v1 · stable

PayOsOne REST API

The single, secure door for external applications to read and write PayOsOne data. The PayOsOne web app and any approved third-party client both reach the same database through this API layer — the database itself is never exposed.

Architecture

PayOsOne Web App (existing)
Other Approved Applications
↓   authenticated HTTPS
PayOsOne Backend / API (v1)
↓   service-role entity access
PayOsOne Database (one source of truth)

The existing web application keeps working unchanged through the platform SDK. External apps go through the REST API. Both share exactly one database.

Base URL & calling convention

All requests are POST to a single gateway endpoint, with the HTTP method and path described in the JSON body:

POST https://dnx-pulse-os.base44.app/functions/payosoneApi

{
  "method": "GET",
  "path":   "/v1/businesses",
  "query":  { "limit": 20 },
  "body":   { },            // for POST/PUT
  "apiKey": "pyo_live_..."  // or use the Authorization header
}

Alternatively pass the key via a header: Authorization: Bearer pyo_live_…

Authentication

Every request (except /v1/health) requires a valid API key. Keys are issued by a PayOsOne admin from the panel below. The raw key is shown once at creation; only its SHA-256 hash is stored. Keys carry scopes and may be scoped to a single business (business_id) or platform-level (blank) for cross-business access.

Authorization scopes

businesses:readbusinesses:writetransactions:readtransactions:writeproducts:readorders:readusers:readroles:readaudit:readconnectivity:read* (all scopes)

A scoped key (with a business_id) only ever sees its own business's records — enforced server-side.

Rate limiting

Each key is limited to 120 requests per 60 seconds by default (configurable per key). Exceeding it returns 429 rate_limited.

Errors

All errors use a consistent shape:

{
  "error": {
    "code": "insufficient_scope",
    "message": "Missing required scope: businesses:write"
  }
}

Status codes: 400 validation, 401 auth, 403 scope/tenant, 404 route/resource, 429 rate limit, 500 server.

Audit logging

Every API call is recorded in the AuditLog entity with the key name, method, path and severity. Denied calls (missing scope) are logged at warning severity.

Example: list businesses

curl -X POST https://dnx-pulse-os.base44.app/functions/payosoneApi \
  -H "Authorization: Bearer pyo_live_..." \
  -H "Content-Type: application/json" \
  -d '{ "method": "GET", "path": "/v1/businesses", "query": { "limit": 5 } }'

→ 200
{
  "data": [ { "id": "...", "business_name": "...", "tenant_id": "TEN-..." } ],
  "count": 1,
  "limit": 5
}

Endpoint reference

Businesses & Merchants

businesses:readbusinesses:write
GET
/v1/businesses

List business/merchant profiles (scoped to the key's business)

GET
/v1/businesses/:id

Retrieve a single business profile

POST
/v1/businesses

Create a new business profile

PUT
/v1/businesses/:id

Update a business profile

GET
/v1/businesses/:id/performance

Aggregated business performance (sales, expenses, net)

GET
/v1/businesses/:id/earnings

Merchant earnings summary + recent sales

GET
/v1/business-profiles

Alias for /v1/businesses

Transactions, Payments & Transfers

transactions:readtransactions:write
GET
/v1/transactions

List finance transactions for the business

GET
/v1/transactions/:id

Retrieve a single transaction

POST
/v1/transactions

Record a new finance transaction

GET
/v1/payments

List payment-type transactions

GET
/v1/transfers

List transfer-type transactions

Products, Services & Orders

products:readorders:read
GET
/v1/products

List products for the business

GET
/v1/products/:id

Retrieve a single product

GET
/v1/services

List published service offerings

GET
/v1/services/:id

Retrieve a single service offering

GET
/v1/orders

List orders (platform key only)

GET
/v1/orders/:id

Retrieve a single order (platform key only)

Users, Roles & Audit

users:readroles:readaudit:read
GET
/v1/users

List platform users (platform key only)

GET
/v1/users/:id

Retrieve a single user (platform key only)

GET
/v1/roles

List roles & permissions (platform key only)

GET
/v1/audit-records

List audit log entries (scoped to the business)

Connectivity

connectivity:read
GET
/v1/devices

List connected devices / terminals

GET
/v1/devices/:id

Retrieve a single device

API key management (admin)

Issue, inspect and revoke API keys. Admin access required.

Authentication required to view users

Issue a new API key

Existing keys

No API keys yet.

PayOsOne API v1 · One database · One backend · Secure by design