The single, secure door for external applications to read and write PayOsOne data. The PayOsOne web app and any approved third-party client both reach the same database through this API layer — the database itself is never exposed.
The existing web application keeps working unchanged through the platform SDK. External apps go through the REST API. Both share exactly one database.
All requests are POST to a single gateway endpoint, with the HTTP method and path described in the JSON body:
POST https://dnx-pulse-os.base44.app/functions/payosoneApi
{
"method": "GET",
"path": "/v1/businesses",
"query": { "limit": 20 },
"body": { }, // for POST/PUT
"apiKey": "pyo_live_..." // or use the Authorization header
}Alternatively pass the key via a header: Authorization: Bearer pyo_live_…
Every request (except /v1/health) requires a valid API key. Keys are issued by a PayOsOne admin from the panel below. The raw key is shown once at creation; only its SHA-256 hash is stored. Keys carry scopes and may be scoped to a single business (business_id) or platform-level (blank) for cross-business access.
A scoped key (with a business_id) only ever sees its own business's records — enforced server-side.
Each key is limited to 120 requests per 60 seconds by default (configurable per key). Exceeding it returns 429 rate_limited.
All errors use a consistent shape:
{
"error": {
"code": "insufficient_scope",
"message": "Missing required scope: businesses:write"
}
}Status codes: 400 validation, 401 auth, 403 scope/tenant, 404 route/resource, 429 rate limit, 500 server.
Every API call is recorded in the AuditLog entity with the key name, method, path and severity. Denied calls (missing scope) are logged at warning severity.
curl -X POST https://dnx-pulse-os.base44.app/functions/payosoneApi \
-H "Authorization: Bearer pyo_live_..." \
-H "Content-Type: application/json" \
-d '{ "method": "GET", "path": "/v1/businesses", "query": { "limit": 5 } }'
→ 200
{
"data": [ { "id": "...", "business_name": "...", "tenant_id": "TEN-..." } ],
"count": 1,
"limit": 5
}/v1/businessesList business/merchant profiles (scoped to the key's business)
/v1/businesses/:idRetrieve a single business profile
/v1/businessesCreate a new business profile
/v1/businesses/:idUpdate a business profile
/v1/businesses/:id/performanceAggregated business performance (sales, expenses, net)
/v1/businesses/:id/earningsMerchant earnings summary + recent sales
/v1/business-profilesAlias for /v1/businesses
/v1/transactionsList finance transactions for the business
/v1/transactions/:idRetrieve a single transaction
/v1/transactionsRecord a new finance transaction
/v1/paymentsList payment-type transactions
/v1/transfersList transfer-type transactions
/v1/productsList products for the business
/v1/products/:idRetrieve a single product
/v1/servicesList published service offerings
/v1/services/:idRetrieve a single service offering
/v1/ordersList orders (platform key only)
/v1/orders/:idRetrieve a single order (platform key only)
/v1/usersList platform users (platform key only)
/v1/users/:idRetrieve a single user (platform key only)
/v1/rolesList roles & permissions (platform key only)
/v1/audit-recordsList audit log entries (scoped to the business)
/v1/devicesList connected devices / terminals
/v1/devices/:idRetrieve a single device
Issue, inspect and revoke API keys. Admin access required.
No API keys yet.