenvironmentstringobligatoire- enum: "sandbox", "production"
statusstringobligatoire- enum: "draft", "verifying", "active", "suspended", "revoked"
publicIdentifierstring | nullobligatoireNever a secret
credentialsobjectobligatoireNon-secret fields in full, secret fields as **** plus their last four characters; never a value usable at the provider
credentialVersionnumberobligatoireCurrent credential version, 1 for the first credentials
verifiedAtstring (date-time) | nullobligatoirelastUsedAtstring (date-time) | nullobligatoirelastVerificationErrorstring | nullobligatoireReadable, never a secret
revokedAtstring (date-time) | nullobligatoirepaymentAccountsRoutedPaymentAccountDto[]obligatoirePayment accounts whose routing uses this affiliation; they lose it on revoke
idstring (uuid)obligatoirenamestringobligatoirestatusstringobligatoire- enum: "active", "paused", "archived"
createdAtstring (date-time)obligatoireupdatedAtstring (date-time)obligatoire
Exemples de code
curl -X GET "$KONNECT_API_URL/organisations/org_01J9Z3K4EXAMPLE0000000000/affiliations/affiliationId" \
-H "x-api-key: $KONNECT_API_KEY"Exemple : 200
{
"id": "id",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"provider": "clictopay",
"providerName": "ClicToPay",
"label": "default",
"environment": "sandbox",
"status": "draft",
"publicIdentifier": "publicIdentifier",
"credentials": {},
"credentialVersion": 1,
"verifiedAt": "2026-10-01T09:30:00.000Z",
"lastUsedAt": "2026-10-01T09:30:00.000Z",
"lastVerificationError": "lastVerificationError",
"revokedAt": "2026-10-01T09:30:00.000Z",
"paymentAccounts": [
{
"id": "id",
"name": "name",
"status": "active"
}
],
"createdAt": "2026-10-01T09:30:00.000Z",
"updatedAt": "2026-10-01T09:30:00.000Z"
}Run the credential check again
POST/organisations/{organisationId}/affiliations/{affiliationId}/verifyClé API
Paramètres
organisationIdstringpathobligatoireaffiliationIdstringpathobligatoire
Réponses
200
idstring (uuid)obligatoireorganisationIdstring (uuid)obligatoireproviderstringobligatoire- enum: "clictopay", "flouci", "izi", "mpgs_poste", "pluxee", "kashy", "enda_tao"
providerNamestringobligatoirelabelstringobligatoireenvironmentstringobligatoire- enum: "sandbox", "production"
statusstringobligatoire- enum: "draft", "verifying", "active", "suspended", "revoked"
publicIdentifierstring | nullobligatoireNever a secret
credentialsobjectobligatoireNon-secret fields in full, secret fields as **** plus their last four characters; never a value usable at the provider
credentialVersionnumberobligatoireCurrent credential version, 1 for the first credentials
verifiedAtstring (date-time) | nullobligatoirelastUsedAtstring (date-time) | nullobligatoirelastVerificationErrorstring | nullobligatoireReadable, never a secret
revokedAtstring (date-time) | nullobligatoirepaymentAccountsRoutedPaymentAccountDto[]obligatoirePayment accounts whose routing uses this affiliation; they lose it on revoke
idstring (uuid)obligatoirenamestringobligatoirestatusstringobligatoire- enum: "active", "paused", "archived"
createdAtstring (date-time)obligatoireupdatedAtstring (date-time)obligatoire
409affiliation_revoked or invalid_transition
Exemples de code
curl -X POST "$KONNECT_API_URL/organisations/org_01J9Z3K4EXAMPLE0000000000/affiliations/affiliationId/verify" \
-H "x-api-key: $KONNECT_API_KEY"Exemple : 200
{
"id": "id",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"provider": "clictopay",
"providerName": "ClicToPay",
"label": "default",
"environment": "sandbox",
"status": "draft",
"publicIdentifier": "publicIdentifier",
"credentials": {},
"credentialVersion": 1,
"verifiedAt": "2026-10-01T09:30:00.000Z",
"lastUsedAt": "2026-10-01T09:30:00.000Z",
"lastVerificationError": "lastVerificationError",
"revokedAt": "2026-10-01T09:30:00.000Z",
"paymentAccounts": [
{
"id": "id",
"name": "name",
"status": "active"
}
],
"createdAt": "2026-10-01T09:30:00.000Z",
"updatedAt": "2026-10-01T09:30:00.000Z"
}Replace the credentials (rotation): the previous version stays until the new one verifies
PUT/organisations/{organisationId}/affiliations/{affiliationId}/credentialsClé API
Paramètres
organisationIdstringpathobligatoireaffiliationIdstringpathobligatoire
Corps de la requête application/json
credentialsobjectobligatoireThe replacement credentials, one value per field of the credentialSchema
Réponses
200
idstring (uuid)obligatoireorganisationIdstring (uuid)obligatoireproviderstringobligatoire- enum: "clictopay", "flouci", "izi", "mpgs_poste", "pluxee", "kashy", "enda_tao"
providerNamestringobligatoirelabelstringobligatoireenvironmentstringobligatoire- enum: "sandbox", "production"
statusstringobligatoire- enum: "draft", "verifying", "active", "suspended", "revoked"
publicIdentifierstring | nullobligatoireNever a secret
credentialsobjectobligatoireNon-secret fields in full, secret fields as **** plus their last four characters; never a value usable at the provider
credentialVersionnumberobligatoireCurrent credential version, 1 for the first credentials
verifiedAtstring (date-time) | nullobligatoirelastUsedAtstring (date-time) | nullobligatoirelastVerificationErrorstring | nullobligatoireReadable, never a secret
revokedAtstring (date-time) | nullobligatoirepaymentAccountsRoutedPaymentAccountDto[]obligatoirePayment accounts whose routing uses this affiliation; they lose it on revoke
idstring (uuid)obligatoirenamestringobligatoirestatusstringobligatoire- enum: "active", "paused", "archived"
createdAtstring (date-time)obligatoireupdatedAtstring (date-time)obligatoire
403reauth_required or permission_denied
422credentials_rejected: the provider refused the new credentials, the current ones stay
errorstringobligatoirereasonstringobligatoireReadable reason from the connector, never a secret
Exemples de code
curl -X PUT "$KONNECT_API_URL/organisations/org_01J9Z3K4EXAMPLE0000000000/affiliations/affiliationId/credentials" \
-H "x-api-key: $KONNECT_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"credentials": {}
}'Exemple : corps de la requête
{
"credentials": {}
}Exemple : 200
{
"id": "id",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"provider": "clictopay",
"providerName": "ClicToPay",
"label": "default",
"environment": "sandbox",
"status": "draft",
"publicIdentifier": "publicIdentifier",
"credentials": {},
"credentialVersion": 1,
"verifiedAt": "2026-10-01T09:30:00.000Z",
"lastUsedAt": "2026-10-01T09:30:00.000Z",
"lastVerificationError": "lastVerificationError",
"revokedAt": "2026-10-01T09:30:00.000Z",
"paymentAccounts": [
{
"id": "id",
"name": "name",
"status": "active"
}
],
"createdAt": "2026-10-01T09:30:00.000Z",
"updatedAt": "2026-10-01T09:30:00.000Z"
}Exemple : 422
{
"error": "credentials_rejected",
"reason": "reason"
}Suspend an active affiliation
POST/organisations/{organisationId}/affiliations/{affiliationId}/suspendClé API
Paramètres
organisationIdstringpathobligatoireaffiliationIdstringpathobligatoire
Réponses
200
idstring (uuid)obligatoireorganisationIdstring (uuid)obligatoireproviderstringobligatoire- enum: "clictopay", "flouci", "izi", "mpgs_poste", "pluxee", "kashy", "enda_tao"
providerNamestringobligatoirelabelstringobligatoireenvironmentstringobligatoire- enum: "sandbox", "production"
statusstringobligatoire- enum: "draft", "verifying", "active", "suspended", "revoked"
publicIdentifierstring | nullobligatoireNever a secret
credentialsobjectobligatoireNon-secret fields in full, secret fields as **** plus their last four characters; never a value usable at the provider
credentialVersionnumberobligatoireCurrent credential version, 1 for the first credentials
verifiedAtstring (date-time) | nullobligatoirelastUsedAtstring (date-time) | nullobligatoirelastVerificationErrorstring | nullobligatoireReadable, never a secret
revokedAtstring (date-time) | nullobligatoirepaymentAccountsRoutedPaymentAccountDto[]obligatoirePayment accounts whose routing uses this affiliation; they lose it on revoke
idstring (uuid)obligatoirenamestringobligatoirestatusstringobligatoire- enum: "active", "paused", "archived"
createdAtstring (date-time)obligatoireupdatedAtstring (date-time)obligatoire
409invalid_transition
Exemples de code
curl -X POST "$KONNECT_API_URL/organisations/org_01J9Z3K4EXAMPLE0000000000/affiliations/affiliationId/suspend" \
-H "x-api-key: $KONNECT_API_KEY"Exemple : 200
{
"id": "id",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"provider": "clictopay",
"providerName": "ClicToPay",
"label": "default",
"environment": "sandbox",
"status": "draft",
"publicIdentifier": "publicIdentifier",
"credentials": {},
"credentialVersion": 1,
"verifiedAt": "2026-10-01T09:30:00.000Z",
"lastUsedAt": "2026-10-01T09:30:00.000Z",
"lastVerificationError": "lastVerificationError",
"revokedAt": "2026-10-01T09:30:00.000Z",
"paymentAccounts": [
{
"id": "id",
"name": "name",
"status": "active"
}
],
"createdAt": "2026-10-01T09:30:00.000Z",
"updatedAt": "2026-10-01T09:30:00.000Z"
}Resume a suspended affiliation
POST/organisations/{organisationId}/affiliations/{affiliationId}/resumeClé API
Paramètres
organisationIdstringpathobligatoireaffiliationIdstringpathobligatoire
Réponses
200
idstring (uuid)obligatoireorganisationIdstring (uuid)obligatoireproviderstringobligatoire- enum: "clictopay", "flouci", "izi", "mpgs_poste", "pluxee", "kashy", "enda_tao"
providerNamestringobligatoirelabelstringobligatoireenvironmentstringobligatoire- enum: "sandbox", "production"
statusstringobligatoire- enum: "draft", "verifying", "active", "suspended", "revoked"
publicIdentifierstring | nullobligatoireNever a secret
credentialsobjectobligatoireNon-secret fields in full, secret fields as **** plus their last four characters; never a value usable at the provider
credentialVersionnumberobligatoireCurrent credential version, 1 for the first credentials
verifiedAtstring (date-time) | nullobligatoirelastUsedAtstring (date-time) | nullobligatoirelastVerificationErrorstring | nullobligatoireReadable, never a secret
revokedAtstring (date-time) | nullobligatoirepaymentAccountsRoutedPaymentAccountDto[]obligatoirePayment accounts whose routing uses this affiliation; they lose it on revoke
idstring (uuid)obligatoirenamestringobligatoirestatusstringobligatoire- enum: "active", "paused", "archived"
createdAtstring (date-time)obligatoireupdatedAtstring (date-time)obligatoire
409invalid_transition
Exemples de code
curl -X POST "$KONNECT_API_URL/organisations/org_01J9Z3K4EXAMPLE0000000000/affiliations/affiliationId/resume" \
-H "x-api-key: $KONNECT_API_KEY"Exemple : 200
{
"id": "id",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"provider": "clictopay",
"providerName": "ClicToPay",
"label": "default",
"environment": "sandbox",
"status": "draft",
"publicIdentifier": "publicIdentifier",
"credentials": {},
"credentialVersion": 1,
"verifiedAt": "2026-10-01T09:30:00.000Z",
"lastUsedAt": "2026-10-01T09:30:00.000Z",
"lastVerificationError": "lastVerificationError",
"revokedAt": "2026-10-01T09:30:00.000Z",
"paymentAccounts": [
{
"id": "id",
"name": "name",
"status": "active"
}
],
"createdAt": "2026-10-01T09:30:00.000Z",
"updatedAt": "2026-10-01T09:30:00.000Z"
}Revoke (terminal): the row stays, the credentials and their data keys are destroyed
POST/organisations/{organisationId}/affiliations/{affiliationId}/revokeClé API
Paramètres
organisationIdstringpathobligatoireaffiliationIdstringpathobligatoire
Réponses
200
idstring (uuid)obligatoireorganisationIdstring (uuid)obligatoireproviderstringobligatoire- enum: "clictopay", "flouci", "izi", "mpgs_poste", "pluxee", "kashy", "enda_tao"
providerNamestringobligatoirelabelstringobligatoireenvironmentstringobligatoire- enum: "sandbox", "production"
statusstringobligatoire- enum: "draft", "verifying", "active", "suspended", "revoked"
publicIdentifierstring | nullobligatoireNever a secret
credentialsobjectobligatoireNon-secret fields in full, secret fields as **** plus their last four characters; never a value usable at the provider
credentialVersionnumberobligatoireCurrent credential version, 1 for the first credentials
verifiedAtstring (date-time) | nullobligatoirelastUsedAtstring (date-time) | nullobligatoirelastVerificationErrorstring | nullobligatoireReadable, never a secret
revokedAtstring (date-time) | nullobligatoirepaymentAccountsRoutedPaymentAccountDto[]obligatoirePayment accounts whose routing uses this affiliation; they lose it on revoke
idstring (uuid)obligatoirenamestringobligatoirestatusstringobligatoire- enum: "active", "paused", "archived"
createdAtstring (date-time)obligatoireupdatedAtstring (date-time)obligatoire
409affiliation_revoked
Exemples de code
curl -X POST "$KONNECT_API_URL/organisations/org_01J9Z3K4EXAMPLE0000000000/affiliations/affiliationId/revoke" \
-H "x-api-key: $KONNECT_API_KEY"Exemple : 200
{
"id": "id",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"provider": "clictopay",
"providerName": "ClicToPay",
"label": "default",
"environment": "sandbox",
"status": "draft",
"publicIdentifier": "publicIdentifier",
"credentials": {},
"credentialVersion": 1,
"verifiedAt": "2026-10-01T09:30:00.000Z",
"lastUsedAt": "2026-10-01T09:30:00.000Z",
"lastVerificationError": "lastVerificationError",
"revokedAt": "2026-10-01T09:30:00.000Z",
"paymentAccounts": [
{
"id": "id",
"name": "name",
"status": "active"
}
],
"createdAt": "2026-10-01T09:30:00.000Z",
"updatedAt": "2026-10-01T09:30:00.000Z"
}Audit events of one affiliation, newest first (the owner and Konnect support)
GET/organisations/{organisationId}/affiliations/{affiliationId}/auditSession du tableau de bord
Paramètres
organisationIdstringpathobligatoireaffiliationIdstringpathobligatoirecursoranyquerylimitintegerquery- max: 200
- default: 50
actionanyquery
Réponses
200
itemsAffiliationAuditEventDto[]obligatoireidstring (uuid)obligatoireactorUserIdstring (uuid) | nullorganisationIdstring (uuid) | nullaffiliationIdstring (uuid) | nullactionstringobligatoireipstring | nulldetailsobjectobligatoirecreatedAtstring (date-time)obligatoire
nextCursorstring | nullobligatoire
Exemples de code
curl -X GET "$KONNECT_API_URL/organisations/org_01J9Z3K4EXAMPLE0000000000/affiliations/affiliationId/audit" \
-H "Cookie: konnect_session=$KONNECT_SESSION"Exemple : 200
{
"items": [
{
"id": "id",
"actorUserId": "actorUserId",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"affiliationId": "affiliationId",
"action": "affiliation.credentials_read",
"ip": "ip",
"details": {},
"createdAt": "2026-10-01T09:30:00.000Z"
}
],
"nextCursor": "nextCursor"
}