API reference
WinkPG API version v1. 730 endpoints published by this instance.
The API reference isn't available right now
This instance couldn't load its API specification, so this page lists nothing. The reference returns as soon as the specification is readable again.
This reference may be out of date
This instance couldn't reach its API specification on the last attempt, so this page shows the copy fetched before that. Anything added or changed since then is missing here, and the reference updates itself as soon as the specification is readable again. Last fetched 2026-10-01 06:25 UTC.
This instance publishes no API operations.
Identity & Access
Account
Sign-in account self-service: registration, password reset, email and phone confirmation, and profile management.
- POST
/api/account/confirm-emaildeprecated Confirm email address No permission required. - POST
/api/account/confirm-phone-numberdeprecated Confirm phone number No permission required. - GET
/api/account/confirmation-statedeprecated Get account confirmation state No permission required. - POST
/api/account/profile-picturedeprecated Set profile picture No permission required. - GET
/api/account/profile-picture-file/{id}deprecated GetProfilePictureFile for Account No permission required. - GET
/api/account/profile-picture/{id}deprecated Get profile picture No permission required. - GET
/api/account/recaptcha-validatedeprecated Recaptcha for Account No permission required. - POST
/api/account/registerdeprecated Register new account No permission required. - POST
/api/account/reset-passworddeprecated Reset password No permission required. - GET
/api/account/security-logsdeprecated Get security logs No permission required. - POST
/api/account/send-email-confirmation-tokendeprecated Send email confirmation token No permission required. - POST
/api/account/send-password-reset-codedeprecated Send password reset code No permission required. - POST
/api/account/send-phone-number-confirmation-tokendeprecated Send phone confirmation token No permission required. - POST
/api/account/verify-email-confirmation-tokendeprecated Verify email confirmation token No permission required. - POST
/api/account/verify-password-reset-tokendeprecated Verify password reset token No permission required. - POST
/api/app/account/send-password-reset-code-with-usernamedeprecated SendPasswordResetCodeWithUsername for Account No permission required. - GET
/api/account/my-profiledeprecated Get user profile No permission required. - PUT
/api/account/my-profiledeprecated Update user profile No permission required. - POST
/api/account/my-profile/change-passworddeprecated Change password No permission required. - POST
/api/account/my-profile/set-two-factor-enableddeprecated SetTwoFactorEnabled for Profile No permission required. - GET
/api/account/my-profile/timezonesdeprecated GetTimezones for Profile No permission required. - GET
/api/account/my-profile/two-factor-enableddeprecated GetTwoFactorEnabled for Profile No permission required. - GET
/api/app/wink-pg-profiledeprecated No permission required. - PUT
/api/app/wink-pg-profiledeprecated No permission required. - POST
/api/app/wink-pg-profile/can-enable-two-factordeprecated No permission required. - POST
/api/app/wink-pg-profile/change-passworddeprecated No permission required. - POST
/api/app/wink-pg-profile/set-two-factor-enableddeprecated No permission required. - GET
/api/app/wink-pg-profile/timezonesdeprecated No permission required. - GET
/api/app/wink-pg-profile/two-factor-enableddeprecated No permission required.
Platform Configuration
Accounting OAuth
Connecting a merchant to an accounting provider over OAuth, and completing the provider's callback.
Messaging & Notifications
Announcements
System announcements and banner management.
- GET
/api/announcementsdeprecated Get a list of Announcements Requires: Announcements.Management, merchant scope. - POST
/api/announcementsdeprecated Create an Announcement Requires: Announcements.Management, Announcements.Management.Create, merchant scope. - POST
/api/announcements/disable-asyncdeprecated Disables an announcement. Requires: Announcements.Management, Announcements.Management.Update, merchant scope. - POST
/api/announcements/duplicate-asyncdeprecated Duplicates an existing announcement with a new title. Requires: Announcements.Management, Announcements.Management.Create, merchant scope. - POST
/api/announcements/enable-asyncdeprecated Enables an announcement. Requires: Announcements.Management, Announcements.Management.Update, merchant scope. - GET
/api/announcements/templatesdeprecated Get a list of AnnouncementTemplates Requires: Announcements.Management, merchant scope. - POST
/api/announcements/templatesdeprecated Create an AnnouncementTemplate Requires: Announcements.Management, Announcements.Management.Create, merchant scope. - GET
/api/announcements/templates/picker-listdeprecated Lists every template as an id and a name. Requires: Announcements.Management, merchant scope. - DELETE
/api/announcements/templates/{id}deprecated Delete an AnnouncementTemplate Requires: Announcements.Management, Announcements.Management.Delete, merchant scope. - GET
/api/announcements/templates/{id}deprecated Get an AnnouncementTemplate Requires: Announcements.Management, merchant scope. - PUT
/api/announcements/templates/{id}deprecated Update an AnnouncementTemplate Requires: Announcements.Management, Announcements.Management.Update, merchant scope. - GET
/api/announcements/templates/{id}/accessdeprecated Check AnnouncementTemplate access Requires: Announcements.Management, merchant scope. - GET
/api/announcements/templates/{id}/namedeprecated Get an AnnouncementTemplate name by id Requires: Announcements.Management, merchant scope. - POST
/api/announcements/templates/{id}/restoredeprecated Restore a deleted AnnouncementTemplate Requires: Announcements.Management, Announcements.Management.Update, merchant scope. - DELETE
/api/announcements/{id}deprecated Delete an Announcement Requires: Announcements.Management, Announcements.Management.Delete, merchant scope. - GET
/api/announcements/{id}deprecated Get an Announcement Requires: Announcements.Management, merchant scope. - PATCH
/api/announcements/{id}deprecated Partially update an Announcement Requires: Announcements.Management, Announcements.Management.Update, merchant scope. - PUT
/api/announcements/{id}deprecated Update an Announcement Requires: Announcements.Management, Announcements.Management.Update, merchant scope. - GET
/api/announcements/{id}/accessdeprecated Check Announcement access Requires: Announcements.Management, merchant scope. - GET
/api/announcements/{id}/engagement-statsdeprecated Gets engagement statistics for a specific announcement. Requires: Announcements.Management, merchant scope. - GET
/api/announcements/{id}/namedeprecated Get an Announcement name by id Requires: Announcements.Management, merchant scope. - POST
/api/announcements/{id}/restoredeprecated Restore a deleted Announcement Requires: Announcements.Management, Announcements.Management.Update, merchant scope. - GET
/api/announcements/userdeprecated Gets announcements for the current user, ordered by priority and date. Requires: Announcements.View, merchant scope. - POST
/api/announcements/user/dismiss-alldeprecated Dismisses all announcements for the current user. Requires: Announcements.View, merchant scope. - POST
/api/announcements/user/mark-many-as-readdeprecated Marks multiple announcements as read for the current user. Requires: Announcements.View, merchant scope. - GET
/api/announcements/user/pending-popupsdeprecated Gets announcements that need to display a popup to the current user. Requires: Announcements.View, merchant scope. - GET
/api/announcements/user/unread-countdeprecated Gets the count of unread announcements for the current user. Requires: Announcements.View, merchant scope. - POST
/api/announcements/user/{announcementId}/dismissdeprecated Dismisses an announcement for the current user. Requires: Announcements.View, merchant scope. - POST
/api/announcements/user/{announcementId}/mark-as-readdeprecated Marks an announcement as read for the current user. Requires: Announcements.View, merchant scope. - POST
/api/announcements/user/{announcementId}/record-popup-showndeprecated Records that a popup was shown to the current user for the specified announcement. Requires: Announcements.View, merchant scope.
Identity & Access
API Keys
API key lifecycle for programmatic access: issuing a key, revealing it once, rotating it, and deactivating or deleting it.
- GET
/api/api-keysdeprecated List API keys Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - POST
/api/api-keysdeprecated Create API key Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - GET
/api/api-keys/approximate-countdeprecated Gets the approximate total count of API keys based on the provided input. Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - GET
/api/api-keys/continuation-listdeprecated Gets a continuation list of API keys based on the provided input. Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - POST
/api/api-keys/revealdeprecated CreateAndReveal for ApiKeys Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - DELETE
/api/api-keys/{id}deprecated Delete API key Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - GET
/api/api-keys/{id}deprecated Get API key Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - PUT
/api/api-keys/{id}deprecated Update API key Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - GET
/api/api-keys/{id}/detaildeprecated Get an API key's details Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - GET
/api/api-keys/{id}/has-accessdeprecated Checks if the caller may access the API key. Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - GET
/api/api-keys/{id}/namedeprecated Gets the name of the API key by id. Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - POST
/api/api-keys/{id}/reinstatedeprecated Reinstate a suspended API key Requires: ApiKeyAuthorization.ApiKeys, ApiKeyAuthorization.ApiKeys.Suspend, merchant scope. - POST
/api/api-keys/{id}/restoredeprecated Restores a deleted API key item by id. Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - POST
/api/api-keys/{id}/revokedeprecated Revoke an API key Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - POST
/api/api-keys/{id}/rotatedeprecated Rotate an API key Requires: ApiKeyAuthorization.ApiKeys, merchant scope. - POST
/api/api-keys/{id}/suspenddeprecated Suspend an API key Requires: ApiKeyAuthorization.ApiKeys, ApiKeyAuthorization.ApiKeys.Suspend, merchant scope. - POST
/api/api-keys/for-userdeprecated Create and reveal an API key for a merchant user. Requires: ApiKeyAuthorization.ApiKeys.CreateForUser, merchant scope.
Reporting & Operations
Audit Log
The platform audit trail: who changed what, when, and from where, paged with continuation tokens.
- GET
/api/app/audit-log-continuation/approximate-total-countdeprecated Counts the entities matching `input`. Requires: AuditLogging.AuditLogs, merchant scope. - GET
/api/app/audit-log-continuation/continuation-listdeprecated Requires: AuditLogging.AuditLogs, merchant scope. - GET
/api/app/audit-log-continuation/summary-countsdeprecated Requires: AuditLogging.AuditLogs, merchant scope. - POST
/api/app/audit-log-continuation/{id}/ensure-entity-accessdeprecated Requires: AuditLogging.AuditLogs, merchant scope. - POST
/api/app/audit-log-continuation/{id}/try-ensure-entity-accessdeprecated Requires: AuditLogging.AuditLogs, merchant scope.
Payments
Campaigns
Group payment links into a campaign with one status, one schedule and one report.
- GET
/api/campaignsdeprecated Get a list of Campaigns Requires: Campaigns.Campaigns, merchant scope. - POST
/api/campaignsdeprecated Create a Campaign Requires: Campaigns.Campaigns, Campaigns.Campaigns.Create, merchant scope. - POST
/api/campaigns/list/continuationdeprecated Retrieves a continuation-based page of Campaigns. Requires: Campaigns.Campaigns, merchant scope. - POST
/api/campaigns/list/continuation/countdeprecated Counts the Campaigns that match a filter. Requires: Campaigns.Campaigns, merchant scope. - POST
/api/campaigns/list/continuation/summary-countsdeprecated Counts Campaigns for several filters at once. Requires: Campaigns.Campaigns, merchant scope. - DELETE
/api/campaigns/{id}deprecated Delete a Campaign Requires: Campaigns.Campaigns, Campaigns.Campaigns.Delete, merchant scope. - GET
/api/campaigns/{id}deprecated Get a Campaign Requires: Campaigns.Campaigns, merchant scope. - PUT
/api/campaigns/{id}deprecated Update a Campaign Requires: Campaigns.Campaigns, Campaigns.Campaigns.Update, merchant scope. - GET
/api/campaigns/{id}/accessdeprecated Check Campaign access Requires: Campaigns.Campaigns, merchant scope. - POST
/api/campaigns/{id}/activatedeprecated Moves a draft campaign to active. Requires: Campaigns.Campaigns, Campaigns.Campaigns.ManageStatus, merchant scope. - POST
/api/campaigns/{id}/archivedeprecated Retires a campaign from the working set. Requires: Campaigns.Campaigns, Campaigns.Campaigns.ManageStatus, merchant scope. - POST
/api/campaigns/{id}/clonedeprecated Creates a new draft campaign from an existing one, for running the same campaign again. Requires: Campaigns.Campaigns, Campaigns.Campaigns.Create, merchant scope. - POST
/api/campaigns/{id}/enddeprecated Ends a running or paused campaign. Requires: Campaigns.Campaigns, Campaigns.Campaigns.ManageStatus, merchant scope. - GET
/api/campaigns/{id}/namedeprecated Get a Campaign name by id Requires: Campaigns.Campaigns, merchant scope. - POST
/api/campaigns/{id}/pausedeprecated Suspends a running campaign. No member link's own status is touched. Requires: Campaigns.Campaigns, Campaigns.Campaigns.ManageStatus, merchant scope. - GET
/api/campaigns/{id}/progressdeprecated Reads a campaign's public progress. No permission required. - POST
/api/campaigns/{id}/restoredeprecated Restore a deleted Campaign Requires: Campaigns.Campaigns, Campaigns.Campaigns.Update, merchant scope. - POST
/api/campaigns/{id}/resumedeprecated Returns a paused campaign to active. Requires: Campaigns.Campaigns, Campaigns.Campaigns.ManageStatus, merchant scope.
Customers & Contracts
Contract Plans
Reusable plans that recurring contracts subscribe to for their price.
- GET
/api/contract-plansdeprecated Get a list of ContractPlans Requires: Customers.ContractPlans, merchant scope. - POST
/api/contract-plansdeprecated Create a ContractPlan Requires: Customers.ContractPlans, Customers.ContractPlans.Create, merchant scope. - POST
/api/contract-plans/list/continuationdeprecated Retrieves a continuation-based page of ContractPlans. Requires: Customers.ContractPlans, merchant scope. - POST
/api/contract-plans/list/continuation/countdeprecated Counts the ContractPlans that match a filter. Requires: Customers.ContractPlans, merchant scope. - POST
/api/contract-plans/list/continuation/summary-countsdeprecated Counts ContractPlans for several filters at once. Requires: Customers.ContractPlans, merchant scope. - GET
/api/contract-plans/lookupdeprecated Lists the active plans the caller may subscribe a contract to, with today's price on each. Requires: Customers.ContractPlans, merchant scope. - DELETE
/api/contract-plans/{id}deprecated Delete a ContractPlan Requires: Customers.ContractPlans, Customers.ContractPlans.Delete, merchant scope. - GET
/api/contract-plans/{id}deprecated Get a ContractPlan Requires: Customers.ContractPlans, merchant scope. - PUT
/api/contract-plans/{id}deprecated Update a ContractPlan Requires: Customers.ContractPlans, Customers.ContractPlans.Update, merchant scope. - GET
/api/contract-plans/{id}/accessdeprecated Check ContractPlan access Requires: Customers.ContractPlans, merchant scope. - GET
/api/contract-plans/{id}/namedeprecated Get a ContractPlan name by id Requires: Customers.ContractPlans, merchant scope. - POST
/api/contract-plans/{id}/pricesdeprecated Records a new price on a plan and states when it starts applying to existing subscribers. Requires: Customers.ContractPlans, Customers.ContractPlans.ChangePrice, merchant scope. - POST
/api/contract-plans/{id}/restoredeprecated Restore a deleted ContractPlan Requires: Customers.ContractPlans, Customers.ContractPlans.Delete, merchant scope.
Customers & Contracts
Contracts
Customer contract and billing agreement management.
- GET
/api/contractsdeprecated List contracts Requires: Customers.Contracts, merchant scope. - POST
/api/contractsdeprecated Create contract Requires: Customers.Contracts, Customers.Contracts.Create, merchant scope. - POST
/api/contracts/list/continuationdeprecated Retrieves a continuation-based page of Contracts. Requires: Customers.Contracts, merchant scope. - POST
/api/contracts/list/continuation/countdeprecated Counts the Contracts that match a filter. Requires: Customers.Contracts, merchant scope. - POST
/api/contracts/list/continuation/summary-countsdeprecated Counts Contracts for several filters at once. Requires: Customers.Contracts, merchant scope. - DELETE
/api/contracts/{id}deprecated Delete contract Requires: Customers.Contracts, Customers.Contracts.Delete, merchant scope. - GET
/api/contracts/{id}deprecated Get contract by ID Requires: Customers.Contracts, merchant scope. - PUT
/api/contracts/{id}deprecated Update contract Requires: Customers.Contracts, Customers.Contracts.Update, merchant scope. - GET
/api/contracts/{id}/accessdeprecated Check contract access Requires: Customers.Contracts, merchant scope. - GET
/api/contracts/{id}/namedeprecated Get contract name Requires: Customers.Contracts, merchant scope. - POST
/api/contracts/{id}/pausedeprecated Pauses an active contract. Requires: Customers.Contracts, Customers.Contracts.Update, merchant scope. - POST
/api/contracts/{id}/restoredeprecated Restore deleted contract Requires: Customers.Contracts, Customers.Contracts.Delete, merchant scope. - POST
/api/contracts/{id}/resumedeprecated Resumes a paused contract. Requires: Customers.Contracts, Customers.Contracts.Update, merchant scope.
Customers & Contracts
Customers
Customer profile management, payment methods, and contact details.
- GET
/api/customersdeprecated List customers Requires: Customers.Customers, merchant scope. - POST
/api/customersdeprecated Create customer Requires: Customers.Customers, Customers.Customers.Create, merchant scope. - POST
/api/customers/add-stored-payment-method-asyncdeprecated Adds a new stored payment method to a customer's collection and persists it. Requires: Customers.Customers, Customers.Customers.Create, merchant scope. - POST
/api/customers/delete-stored-payment-method-asyncdeprecated Soft-deletes a stored payment method from a customer. Requires: Customers.Customers, Customers.Customers.Delete, merchant scope. - POST
/api/customers/list/continuationdeprecated Retrieves a continuation-based page of Customers. Requires: Customers.Customers, merchant scope. - POST
/api/customers/list/continuation/countdeprecated Counts the Customers that match a filter. Requires: Customers.Customers, merchant scope. - POST
/api/customers/list/continuation/summary-countsdeprecated Counts Customers for several filters at once. Requires: Customers.Customers, merchant scope. - DELETE
/api/customers/{id}deprecated Delete customer Requires: Customers.Customers, Customers.Customers.Delete, merchant scope. - GET
/api/customers/{id}deprecated Get customer by ID Requires: Customers.Customers, merchant scope. - PUT
/api/customers/{id}deprecated Update customer Requires: Customers.Customers, Customers.Customers.Update, merchant scope. - GET
/api/customers/{id}/accessdeprecated Check customer access Requires: Customers.Customers, merchant scope. - GET
/api/customers/{id}/namedeprecated Get customer name Requires: Customers.Customers, merchant scope. - POST
/api/customers/{id}/restoredeprecated Restore deleted customer Requires: Customers.Customers, merchant scope.
Identity & Access
Developer Portal
Back-office management of Developer Portal access: the accounts that grant it and the invitations that offer it. Every operation is scoped to the acting merchant.
- POST
/api/developer-portal/accountsdeprecated Create a DeveloperAccount Requires: DeveloperPortal.Accounts, DeveloperPortal.Accounts.Create, merchant scope. - GET
/api/developer-portal/accounts/assignable-usersdeprecated Lists the users who can be granted portal access for the current merchant. Requires: DeveloperPortal.Accounts, DeveloperPortal.Accounts.Create, merchant scope. - POST
/api/developer-portal/accounts/list/continuationdeprecated Retrieves a continuation-based page of DeveloperAccounts. Requires: DeveloperPortal.Accounts, merchant scope. - POST
/api/developer-portal/accounts/list/continuation/countdeprecated Counts the DeveloperAccounts that match a filter. Requires: DeveloperPortal.Accounts, merchant scope. - POST
/api/developer-portal/accounts/list/continuation/summary-countsdeprecated Counts DeveloperAccounts for several filters at once. Requires: DeveloperPortal.Accounts, merchant scope. - DELETE
/api/developer-portal/accounts/{id}deprecated Delete a DeveloperAccount Requires: DeveloperPortal.Accounts, DeveloperPortal.Accounts.Delete, merchant scope. - GET
/api/developer-portal/accounts/{id}deprecated Get a DeveloperAccount Requires: DeveloperPortal.Accounts, merchant scope. - PUT
/api/developer-portal/accounts/{id}deprecated Update a DeveloperAccount Requires: DeveloperPortal.Accounts, DeveloperPortal.Accounts.Update, merchant scope. - GET
/api/developer-portal/accounts/{id}/accessdeprecated Check DeveloperAccount access Requires: DeveloperPortal.Accounts, merchant scope. - GET
/api/developer-portal/accounts/{id}/namedeprecated Get a DeveloperAccount name by id Requires: DeveloperPortal.Accounts, merchant scope. - POST
/api/developer-portal/accounts/{id}/restoredeprecated Restore a deleted DeveloperAccount Requires: DeveloperPortal.Accounts, DeveloperPortal.Accounts.Create, merchant scope. - POST
/api/developer-portal/invitationsdeprecated Issues an invitation and emails its redemption link to the invited party. Requires: DeveloperPortal.Invitations, DeveloperPortal.Invitations.Create, merchant scope. - GET
/api/developer-portal/invitations/invitable-usersdeprecated Lists the users the caller may invite for the acting merchant. Requires: DeveloperPortal.Invitations, DeveloperPortal.Invitations.Create, merchant scope. - POST
/api/developer-portal/invitations/list/continuationdeprecated Retrieves a continuation-based page of the acting merchant's invitations. Requires: DeveloperPortal.Invitations, merchant scope. - POST
/api/developer-portal/invitations/list/continuation/countdeprecated Counts the invitations that match a filter. Requires: DeveloperPortal.Invitations, merchant scope. - POST
/api/developer-portal/invitations/list/continuation/summary-countsdeprecated Counts invitations for several filters at once. Requires: DeveloperPortal.Invitations, merchant scope. - GET
/api/developer-portal/invitations/{id}deprecated Reads one of the acting merchant's invitations. Requires: DeveloperPortal.Invitations, merchant scope. - POST
/api/developer-portal/invitations/{id}/revokedeprecated Withdraws a pending invitation, so its link stops working. Requires: DeveloperPortal.Invitations, DeveloperPortal.Invitations.Delete, merchant scope.
Reporting & Operations
Health Checks
Platform health: the overall status, and the state of the individual components behind it.
- GET
/api/healthdeprecated Returns overall health status. No permission required. - GET
/api/health/category/{category}deprecated Returns health checks for a specific category. Requires: HealthChecks.HealthChecks, merchant scope. - GET
/api/health/components/{name}deprecated Returns health status for a specific component by name. Requires: HealthChecks.HealthChecks, merchant scope. - GET
/api/health/groupsdeprecated Returns health checks grouped by category with per-group aggregate status. Requires: HealthChecks.HealthChecks, merchant scope.
Payments
Hosted Payment Pages
Hosted payment pages: the checkout pages WinkPG hosts on a merchant's behalf, their branding and field configuration, and the sessions a shopper is sent to.
- POST
/api/hosted-payment-page/interactionsdeprecated Records a single client interaction beacon. No permission required. - GET
/api/hostedpaymentpagesdeprecated List hosted payment pages Requires: HostedPaymentPage.HostedPaymentPages, merchant scope. - POST
/api/hostedpaymentpagesdeprecated Create hosted payment page Requires: HostedPaymentPage.HostedPaymentPages, HostedPaymentPage.HostedPaymentPages.Create, merchant scope. - POST
/api/hostedpaymentpages/create-save-card-capture-asyncdeprecated Creates a ready-to-use Save Card page for storing a card on file. Requires: HostedPaymentPage.HostedPaymentPages, HostedPaymentPage.HostedPaymentPages.Create, merchant scope. - POST
/api/hostedpaymentpages/images/uploaddeprecated Uploads a banner or product image. Requires: HostedPaymentPage.HostedPaymentPages.Update, merchant scope. - POST
/api/hostedpaymentpages/list/continuationdeprecated Retrieves a continuation-based page of HostedPaymentPages. Requires: HostedPaymentPage.HostedPaymentPages, merchant scope. - POST
/api/hostedpaymentpages/list/continuation/countdeprecated Counts the HostedPaymentPages that match a filter. Requires: HostedPaymentPage.HostedPaymentPages, merchant scope. - POST
/api/hostedpaymentpages/list/continuation/summary-countsdeprecated Counts HostedPaymentPages for several filters at once. Requires: HostedPaymentPage.HostedPaymentPages, merchant scope. - POST
/api/hostedpaymentpages/lock-asyncdeprecated Locks the page against deletion and against changes to its billing-critical fields. Requires: HostedPaymentPage.HostedPaymentPages, HostedPaymentPage.HostedPaymentPages.Lock, merchant scope. - GET
/api/hostedpaymentpages/sessionsdeprecated Lists HPP sessions for a specific hosted payment page. Requires: HostedPaymentPage.HppSessions, merchant scope. - POST
/api/hostedpaymentpages/sessionsdeprecated Creates a new HPP session with pre-populated field data. Requires: HostedPaymentPage.HppSessions, HostedPaymentPage.HppSessions.Create, merchant scope. - GET
/api/hostedpaymentpages/sessions/{sessionId}/clone-datadeprecated Retrieves the full prefilled field data for an existing session for cloning. Requires: HostedPaymentPage.HppSessions, HostedPaymentPage.HppSessions.Create, merchant scope. - GET
/api/hostedpaymentpages/sessions/{sessionId}/completionsdeprecated Lists the completions of one reusable payment link: one row per payer who arrived on it. Requires: HostedPaymentPage.HppSessions, merchant scope. - GET
/api/hostedpaymentpages/sessions/{sessionId}/level3-datadeprecated Returns the Level 3 commercial-card payload stored on a session. Requires: HostedPaymentPage.HppSessions, HostedPaymentPage.HppSessions.Create, merchant scope. - POST
/api/hostedpaymentpages/sessions/{sessionId}/pausedeprecated Pauses a payment link. Requires: HostedPaymentPage.HppSessions, HostedPaymentPage.HppSessions.Create, merchant scope. - GET
/api/hostedpaymentpages/sessions/{sessionId}/payment-linkdeprecated Returns the canonical payment-link URL for a session. Requires: HostedPaymentPage.HppSessions, merchant scope. - GET
/api/hostedpaymentpages/sessions/{sessionId}/qrcode.pngdeprecated Serves a QR code PNG image for the session's payment link. Requires: HostedPaymentPage.HppSessions, merchant scope. - POST
/api/hostedpaymentpages/sessions/{sessionId}/reconcile-completionsdeprecated Recomputes a reusable link's completion count from its own completions. Requires: HostedPaymentPage.HppSessions, HostedPaymentPage.HppSessions.Create, merchant scope. - POST
/api/hostedpaymentpages/sessions/{sessionId}/resumedeprecated Resumes a paused payment link. Requires: HostedPaymentPage.HppSessions, HostedPaymentPage.HppSessions.Create, merchant scope. - POST
/api/hostedpaymentpages/sessions/{sessionId}/revokedeprecated Revokes an active HPP session so it can no longer be used. Requires: HostedPaymentPage.HppSessions, HostedPaymentPage.HppSessions.Delete, merchant scope. - POST
/api/hostedpaymentpages/sessions/{sessionId}/send-linkdeprecated Sends an HPP session payment link to a recipient via email. Requires: HostedPaymentPage.HppSessions, HostedPaymentPage.HppSessions.Create, merchant scope. - POST
/api/hostedpaymentpages/unlock-asyncdeprecated Removes the lock from a page. Requires: HostedPaymentPage.HostedPaymentPages, HostedPaymentPage.HostedPaymentPages.Unlock, merchant scope. - DELETE
/api/hostedpaymentpages/{id}deprecated Delete hosted payment page Requires: HostedPaymentPage.HostedPaymentPages, HostedPaymentPage.HostedPaymentPages.Delete, merchant scope. - GET
/api/hostedpaymentpages/{id}deprecated Get hosted payment page Requires: HostedPaymentPage.HostedPaymentPages, merchant scope. - PUT
/api/hostedpaymentpages/{id}deprecated Update hosted payment page Requires: HostedPaymentPage.HostedPaymentPages, HostedPaymentPage.HostedPaymentPages.Update, merchant scope. - GET
/api/hostedpaymentpages/{id}/accessdeprecated Check page access Requires: HostedPaymentPage.HostedPaymentPages, merchant scope. - GET
/api/hostedpaymentpages/{id}/namedeprecated Get page name Requires: HostedPaymentPage.HostedPaymentPages, merchant scope. - POST
/api/hostedpaymentpages/{id}/restoredeprecated Restore deleted page Requires: HostedPaymentPage.HostedPaymentPages, merchant scope. - POST
/api/hpp/csp-reportdeprecated Accepts a single CSP violation report. No permission required. - GET
/sdk/core/manifest.jsondeprecated Publishes the release this host serves. No permission required. - GET
/sdk/core/{version}/{fingerprint}/{file}deprecated Serves one published artifact. No permission required. - GET
/sdk/sample/{product}.zipdeprecated Serves the sample for the given SDK product, preconfigured for this environment and brand. No permission required. - GET
/sdk/v1/{product}.jsdeprecated Serves the shim for the given SDK product. No permission required.
Messaging & Notifications
Inbound Sms Message
Operator access to the inbound SMS log: what recipients replied, and honoring a free-text opt-out that no automated keyword rule interprets.
Billing & Invoicing
Invoicing
Invoice generation, tracking, and payment reconciliation.
- GET
/api/invoicing/exports/invoices/csvdeprecated Invoices: Exports the filtered invoice list as CSV. Requires: Invoicing.Invoices, merchant scope. - GET
/api/invoicing/exports/invoices/exceldeprecated Invoices: Exports the filtered invoice list as an Excel workbook. Requires: Invoicing.Invoices, merchant scope. - GET
/api/invoicing/invoicesdeprecated Invoices: Retrieves a continuation-token paged, filtered list of invoices. Requires: Invoicing.Invoices, merchant scope. - POST
/api/invoicing/invoicesdeprecated Invoices: Creates a new draft invoice. Requires: Invoicing.Invoices, Invoicing.Invoices.Create, merchant scope. - POST
/api/invoicing/invoices/tax-rate-lookupdeprecated Invoices: Looks up a line's sales-tax rate from the merchant biller's tax provider. Requires: Invoicing.Invoices, merchant scope. - DELETE
/api/invoicing/invoices/{id}deprecated Invoices: Deletes a draft invoice by id. Requires: Invoicing.Invoices, Invoicing.Invoices.Delete, merchant scope. - GET
/api/invoicing/invoices/{id}deprecated Invoices: Retrieves a single invoice by id. Requires: Invoicing.Invoices, merchant scope. - PUT
/api/invoicing/invoices/{id}deprecated Invoices: Updates an existing draft invoice by id. Requires: Invoicing.Invoices, Invoicing.Invoices.Update, merchant scope. - POST
/api/invoicing/invoices/{id}/canceldeprecated Invoices: Cancels a draft invoice. Requires: Invoicing.Invoices, Invoicing.Invoices.Cancel, merchant scope. - POST
/api/invoicing/invoices/{id}/clonedeprecated Invoices: Clones an existing invoice as a new draft. Requires: Invoicing.Invoices, Invoicing.Invoices.Create, merchant scope. - POST
/api/invoicing/invoices/{id}/closedeprecated Invoices: Closes an invoice (write-off). Requires: Invoicing.Invoices, Invoicing.Invoices.Close, merchant scope. - POST
/api/invoicing/invoices/{id}/issuedeprecated Invoices: Issues a draft invoice (locks it, assigns a number, computes the due date). Requires: Invoicing.Invoices, Invoicing.Invoices.Send, merchant scope. - POST
/api/invoicing/invoices/{id}/mark-as-sentdeprecated Invoices: Marks an issued invoice as sent (status only, no notification). Requires: Invoicing.Invoices, Invoicing.Invoices.Send, merchant scope. - POST
/api/invoicing/invoices/{id}/mark-as-vieweddeprecated Invoices: Marks an invoice as viewed by the recipient. Requires: Invoicing.Invoices, merchant scope. - POST
/api/invoicing/invoices/{id}/notesdeprecated Invoices: Appends an internal note to an invoice. Requires: Invoicing.Invoices, Invoicing.Invoices.Update, merchant scope. - GET
/api/invoicing/invoices/{id}/payment-linkdeprecated Invoices: Reads the invoice's pay-by-link state. Requires: Invoicing.Invoices, merchant scope. - POST
/api/invoicing/invoices/{id}/payment-link/reissuedeprecated Invoices: Reissues the payment link without emailing the recipient. Requires: Invoicing.Invoices, Invoicing.Invoices.Send, merchant scope. - GET
/api/invoicing/invoices/{id}/pdfdeprecated Invoices: Downloads an invoice's PDF document. Requires: Invoicing.Invoices, merchant scope. - GET
/api/invoicing/invoices/{id}/pdf/metadatadeprecated Invoices: Retrieves the metadata of an invoice's PDF document. Requires: Invoicing.Invoices, merchant scope. - POST
/api/invoicing/invoices/{id}/record-paymentdeprecated Invoices: Records an offline or manual payment against an invoice. Requires: Invoicing.Invoices, Invoicing.Invoices.RecordPayment, merchant scope. - POST
/api/invoicing/invoices/{id}/refunddeprecated Invoices: Refunds the payments collected against an invoice. Requires: Invoicing.Invoices, Invoicing.Invoices.Refund, merchant scope. - POST
/api/invoicing/invoices/{id}/senddeprecated Invoices: Runs the full send workflow. Requires: Invoicing.Invoices, Invoicing.Invoices.Send, merchant scope. - GET
/api/invoicing/credit-notesdeprecated Credit Notes: Retrieves a paged list of credit notes. Requires: Invoicing.CreditNotes, merchant scope. - POST
/api/invoicing/credit-notesdeprecated Credit Notes: Creates a new credit note. Requires: Invoicing.CreditNotes, Invoicing.CreditNotes.Create, merchant scope. - DELETE
/api/invoicing/credit-notes/{id}deprecated Credit Notes: Deletes a credit note by id. Requires: Invoicing.CreditNotes, Invoicing.CreditNotes.Delete, merchant scope. - GET
/api/invoicing/credit-notes/{id}deprecated Credit Notes: Retrieves a single credit note by id. Requires: Invoicing.CreditNotes, merchant scope. - PUT
/api/invoicing/credit-notes/{id}deprecated Credit Notes: Updates an existing credit note by id. Requires: Invoicing.CreditNotes, Invoicing.CreditNotes.Update, merchant scope. - GET
/api/invoicing/custom-field-definitionsdeprecated Custom Field Definitions: Retrieves a paged list of invoice custom field definitions. Requires: Invoicing.CustomFieldDefinitions, merchant scope. - POST
/api/invoicing/custom-field-definitionsdeprecated Custom Field Definitions: Creates a new invoice custom field definition. Requires: Invoicing.CustomFieldDefinitions, Invoicing.CustomFieldDefinitions.Create, merchant scope. - DELETE
/api/invoicing/custom-field-definitions/{id}deprecated Custom Field Definitions: Deletes an invoice custom field definition by id. Requires: Invoicing.CustomFieldDefinitions, Invoicing.CustomFieldDefinitions.Delete, merchant scope. - GET
/api/invoicing/custom-field-definitions/{id}deprecated Custom Field Definitions: Retrieves a single invoice custom field definition by id. Requires: Invoicing.CustomFieldDefinitions, merchant scope. - PUT
/api/invoicing/custom-field-definitions/{id}deprecated Custom Field Definitions: Updates an existing invoice custom field definition by id. Requires: Invoicing.CustomFieldDefinitions, Invoicing.CustomFieldDefinitions.Update, merchant scope. - GET
/api/invoicing/invoices/{id}/payment-plandeprecated Payment Plan: Returns the invoice's payment plan. Requires: Invoicing.Invoices, merchant scope. - POST
/api/invoicing/invoices/{id}/payment-plandeprecated Payment Plan: Sets up a plan against the outstanding balance. Requires: Invoicing.Invoices, Invoicing.Invoices.PaymentPlan, merchant scope. - POST
/api/invoicing/invoices/{id}/payment-plan/canceldeprecated Payment Plan: Cancels the active payment plan. Requires: Invoicing.Invoices, Invoicing.Invoices.PaymentPlan, merchant scope. - POST
/api/invoicing/invoices/{id}/payment-plan/pay-installmentdeprecated Payment Plan: Records a manual payment for one pending installment. Requires: Invoicing.Invoices, Invoicing.Invoices.PaymentPlan, merchant scope. - GET
/api/invoicing/productsdeprecated Products: Retrieves a skip/take paged list of invoice products. Deprecated. Requires: Invoicing.Products, merchant scope. - POST
/api/invoicing/productsdeprecated Products: Creates a new invoice product. Requires: Invoicing.Products, Invoicing.Products.Create, merchant scope. - GET
/api/invoicing/products/continuation-listdeprecated Products: Retrieves a continuation-token paged, filtered list of invoice products. Requires: Invoicing.Products, merchant scope. - DELETE
/api/invoicing/products/{id}deprecated Products: Deletes an invoice product by id. Requires: Invoicing.Products, Invoicing.Products.Delete, merchant scope. - GET
/api/invoicing/products/{id}deprecated Products: Retrieves a single invoice product by id. Requires: Invoicing.Products, merchant scope. - PUT
/api/invoicing/products/{id}deprecated Products: Updates an existing invoice product by id. Requires: Invoicing.Products, Invoicing.Products.Update, merchant scope. - GET
/api/invoicing/public/invoice/{invoiceId}deprecated Public: Retrieves an invoice for public viewing using a view token. No permission required. - GET
/api/invoicing/public/invoice/{invoiceId}/pdfdeprecated Public: Downloads an invoice's PDF document using a view token. No permission required. - GET
/api/invoicing/recurring-schedulesdeprecated Recurring schedules: Retrieves a filtered list of recurring invoice schedules. Requires: Invoicing.RecurringSchedules, merchant scope. - POST
/api/invoicing/recurring-schedulesdeprecated Recurring schedules: Creates a new recurring invoice schedule. Requires: Invoicing.RecurringSchedules, Invoicing.RecurringSchedules.Create, merchant scope. - DELETE
/api/invoicing/recurring-schedules/{id}deprecated Recurring schedules: Deletes a recurring invoice schedule by id. Requires: Invoicing.RecurringSchedules, Invoicing.RecurringSchedules.Delete, merchant scope. - GET
/api/invoicing/recurring-schedules/{id}deprecated Recurring schedules: Retrieves a single recurring invoice schedule by id. Requires: Invoicing.RecurringSchedules, merchant scope. - PUT
/api/invoicing/recurring-schedules/{id}deprecated Recurring schedules: Updates an existing recurring invoice schedule by id. Requires: Invoicing.RecurringSchedules, Invoicing.RecurringSchedules.Update, merchant scope. - POST
/api/invoicing/recurring-schedules/{id}/canceldeprecated Recurring schedules: Cancels a series permanently. Requires: Invoicing.RecurringSchedules, Invoicing.RecurringSchedules.Cancel, merchant scope. - POST
/api/invoicing/recurring-schedules/{id}/generate-nowdeprecated Recurring schedules: Generates the currently due invoice immediately. Requires: Invoicing.RecurringSchedules, Invoicing.RecurringSchedules.GenerateNow, merchant scope. - POST
/api/invoicing/recurring-schedules/{id}/pausedeprecated Recurring schedules: Pauses an active series. Requires: Invoicing.RecurringSchedules, Invoicing.RecurringSchedules.Pause, merchant scope. - POST
/api/invoicing/recurring-schedules/{id}/resumedeprecated Recurring schedules: Resumes a paused series. Requires: Invoicing.RecurringSchedules, Invoicing.RecurringSchedules.Resume, merchant scope. - GET
/api/invoicing/reports/agingdeprecated Reports: Retrieves the accounts-receivable aging report. Requires: Invoicing.Reports, merchant scope. - GET
/api/invoicing/reports/aging/export/csvdeprecated Reports: Exports the accounts-receivable aging report as CSV. Requires: Invoicing.Reports, Invoicing.Reports.Export, merchant scope. - GET
/api/invoicing/reports/aging/export/exceldeprecated Reports: Exports the accounts-receivable aging report as an Excel workbook. Requires: Invoicing.Reports, Invoicing.Reports.Export, merchant scope. - GET
/api/invoicing/tax-ratesdeprecated Tax Rates: Retrieves a paged list of invoice tax rates. Requires: Invoicing.TaxRates, merchant scope. - POST
/api/invoicing/tax-ratesdeprecated Tax Rates: Creates a new invoice tax rate. Requires: Invoicing.TaxRates, Invoicing.TaxRates.Create, merchant scope. - DELETE
/api/invoicing/tax-rates/{id}deprecated Tax Rates: Deletes an invoice tax rate by id. Requires: Invoicing.TaxRates, Invoicing.TaxRates.Delete, merchant scope. - GET
/api/invoicing/tax-rates/{id}deprecated Tax Rates: Retrieves a single invoice tax rate by id. Requires: Invoicing.TaxRates, merchant scope. - PUT
/api/invoicing/tax-rates/{id}deprecated Tax Rates: Updates an existing invoice tax rate by id. Requires: Invoicing.TaxRates, Invoicing.TaxRates.Update, merchant scope. - GET
/api/invoicing/templatesdeprecated Templates: Retrieves a paged list of invoice templates. Requires: Invoicing.Templates, merchant scope. - POST
/api/invoicing/templatesdeprecated Templates: Creates a new invoice template. Requires: Invoicing.Templates, Invoicing.Templates.Create, merchant scope. - DELETE
/api/invoicing/templates/{id}deprecated Templates: Deletes an invoice template by id. Requires: Invoicing.Templates, Invoicing.Templates.Delete, merchant scope. - GET
/api/invoicing/templates/{id}deprecated Templates: Retrieves a single invoice template by id. Requires: Invoicing.Templates, merchant scope. - PUT
/api/invoicing/templates/{id}deprecated Templates: Updates an existing invoice template by id. Requires: Invoicing.Templates, Invoicing.Templates.Update, merchant scope.
Identity & Access
Login
Interactive sign-in and sign-out: password authentication, external login linking, and the password re-check a sensitive operation asks for.
- POST
/api/account/checkPassworddeprecated Check password No permission required. - POST
/api/account/linkLogindeprecated Link external login No permission required. - POST
/api/account/logindeprecated User login No permission required. - GET
/api/account/logoutdeprecated User logout No permission required.
Billing & Invoicing
Merchant Billing
Reseller-to-merchant billing: billing runs and history, plan-scoped reporting, and the stored payment method used to draft recurring charges.
- GET
/api/billing-runsdeprecated Billing Runs: Lists billing runs in the caller's reseller scope. Requires: MerchantBilling.BillingRuns, merchant scope. - POST
/api/billing-runsdeprecated Billing Runs: Creates and runs a billing run for the caller's reseller scope. Requires: MerchantBilling.BillingRuns, MerchantBilling.BillingRuns.Create, merchant scope. - GET
/api/billing-runs/batchdeprecated Billing Runs: Gets the active all-resellers batch, or the most recent batch. Requires: MerchantBilling.BillingRuns, merchant scope. - POST
/api/billing-runs/batch/cleardeprecated Billing Runs: Force-clears the current all-resellers fan-out batch. Requires: MerchantBilling.BillingRuns, MerchantBilling.BillingRuns.Manage, merchant scope. - GET
/api/billing-runs/environment-coveragedeprecated Billing Runs: Counts the merchants a run bills that their plan does not price. Requires: MerchantBilling.BillingRuns, merchant scope. - GET
/api/billing-runs/merchant-historydeprecated Billing Runs: Gets one merchant's billing history across every run that included it. Requires: MerchantBilling.BillingRuns, merchant scope. - GET
/api/billing-runs/price-plan-historydeprecated Billing Runs: Gets the plan-scoped historic billing report. Requires: MerchantBilling.BillingRuns, MerchantBilling.Reports, merchant scope. - GET
/api/billing-runs/price-plan-history/exportdeprecated Billing Runs: Exports the plan-scoped historic billing report as a file. Requires: MerchantBilling.BillingRuns, MerchantBilling.Reports, merchant scope. - GET
/api/billing-runs/target-resellersdeprecated Billing Runs: Lists the resellers the caller can run billing for. Requires: MerchantBilling.BillingRuns, merchant scope. - POST
/api/billing-runs/trigger-all-resellersdeprecated Billing Runs: Triggers the admin all-resellers billing fan-out as a background process. Requires: MerchantBilling.BillingRuns, MerchantBilling.BillingRuns.Create, merchant scope. - GET
/api/billing-runs/{id}deprecated Billing Runs: Gets a single billing run by its identifier. Requires: MerchantBilling.BillingRuns, merchant scope. - POST
/api/billing-runs/{id}/canceldeprecated Billing Runs: Cancels a pending or running billing run. Requires: MerchantBilling.BillingRuns, MerchantBilling.BillingRuns.Create, merchant scope. - GET
/api/billing-runs/{id}/exportdeprecated Billing Runs: Exports a billing run's merchant results and line items as a file. Requires: MerchantBilling.BillingRuns, merchant scope. - POST
/api/billing-runs/{id}/results/{resultId}/retry-chargedeprecated Billing Runs: Retries a failed recurring charge on a billing run. Requires: MerchantBilling.BillingRuns, MerchantBilling.BillingRuns.Retry, merchant scope. - GET
/api/merchants/{id}/billing/payment-methoddeprecated Payment Methods: Gets the merchant's active stored payment method. Requires: MerchantBilling.PaymentMethods, merchant scope. - POST
/api/merchants/{id}/billing/payment-method/capture-link/canceldeprecated Payment Methods: Cancels (revokes) the outstanding capture link for the merchant. Requires: MerchantBilling.PaymentMethods, MerchantBilling.PaymentMethods.Manage, merchant scope. - POST
/api/merchants/{id}/billing/payment-method/capture-link/resenddeprecated Payment Methods: Resends the outstanding capture link for the merchant. Requires: MerchantBilling.PaymentMethods, MerchantBilling.PaymentMethods.Manage, merchant scope. - POST
/api/merchants/{id}/billing/payment-method/capture-link/senddeprecated Payment Methods: Emails the merchant a capture link. Requires: MerchantBilling.PaymentMethods, MerchantBilling.PaymentMethods.Manage, merchant scope. - GET
/api/merchants/{id}/billing/payment-method/capture-link/statusdeprecated Payment Methods: Gets the status of the outstanding capture link for the merchant. Requires: MerchantBilling.PaymentMethods, MerchantBilling.PaymentMethods.Manage, merchant scope. - GET
/api/merchants/{id}/billing/payment-method/capture-readinessdeprecated Payment Methods: Reports whether capture is configured. Requires: MerchantBilling.PaymentMethods, MerchantBilling.PaymentMethods.Manage, merchant scope. - POST
/api/merchants/{id}/billing/payment-method/deactivatedeprecated Payment Methods: Soft-deactivates the active stored payment method for the merchant. Requires: MerchantBilling.PaymentMethods, MerchantBilling.PaymentMethods.Manage, merchant scope. - GET
/api/merchants/{id}/billing/payment-method/historydeprecated Payment Methods: Gets the merchant's stored-method history. Requires: MerchantBilling.PaymentMethods, merchant scope. - POST
/api/merchants/{id}/billing/payment-method/{paymentMethodId}/activatedeprecated Payment Methods: Re-activates a stored-but-inactive payment method for the merchant. Requires: MerchantBilling.PaymentMethods, MerchantBilling.PaymentMethods.Manage, merchant scope.
Merchants & Resellers
Merchant Payment Encryption Binding
Read or change one merchant's payment encryption provider bindings, and the key serial identifier entries under them, without sending the whole merchant document back.
- GET
/api/merchants/{id}/payment-encryption-bindingsdeprecated Payment encryption: lists the merchant's provider bindings. No permission required. - DELETE
/api/merchants/{id}/payment-encryption-bindings/{providerName}deprecated Payment encryption: unbinds one provider. Requires: Merchants.Merchants.Update, merchant scope. - GET
/api/merchants/{id}/payment-encryption-bindings/{providerName}deprecated Payment encryption: gets the merchant's binding for one provider. Requires: Merchants.Merchants, merchant scope. - PUT
/api/merchants/{id}/payment-encryption-bindings/{providerName}deprecated Payment encryption: creates or replaces the merchant's binding for one provider. Requires: Merchants.Merchants.Update, merchant scope. - DELETE
/api/merchants/{id}/payment-encryption-bindings/{providerName}/keys/{ksi}deprecated Payment encryption: removes one key entry. Requires: Merchants.Merchants.Update, merchant scope. - PUT
/api/merchants/{id}/payment-encryption-bindings/{providerName}/keys/{ksi}deprecated Payment encryption: adds or replaces one key entry. Requires: Merchants.Merchants.Update, merchant scope. - POST
/api/merchants/{id}/payment-encryption-bindings/{providerName}/keys/{ksi}/deactivatedeprecated Payment encryption: retires one key entry. Requires: Merchants.Merchants.Update, merchant scope. - POST
/api/merchants/{id}/payment-encryption-bindings/{providerName}/keys/{ksi}/reactivatedeprecated Payment encryption: returns one retired key entry to service. Requires: Merchants.Merchants.Update, merchant scope. - POST
/api/merchants/{id}/payment-encryption-bindings/{providerName}/test-connectiondeprecated Payment encryption: tests the connection to the bound provider. Requires: Merchants.Merchants.Update, merchant scope.
Merchants & Resellers
Merchants
Merchant onboarding, configuration, processing settings, and lifecycle management.
- GET
/api/merchantsdeprecated List merchants No permission required. - POST
/api/merchantsdeprecated Create merchant Requires: Merchants.Merchants.Create, merchant scope. - GET
/api/merchants/assignable-for-price-plandeprecated Lists the merchants that can be assigned to a price plan. Requires: Merchants.Merchants, merchant scope. - GET
/api/merchants/by-price-plandeprecated Lists the merchants currently assigned to a price plan. Requires: Merchants.Merchants, merchant scope. - POST
/api/merchants/get-default-merchant-user-asyncdeprecated Gets the default user account associated with the specified merchant. Requires: Merchants.Merchants, merchant scope. - POST
/api/merchants/get-merchant-users-asyncdeprecated Lists the active users of a merchant, with their email addresses. No permission required. - POST
/api/merchants/list/continuationdeprecated Retrieves a continuation-based page of merchants. No permission required. - POST
/api/merchants/list/continuation/countdeprecated Counts the Merchants that match a filter. No permission required. - POST
/api/merchants/list/continuation/summary-countsdeprecated Counts Merchants for several filters at once. No permission required. - GET
/api/merchants/reseller-scopedeprecated Lists the active merchants under the calling reseller and every reseller beneath it. Requires: Merchants.Merchants, merchant scope. - GET
/api/merchants/self/custom-fieldsdeprecated Get custom field definitions for the signed-in user's merchant Requires: Merchants.SelfServiceSettings, merchant scope. - PUT
/api/merchants/self/custom-fieldsdeprecated Update custom field definitions for the signed-in user's merchant Requires: Merchants.SelfServiceSettings.Manage, merchant scope. - GET
/api/merchants/self/order-data-defaultsdeprecated Get order data defaults for the signed-in user's merchant Requires: Merchants.SelfServiceSettings, merchant scope. - PUT
/api/merchants/self/order-data-defaultsdeprecated Update order data defaults for the signed-in user's merchant Requires: Merchants.SelfServiceSettings.Manage, merchant scope. - POST
/api/merchants/validate-processor-profile-deactivation-asyncdeprecated Reports whether a processor profile can be deactivated. No permission required. - DELETE
/api/merchants/{id}deprecated Delete merchant Requires: Merchants.Merchants.Delete, merchant scope. - GET
/api/merchants/{id}deprecated Get merchant by ID No permission required. - PUT
/api/merchants/{id}deprecated Update merchant Requires: Merchants.Merchants.Update, merchant scope. - GET
/api/merchants/{id}/accessdeprecated Check merchant access No permission required. - POST
/api/merchants/{id}/assign-price-plan/{pricePlanId}deprecated Assigns a merchant to a price plan. Requires: MerchantBilling.PricePlans.Assign, merchant scope. - GET
/api/merchants/{id}/custom-fieldsdeprecated Reads one merchant's custom field definitions. No permission required. - POST
/api/merchants/{id}/lockdeprecated Locks the specified merchant, preventing modifications and deletions until unlocked. Requires: Merchants.Merchants.Lock, merchant scope. - GET
/api/merchants/{id}/namedeprecated Get merchant name No permission required. - POST
/api/merchants/{id}/promotedeprecated Promotes the specified merchant to the Production environment. Requires: Merchants.Merchants.ManageEnvironment, merchant scope. - GET
/api/merchants/{id}/registersdeprecated Get merchant registers No permission required. - POST
/api/merchants/{id}/restoredeprecated Restore deleted merchant Requires: Merchants.Merchants.Delete, merchant scope. - POST
/api/merchants/{id}/trial/extenddeprecated Extends the specified merchant's trial. Requires: Merchants.Merchants.ExtendTrial, merchant scope. - POST
/api/merchants/{id}/unassign-price-plandeprecated Clears a merchant's price-plan assignment. Requires: MerchantBilling.PricePlans.Assign, merchant scope. - POST
/api/merchants/{id}/unlockdeprecated Unlocks the specified merchant, allowing modifications and deletions again. Requires: Merchants.Merchants.Unlock, merchant scope. - GET
/api/merchants/{id}/processor-capabilitiesdeprecated Processor Capability: lists what each of the merchant's active processor profiles can do. No permission required. - GET
/api/merchants/{id}/processor-profilesdeprecated Processor Profile: lists the merchant's processor profiles. Requires: Merchants.Merchants, merchant scope. - POST
/api/merchants/{id}/processor-profilesdeprecated Processor Profile: adds a new processor profile to the merchant. Requires: Merchants.Merchants.Update, merchant scope. - DELETE
/api/merchants/{id}/processor-profiles/{profileId}deprecated Processor Profile: removes a processor profile from the merchant. Requires: Merchants.Merchants.Update, merchant scope. - GET
/api/merchants/{id}/processor-profiles/{profileId}deprecated Processor Profile: gets a single processor profile by id. Requires: Merchants.Merchants, merchant scope. - PUT
/api/merchants/{id}/processor-profiles/{profileId}deprecated Processor Profile: replaces an existing processor profile. Requires: Merchants.Merchants.Update, merchant scope. - GET
/api/merchants/{id}/processor-profiles/{profileId}/summarydeprecated Processor Profile: gets a read-only, non-secret summary of a single processor profile. Requires: Transactions.ProcessorConfiguration.View, merchant scope. - GET
/api/merchants/registers/by-legacy-number/{legacyNumber}deprecated Register: resolves a register by its legacy numeric key within the caller's own merchant. Requires: Merchants.SelfServiceSettings, merchant scope. - POST
/api/merchants/{id}/registersdeprecated Register: creates or replaces a single register on the merchant. Requires: Merchants.Merchants.Update, merchant scope. - GET
/api/merchants/{id}/screening-provider-profilesdeprecated Screening Provider: lists the merchant's screening provider profiles. No permission required. - POST
/api/merchants/{id}/screening-provider-profilesdeprecated Screening Provider: adds a screening provider profile to the merchant. Requires: Merchants.Merchants.Create, merchant scope. - DELETE
/api/merchants/{id}/screening-provider-profiles/{profileId}deprecated Screening Provider: removes a screening provider profile from the merchant. Requires: Merchants.Merchants.Delete, merchant scope. - GET
/api/merchants/{id}/screening-provider-profiles/{profileId}deprecated Screening Provider: gets a single screening provider profile by id. No permission required. - PUT
/api/merchants/{id}/screening-provider-profiles/{profileId}deprecated Screening Provider: Replaces an existing profile. Requires: Merchants.Merchants.Update, merchant scope.
Merchants & Resellers
Merchant Shipping Binding
Read or change one merchant's shipping rate provider bindings without sending the whole merchant document back.
- GET
/api/merchants/{id}/shipping-bindingsdeprecated Shipping: lists the merchant's provider bindings. No permission required. - DELETE
/api/merchants/{id}/shipping-bindings/{providerName}deprecated Shipping: removes the merchant's binding for one provider, with any stored credentials. Requires: Merchants.Merchants.Update, merchant scope. - GET
/api/merchants/{id}/shipping-bindings/{providerName}deprecated Shipping: gets the merchant's binding for one provider. Requires: Merchants.Merchants, merchant scope. - PUT
/api/merchants/{id}/shipping-bindings/{providerName}deprecated Shipping: creates or replaces the merchant's binding for one provider. Requires: Merchants.Merchants.Update, merchant scope. - POST
/api/merchants/{id}/shipping-bindings/{providerName}/test-connectiondeprecated Shipping: probes the merchant's bound provider and reports whether it answered. Requires: Merchants.Merchants.Update, merchant scope.
Merchants & Resellers
Merchant Tax Binding
Read or change one merchant's tax provider bindings without sending the whole merchant document back.
- GET
/api/merchants/{id}/tax-bindingsdeprecated Tax: lists the merchant's provider bindings. No permission required. - DELETE
/api/merchants/{id}/tax-bindings/{providerName}deprecated Tax: removes the merchant's binding for one provider, with any stored credentials. Requires: Merchants.Merchants.Update, merchant scope. - GET
/api/merchants/{id}/tax-bindings/{providerName}deprecated Tax: gets the merchant's binding for one provider. Requires: Merchants.Merchants, merchant scope. - PUT
/api/merchants/{id}/tax-bindings/{providerName}deprecated Tax: creates or replaces the merchant's binding for one provider. Requires: Merchants.Merchants.Update, merchant scope. - POST
/api/merchants/{id}/tax-bindings/{providerName}/test-connectiondeprecated Tax: probes the merchant's bound provider and reports whether it answered. Requires: Merchants.Merchants.Update, merchant scope.
Merchants & Resellers
Merchant Three DS Binding
Read or change one merchant's 3-D Secure bindings without sending the whole merchant document back.
- GET
/api/merchants/{id}/three-d-secure-bindingsdeprecated 3-D Secure: lists the merchant's provider bindings. No permission required. - DELETE
/api/merchants/{id}/three-d-secure-bindings/{providerType}deprecated 3-D Secure: removes the merchant's binding for one provider, with its stored credentials. Requires: Merchants.Merchants.Update, merchant scope. - GET
/api/merchants/{id}/three-d-secure-bindings/{providerType}deprecated 3-D Secure: gets the merchant's binding for one provider. Requires: Merchants.Merchants, merchant scope. - PUT
/api/merchants/{id}/three-d-secure-bindings/{providerType}deprecated 3-D Secure: creates or replaces the merchant's binding for one provider. Requires: Merchants.Merchants.Update, merchant scope. - POST
/api/merchants/{id}/three-d-secure-bindings/{providerType}/test-connectiondeprecated 3-D Secure: probes the merchant's provider account and reports whether it answered. Requires: Merchants.Merchants.Update, merchant scope.
Messaging & Notifications
Messaging
Delivery records for the email and SMS the platform sends on a merchant's behalf, plus the SMS consent register that decides who may be texted.
- GET
/api/twilio/email-logdeprecated Email Log: lists rows for the caller's scope, newest first, with cursor-based paging. Requires: Twilio.EmailLog.View, merchant scope. - GET
/api/twilio/email-log/by-correlation/{correlationId}deprecated Email Log: gets the full event history for one outbound message by its correlation id. Requires: Twilio.EmailLog.View, merchant scope. - GET
/api/twilio/email-log/{id}deprecated Email Log: gets a single row by its id. Requires: Twilio.EmailLog.View, merchant scope. - GET
/api/twilio/sms-consentdeprecated SMS Consent: lists consent records for the caller's scope. Requires: Twilio.SmsConsent.View, merchant scope. - POST
/api/twilio/sms-consentdeprecated SMS Consent: records a consent or opt-out transition with its proof-of-consent evidence. Requires: Twilio.SmsConsent.View, Twilio.SmsConsent.Manage, merchant scope. - GET
/api/twilio/sms-consent/checkdeprecated SMS Consent: checks whether SMS may be sent to a number in the caller's merchant scope. Requires: Twilio.SmsConsent.View, merchant scope. - GET
/api/twilio/sms-logdeprecated SMS Log: lists outbound SMS delivery records for the caller's scope. Requires: Twilio.SmsLog.View, merchant scope. - GET
/api/twilio/sms-log/by-correlation/{correlationId}deprecated SMS Log: gets the delivery record for one outbound message by its correlation id. Requires: Twilio.SmsLog.View, merchant scope.
Identity & Access
My Session
Self-service listing and revocation of the signed-in user's own active login sessions.
- GET
/api/app/my-session/approximate-total-countdeprecated Counts the entities matching `input`. No permission required. - GET
/api/app/my-session/continuation-listdeprecated No permission required. - GET
/api/app/my-session/summary-countsdeprecated No permission required. - POST
/api/app/my-session/{id}/ensure-entity-accessdeprecated No permission required. - POST
/api/app/my-session/{id}/revokedeprecated No permission required. - POST
/api/app/my-session/{id}/try-ensure-entity-accessdeprecated No permission required.
Messaging & Notifications
Notifications
Notification channels, destinations, subscriptions, and delivery tracking.
- GET
/api/notifications/channelsdeprecated Get a list of NotificationChannels Requires: Notifications.Channels, merchant scope. - POST
/api/notifications/channelsdeprecated Create a NotificationChannel Requires: Notifications.Channels, Notifications.Channels.Create, merchant scope. - POST
/api/notifications/channels/list/continuationdeprecated Retrieves a continuation-based page of NotificationChannels. Requires: Notifications.Channels, merchant scope. - POST
/api/notifications/channels/list/continuation/countdeprecated Counts the NotificationChannels that match a filter. Requires: Notifications.Channels, merchant scope. - POST
/api/notifications/channels/list/continuation/summary-countsdeprecated Counts NotificationChannels for several filters at once. Requires: Notifications.Channels, merchant scope. - DELETE
/api/notifications/channels/{id}deprecated Delete a NotificationChannel Requires: Notifications.Channels, Notifications.Channels.Delete, merchant scope. - GET
/api/notifications/channels/{id}deprecated Get a NotificationChannel Requires: Notifications.Channels, merchant scope. - PUT
/api/notifications/channels/{id}deprecated Update a NotificationChannel Requires: Notifications.Channels, Notifications.Channels.Update, merchant scope. - GET
/api/notifications/channels/{id}/accessdeprecated Check NotificationChannel access Requires: Notifications.Channels, merchant scope. - POST
/api/notifications/channels/{id}/disabledeprecated Disables a channel. Requires: Notifications.Channels, Notifications.Channels.Update, merchant scope. - POST
/api/notifications/channels/{id}/duplicatedeprecated Duplicates a channel. Requires: Notifications.Channels, Notifications.Channels.Create, merchant scope. - POST
/api/notifications/channels/{id}/enabledeprecated Enables a channel. Requires: Notifications.Channels, Notifications.Channels.Update, merchant scope. - GET
/api/notifications/channels/{id}/namedeprecated Get a NotificationChannel name by id Requires: Notifications.Channels, merchant scope. - POST
/api/notifications/channels/{id}/restoredeprecated Restore a deleted NotificationChannel Requires: Notifications.Channels, merchant scope. - POST
/api/notifications/deliveries/outcome-summarydeprecated Counts how deliveries ended in a time window, broken down by outcome. Requires: Notifications.Deliveries, merchant scope. - GET
/api/notifications/destinationsdeprecated Get a list of NotificationDestinations Requires: Notifications.Destinations, merchant scope. - POST
/api/notifications/destinationsdeprecated Create a NotificationDestination Requires: Notifications.Destinations, Notifications.Destinations.Create, merchant scope. - POST
/api/notifications/destinations/list/continuationdeprecated Retrieves a continuation-based page of NotificationDestinations. Requires: Notifications.Destinations, merchant scope. - POST
/api/notifications/destinations/list/continuation/countdeprecated Counts the NotificationDestinations that match a filter. Requires: Notifications.Destinations, merchant scope. - POST
/api/notifications/destinations/list/continuation/summary-countsdeprecated Counts NotificationDestinations for several filters at once. Requires: Notifications.Destinations, merchant scope. - GET
/api/notifications/destinations/types/metadatadeprecated Returns metadata (icon, logo) for all supported destination types. Requires: Notifications.Destinations, merchant scope. - POST
/api/notifications/destinations/types/{type}/test-configdeprecated Tests a destination configuration without requiring a saved entity. Requires: Notifications.Destinations, Notifications.Destinations.Create, merchant scope. - POST
/api/notifications/destinations/types/{type}/validatedeprecated Validates destination configuration for a specific type. Requires: Notifications.Destinations, merchant scope. - DELETE
/api/notifications/destinations/{id}deprecated Delete a NotificationDestination Requires: Notifications.Destinations, Notifications.Destinations.Delete, merchant scope. - GET
/api/notifications/destinations/{id}deprecated Get a NotificationDestination Requires: Notifications.Destinations, merchant scope. - PUT
/api/notifications/destinations/{id}deprecated Update a NotificationDestination Requires: Notifications.Destinations, Notifications.Destinations.Update, merchant scope. - GET
/api/notifications/destinations/{id}/accessdeprecated Check NotificationDestination access Requires: Notifications.Destinations, merchant scope. - POST
/api/notifications/destinations/{id}/disabledeprecated Disables a destination. Requires: Notifications.Destinations, Notifications.Destinations.Update, merchant scope. - POST
/api/notifications/destinations/{id}/duplicatedeprecated Duplicates a destination. Requires: Notifications.Destinations, Notifications.Destinations.Create, merchant scope. - POST
/api/notifications/destinations/{id}/enabledeprecated Enables a destination. Requires: Notifications.Destinations, Notifications.Destinations.Update, merchant scope. - GET
/api/notifications/destinations/{id}/namedeprecated Get a NotificationDestination name by id Requires: Notifications.Destinations, merchant scope. - POST
/api/notifications/destinations/{id}/restoredeprecated Restore a deleted NotificationDestination Requires: Notifications.Destinations, merchant scope. - GET
/api/notifications/destinations/{id}/secret-rotationdeprecated Gets a destination's signing-secret rotation state. Requires: Notifications.Destinations, merchant scope. - POST
/api/notifications/destinations/{id}/secret-rotation/begindeprecated Starts a signing-secret rotation. Requires: Notifications.Destinations, Notifications.Destinations.Update, merchant scope. - POST
/api/notifications/destinations/{id}/secret-rotation/canceldeprecated Abandons a signing-secret rotation. Requires: Notifications.Destinations, Notifications.Destinations.Update, merchant scope. - POST
/api/notifications/destinations/{id}/secret-rotation/promotedeprecated Completes a signing-secret rotation. Requires: Notifications.Destinations, Notifications.Destinations.Update, merchant scope. - POST
/api/notifications/destinations/{id}/send-sampledeprecated Sends a realistic sample of one event type to a saved webhook destination. Requires: Notifications.Destinations, Notifications.Destinations.Test, merchant scope. - GET
/api/notifications/destinations/{id}/suppressiondeprecated Gets the durable suppression state for a destination's endpoint. Requires: Notifications.Destinations, merchant scope. - POST
/api/notifications/destinations/{id}/suppression/cleardeprecated Clears the suppression on a destination's endpoint so delivery resumes on the next event. Requires: Notifications.Destinations, Notifications.Suppressions.Clear, merchant scope. - POST
/api/notifications/destinations/{id}/testdeprecated Tests a saved destination by sending a test notification. Requires: Notifications.Destinations, Notifications.Destinations.Test, merchant scope. - GET
/api/notifications/event-typesdeprecated Returns all event types available for the current user's scope. Requires: Notifications.EventTypes, merchant scope. - GET
/api/notifications/event-types/{eventType}/payload-schemadeprecated Describes the webhook payload schema and an illustrative sample for a specific event type. Requires: Notifications.EventTypes, merchant scope. - GET
/api/notifications/event-types/{eventType}/sample-payloaddeprecated Returns a sample payload for a specific event type. Requires: Notifications.EventTypes, merchant scope. - GET
/api/notifications/eventsdeprecated Lists the webhooks sent to your endpoints in a time window. Requires: Notifications.Events, merchant scope. - POST
/api/notifications/events/replaydeprecated Sends every replayable delivery in a time window to your endpoints again. Requires: Notifications.Events.Replay, merchant scope. - GET
/api/notifications/events/{id}deprecated Reads one webhook delivery, including the body posted to your endpoint. Requires: Notifications.Events, merchant scope. - POST
/api/notifications/events/{id}/replaydeprecated Sends one webhook delivery to your endpoint again. Requires: Notifications.Events.Replay, merchant scope. - POST
/api/notifications/filters/validatedeprecated Validates a filter expression. Requires: Notifications.Subscriptions, merchant scope. - GET
/api/notifications/inboxdeprecated Lists the caller's notifications, newest first. No permission required. - GET
/api/notifications/inbox/categoriesdeprecated Lists the notification categories the inbox can be filtered by. No permission required. - POST
/api/notifications/inbox/mark-all-readdeprecated Marks the caller's unread notifications read. No permission required. - GET
/api/notifications/inbox/unread-summarydeprecated Counts the caller's unread notifications. No permission required. - POST
/api/notifications/inbox/{id}/mark-readdeprecated Marks one of the caller's notifications read. No permission required. - POST
/api/notifications/listen-sessionsdeprecated Opens a listen session for the caller's merchant and returns its signing secret, once. Requires: Notifications.ListenSessions.Listen, merchant scope. - POST
/api/notifications/listen-sessions/{id}/enddeprecated Ends the caller's own session. Its cursor and its secret stop working. Requires: Notifications.ListenSessions.Listen, merchant scope. - GET
/api/notifications/listen-sessions/{id}/eventsdeprecated Returns events staged after the cursor, oldest first, and renews the session. Requires: Notifications.ListenSessions.Listen, merchant scope. - POST
/api/notifications/listen-sessions/{id}/sampledeprecated Stages the event catalog's sample for one event type into a live session's buffer. Requires: Notifications.ListenSessions.Listen, Notifications.Destinations.Test, merchant scope. - GET
/api/notifications/subscriptionsdeprecated Get a list of NotificationSubscriptions Requires: Notifications.Subscriptions, merchant scope. - POST
/api/notifications/subscriptionsdeprecated Create a NotificationSubscription Requires: Notifications.Subscriptions, Notifications.Subscriptions.Create, merchant scope. - POST
/api/notifications/subscriptions/list/continuationdeprecated Retrieves a continuation-based page of NotificationSubscriptions. Requires: Notifications.Subscriptions, merchant scope. - POST
/api/notifications/subscriptions/list/continuation/countdeprecated Counts the NotificationSubscriptions that match a filter. Requires: Notifications.Subscriptions, merchant scope. - POST
/api/notifications/subscriptions/list/continuation/summary-countsdeprecated Counts NotificationSubscriptions for several filters at once. Requires: Notifications.Subscriptions, merchant scope. - DELETE
/api/notifications/subscriptions/{id}deprecated Delete a NotificationSubscription Requires: Notifications.Subscriptions, Notifications.Subscriptions.Delete, merchant scope. - GET
/api/notifications/subscriptions/{id}deprecated Get a NotificationSubscription Requires: Notifications.Subscriptions, merchant scope. - PUT
/api/notifications/subscriptions/{id}deprecated Update a NotificationSubscription Requires: Notifications.Subscriptions, Notifications.Subscriptions.Update, merchant scope. - GET
/api/notifications/subscriptions/{id}/accessdeprecated Check NotificationSubscription access Requires: Notifications.Subscriptions, merchant scope. - POST
/api/notifications/subscriptions/{id}/disabledeprecated Disables a subscription. Requires: Notifications.Subscriptions, Notifications.Subscriptions.Update, merchant scope. - POST
/api/notifications/subscriptions/{id}/duplicatedeprecated Duplicates a subscription. Requires: Notifications.Subscriptions, Notifications.Subscriptions.Create, merchant scope. - POST
/api/notifications/subscriptions/{id}/enabledeprecated Enables a subscription. Requires: Notifications.Subscriptions, Notifications.Subscriptions.Update, merchant scope. - GET
/api/notifications/subscriptions/{id}/namedeprecated Get a NotificationSubscription name by id Requires: Notifications.Subscriptions, merchant scope. - POST
/api/notifications/subscriptions/{id}/restoredeprecated Restore a deleted NotificationSubscription Requires: Notifications.Subscriptions, merchant scope. - GET
/api/notifications/unsubscribedeprecated Handles unsubscribe link clicks from emails. No permission required. - POST
/api/notifications/unsubscribedeprecated Handles RFC 8058 one-click unsubscribe (POST with List-Unsubscribe-Post header). No permission required. - POST
/api/notifications/unsubscribe/confirmdeprecated Confirms the unsubscribe request and disables the subscription. No permission required.
Platform Configuration
Processor Metadata
Read-only discovery API that exposes the configuration shape each payment processor requires.
- GET
/api/processorsdeprecated Lists every supported processor. Requires: Transactions.ProcessorConfiguration.ViewSchema, merchant scope. - GET
/api/processors/{processorId}/config-schemadeprecated Returns the configuration field schema for one processor. Requires: Transactions.ProcessorConfiguration.ViewSchema, merchant scope. - GET
/api/processors/{processorId}/config-schema/templatedeprecated Returns a ready-to-fill processor profile skeleton. Requires: Transactions.ProcessorConfiguration.ViewSchema, merchant scope. - POST
/api/processors/{processorId}/validate-configdeprecated Dry-run validates a processor configuration payload. Requires: Transactions.ProcessorConfiguration.ViewSchema, merchant scope.
Payments
Promotions
Merchant promotion codes: one discount, one validity window and one set of redemption ceilings, shared by hosted pages, contracts and invoices.
- GET
/api/promotionsdeprecated Get a list of Promotions Requires: Promotions.Promotions, merchant scope. - POST
/api/promotionsdeprecated Create a Promotion Requires: Promotions.Promotions, Promotions.Promotions.Create, merchant scope. - POST
/api/promotions/list/continuationdeprecated Retrieves a continuation-based page of Promotions. Requires: Promotions.Promotions, merchant scope. - POST
/api/promotions/list/continuation/countdeprecated Counts the Promotions that match a filter. Requires: Promotions.Promotions, merchant scope. - POST
/api/promotions/list/continuation/summary-countsdeprecated Counts Promotions for several filters at once. Requires: Promotions.Promotions, merchant scope. - POST
/api/promotions/suggest-codesdeprecated Suggests promotion codes built from the values the caller has filled in so far. Requires: Promotions.Promotions, merchant scope. - DELETE
/api/promotions/{id}deprecated Delete a Promotion Requires: Promotions.Promotions, Promotions.Promotions.Delete, merchant scope. - GET
/api/promotions/{id}deprecated Get a Promotion Requires: Promotions.Promotions, merchant scope. - PUT
/api/promotions/{id}deprecated Update a Promotion Requires: Promotions.Promotions, Promotions.Promotions.Update, merchant scope. - GET
/api/promotions/{id}/accessdeprecated Check Promotion access Requires: Promotions.Promotions, merchant scope. - GET
/api/promotions/{id}/namedeprecated Get a Promotion name by id Requires: Promotions.Promotions, merchant scope. - POST
/api/promotions/{id}/restoredeprecated Restore a deleted Promotion Requires: Promotions.Promotions, Promotions.Promotions.Update, merchant scope.
Platform Configuration
Rate Limits
Stored rate limiting configuration: profiles that bind a set of limits to a scope, and the rules within them that cap request rates, concurrency, and accumulated amounts.
- GET
/api/rate-limiting/profilesdeprecated Rate Limit Profiles: retrieves a paged list of profiles. Requires: RateLimiting.Profiles, merchant scope. - POST
/api/rate-limiting/profilesdeprecated Rate Limit Profiles: creates a profile. Requires: RateLimiting.Profiles, RateLimiting.Profiles.Create, merchant scope. - GET
/api/rate-limiting/profiles/continuationdeprecated Rate Limit Profiles: retrieves a continuation-token paged list of profiles. Requires: RateLimiting.Profiles, merchant scope. - GET
/api/rate-limiting/profiles/continuation/countdeprecated Rate Limit Profiles: Counts the profiles matching the input. Requires: RateLimiting.Profiles, merchant scope. - DELETE
/api/rate-limiting/profiles/{id}deprecated Rate Limit Profiles: deletes a profile by id. Requires: RateLimiting.Profiles, RateLimiting.Profiles.Delete, merchant scope. - GET
/api/rate-limiting/profiles/{id}deprecated Rate Limit Profiles: retrieves a single profile by id. Requires: RateLimiting.Profiles, merchant scope. - PUT
/api/rate-limiting/profiles/{id}deprecated Rate Limit Profiles: updates a profile by id. Requires: RateLimiting.Profiles, RateLimiting.Profiles.Update, merchant scope. - GET
/api/rate-limiting/profiles/{id}/accessdeprecated Rate Limit Profiles: reports whether the caller may access the profile. Requires: RateLimiting.Profiles, merchant scope. - GET
/api/rate-limiting/profiles/{id}/namedeprecated Rate Limit Profiles: returns a profile's display name. Requires: RateLimiting.Profiles, merchant scope. - POST
/api/rate-limiting/profiles/{id}/restoredeprecated Rate Limit Profiles: restores a previously deleted profile. Requires: RateLimiting.Profiles, RateLimiting.Profiles.Update, merchant scope. - GET
/api/rate-limiting/rulesdeprecated Rate Limit Rules: retrieves a paged list of rules. Requires: RateLimiting.Rules, merchant scope. - POST
/api/rate-limiting/rulesdeprecated Rate Limit Rules: creates a rule. Requires: RateLimiting.Rules, RateLimiting.Rules.Create, merchant scope. - GET
/api/rate-limiting/rules/continuationdeprecated Rate Limit Rules: retrieves a continuation-token paged list of rules. Requires: RateLimiting.Rules, merchant scope. - GET
/api/rate-limiting/rules/continuation/countdeprecated Rate Limit Rules: retrieves the approximate total number of rules matching the input. Requires: RateLimiting.Rules, merchant scope. - GET
/api/rate-limiting/rules/limitersdeprecated Rate Limit Rules: lists every limiter the running host declares, with its defaults. Requires: RateLimiting.Rules, merchant scope. - GET
/api/rate-limiting/rules/profilesdeprecated Rate Limit Rules: lists every profile as a lightweight picker item. Requires: RateLimiting.Rules, merchant scope. - DELETE
/api/rate-limiting/rules/{id}deprecated Rate Limit Rules: deletes a rule by id. Requires: RateLimiting.Rules, RateLimiting.Rules.Delete, merchant scope. - GET
/api/rate-limiting/rules/{id}deprecated Rate Limit Rules: retrieves a single rule by id. Requires: RateLimiting.Rules, merchant scope. - PUT
/api/rate-limiting/rules/{id}deprecated Rate Limit Rules: updates a rule by id. Requires: RateLimiting.Rules, RateLimiting.Rules.Update, merchant scope. - GET
/api/rate-limiting/rules/{id}/accessdeprecated Rate Limit Rules: reports whether the caller may access the rule. Requires: RateLimiting.Rules, merchant scope. - GET
/api/rate-limiting/rules/{id}/namedeprecated Rate Limit Rules: returns a rule's display name. Requires: RateLimiting.Rules, merchant scope. - POST
/api/rate-limiting/rules/{id}/restoredeprecated Rate Limit Rules: restores a previously deleted rule. Requires: RateLimiting.Rules, RateLimiting.Rules.Update, merchant scope.
Billing & Invoicing
Recurring Billing
Recurring billing for customer contracts: triggering a run by hand, and the history of runs already executed.
- GET
/api/customers/recurring-billing/contracts/{contractId}/historydeprecated Get billing history filtered by contract. Requires: Customers.RecurringBilling.ViewHistory, merchant scope. - GET
/api/customers/recurring-billing/customers/{customerId}/historydeprecated Get billing history filtered by customer. Requires: Customers.RecurringBilling.ViewHistory, merchant scope. - GET
/api/customers/recurring-billing/historydeprecated Get paginated execution history of recurring billing runs. Requires: Customers.RecurringBilling.ViewHistory, merchant scope. - GET
/api/customers/recurring-billing/runs/{id}deprecated Get the detail of a specific billing run, including per-contract items. Requires: Customers.RecurringBilling.ViewHistory, merchant scope. - POST
/api/customers/recurring-billing/triggerdeprecated Manually trigger a recurring billing workflow execution. Requires: Customers.RecurringBilling.Trigger, merchant scope.
Reporting & Operations
Reports
Report generation, scheduling, and export.
- GET
/api/reportsdeprecated Lists the reports you can run. No permission required. - GET
/api/reports/{reportId}/columnsdeprecated Lists the columns a report returns. No permission required. - POST
/api/reports/{reportId}/exportdeprecated Runs a report and returns it as a file. No permission required. - GET
/api/reports/{reportId}/parametersdeprecated Lists the filters a report accepts. No permission required. - POST
/api/reports/{reportId}/rundeprecated Runs a report and returns its rows. No permission required.
Merchants & Resellers
Resellers
Reseller partner management, hierarchy, and merchant assignment.
- GET
/api/resellersdeprecated List resellers Requires: Resellers.Resellers, reseller scope. - POST
/api/resellersdeprecated Create reseller Requires: Resellers.Resellers.Create, reseller scope. - POST
/api/resellers/get-billing-preferences-asyncdeprecated Reads a reseller's billing preferences. Requires: Resellers.Resellers.Update, reseller scope. - POST
/api/resellers/get-default-reseller-user-asyncdeprecated Gets default reseller user. Requires: Resellers.Resellers, reseller scope. - POST
/api/resellers/get-effective-collection-configuration-asyncdeprecated Reads a reseller's effective collection configuration. Requires: Resellers.Resellers.Update, reseller scope. - POST
/api/resellers/get-for-billing-self-service-asyncdeprecated Reads a reseller in full for the merchant-billing setup flow. Requires: Resellers.Resellers.Update, reseller scope. - POST
/api/resellers/get-own-billing-preferences-asyncdeprecated Reads the billing preferences of the calling operator's own reseller. Requires: Resellers.Resellers.Update, reseller scope. - POST
/api/resellers/get-own-effective-collection-configuration-asyncdeprecated Reads the calling operator's own effective collection configuration. Requires: Resellers.Resellers.Update, reseller scope. - POST
/api/resellers/list/continuationdeprecated Retrieves a continuation-based page of Resellers. Requires: Resellers.Resellers, reseller scope. - POST
/api/resellers/list/continuation/countdeprecated Counts the Resellers that match a filter. Requires: Resellers.Resellers, reseller scope. - POST
/api/resellers/list/continuation/summary-countsdeprecated Counts Resellers for several filters at once. Requires: Resellers.Resellers, reseller scope. - POST
/api/resellers/update-billing-preferences-asyncdeprecated Replaces a reseller's billing preferences. Requires: Resellers.Resellers.Update, reseller scope. - POST
/api/resellers/update-own-billing-preferences-asyncdeprecated Replaces the billing preferences of the calling operator's own reseller. Requires: Resellers.Resellers.Update, reseller scope. - DELETE
/api/resellers/{id}deprecated Delete reseller Requires: Resellers.Resellers.Delete, reseller scope. - GET
/api/resellers/{id}deprecated Get reseller by ID Requires: Resellers.Resellers, reseller scope. - PUT
/api/resellers/{id}deprecated Update reseller Requires: Resellers.Resellers.Update, reseller scope. - GET
/api/resellers/{id}/accessdeprecated Check reseller access No permission required. - GET
/api/resellers/{id}/namedeprecated Get reseller name No permission required. - POST
/api/resellers/{id}/restoredeprecated Restore deleted reseller Requires: Resellers.Resellers, reseller scope.
Identity & Access
Roles
Roles, and the claims attached to them. A role is how a set of permissions is granted to every user assigned it.
- GET
/api/identity/rolesdeprecated List roles Requires: AbpIdentity.Roles, host scope. - POST
/api/identity/rolesdeprecated Create new role Requires: AbpIdentity.Roles, AbpIdentity.Roles.Create, host scope. - GET
/api/identity/roles/alldeprecated Get all roles Requires: AbpIdentity.Roles, host scope. - GET
/api/identity/roles/all-claim-typesdeprecated GetAllClaimTypes for Role Requires: AbpIdentity.Roles, host scope. - DELETE
/api/identity/roles/{id}deprecated Delete role Requires: AbpIdentity.Roles, AbpIdentity.Roles.Delete, host scope. - GET
/api/identity/roles/{id}deprecated Get role by ID Requires: AbpIdentity.Roles, host scope. - PUT
/api/identity/roles/{id}deprecated Update role Requires: AbpIdentity.Roles, AbpIdentity.Roles.Update, host scope. - GET
/api/identity/roles/{id}/claimsdeprecated GetClaims for Role Requires: AbpIdentity.Roles, host scope. - PUT
/api/identity/roles/{id}/claimsdeprecated Update role claims Requires: AbpIdentity.Roles, AbpIdentity.Roles.Update, host scope. - PUT
/api/identity/roles/{id}/move-all-usersdeprecated Move all users to role Requires: AbpIdentity.Roles, AbpIdentity.Roles.Update, host scope. - DELETE
/api/identity/roles/{id}/users/{userId}deprecated Requires: AbpIdentity.Roles, AbpIdentity.Roles.Update, host scope.
Payments
Sandbox Ach Status
Drives a sandbox ACH sale to a chosen settlement outcome on demand, so an integrator can prove an ACH webhook in one session.
Customers
Sandbox Recurring Billing
Brings a sandbox merchant's recurring contracts due now and bills them, synchronously, for the developer who holds the key.
Payments
Sandbox Settlement
Closes a sandbox merchant's open batch on demand, synchronously, for the developer who holds the key.
Platform Configuration
Screening Provider Metadata
Read-only discovery API that exposes the configuration shape each external screening provider requires.
- GET
/api/screening-providersdeprecated Lists every supported screening provider. Requires: Transactions.ScreeningProviderConfiguration.ViewSchema, merchant scope. - GET
/api/screening-providers/{providerId}/config-schemadeprecated Returns the configuration field schema for a single screening provider. Requires: Transactions.ScreeningProviderConfiguration.ViewSchema, merchant scope. - GET
/api/screening-providers/{providerId}/config-schema/templatedeprecated Returns a ready-to-fill screening provider profile skeleton. Requires: Transactions.ScreeningProviderConfiguration.ViewSchema, merchant scope. - POST
/api/screening-providers/{providerId}/validate-configdeprecated Dry-run validates a screening provider configuration payload. Requires: Transactions.ScreeningProviderConfiguration.ViewSchema, merchant scope.
Reporting & Operations
Security
Self-service access to the signed-in user's own security log: sign-ins, password changes, and the other identity events recorded against their account.
- GET
/api/app/my-security-log/approximate-total-countdeprecated Counts the entities matching `input`. No permission required. - GET
/api/app/my-security-log/continuation-listdeprecated No permission required. - GET
/api/app/my-security-log/summary-countsdeprecated No permission required. - POST
/api/app/my-security-log/{id}/ensure-entity-accessdeprecated No permission required. - POST
/api/app/my-security-log/{id}/try-ensure-entity-accessdeprecated No permission required. - GET
/api/security-posture/sbom/buildsdeprecated List archived SBOM builds, most-recent-first, with continuation-token paging. Requires: SecurityPosture.Sbom, merchant scope. - GET
/api/security-posture/sbom/builds/{buildId}deprecated Return the component manifest for a single build. Requires: SecurityPosture.Sbom, merchant scope. - GET
/api/security-posture/sbom/builds/{buildId}/components/{componentName}deprecated Stream the CycloneDX JSON for one component within a build. Each call is audit-logged. Requires: SecurityPosture.Sbom, SecurityPosture.Sbom.Download, merchant scope.
Identity & Access
Security Overview
Reads the security posture of an account, and of a merchant's accounts and API keys, for the security hub.
- GET
/api/app/security-overviewdeprecated No permission required. - GET
/api/app/security-overview/for-user/{userId}deprecated Requires: AbpIdentity.Users, host scope. - GET
/api/app/security-overview/impersonation-access-historydeprecated Requires: AbpIdentity.Users, host scope. - GET
/api/app/security-overview/merchant-posturedeprecated Requires: AbpIdentity.Users, host scope. - POST
/api/app/security-overview/revoke-other-sessionsdeprecated No permission required.
Payments
Shipping
A merchant's ship-from origins and parcel presets: the two inputs a shipping rate quote needs beyond the destination.
- GET
/api/shipping/parcel-presetsdeprecated Parcel presets: retrieves a paged list of presets. Requires: Shipping.ParcelPresets, merchant scope. - POST
/api/shipping/parcel-presetsdeprecated Parcel presets: creates a preset. A merchant's first preset becomes its default. Requires: Shipping.ParcelPresets, Shipping.ParcelPresets.Create, merchant scope. - GET
/api/shipping/parcel-presets/continuationdeprecated Parcel presets: retrieves a continuation-token paged list of presets. Requires: Shipping.ParcelPresets, merchant scope. - GET
/api/shipping/parcel-presets/continuation/countdeprecated Parcel presets: counts the presets matching the input. Requires: Shipping.ParcelPresets, merchant scope. - DELETE
/api/shipping/parcel-presets/{id}deprecated Parcel presets: deletes a preset by id. Requires: Shipping.ParcelPresets, Shipping.ParcelPresets.Delete, merchant scope. - GET
/api/shipping/parcel-presets/{id}deprecated Parcel presets: retrieves a single preset by id. Requires: Shipping.ParcelPresets, merchant scope. - PUT
/api/shipping/parcel-presets/{id}deprecated Parcel presets: updates a preset by id. Requires: Shipping.ParcelPresets, Shipping.ParcelPresets.Update, merchant scope. - GET
/api/shipping/parcel-presets/{id}/accessdeprecated Parcel presets: reports whether the caller may access the preset. Requires: Shipping.ParcelPresets, merchant scope. - GET
/api/shipping/parcel-presets/{id}/namedeprecated Parcel presets: returns a preset's display name. Requires: Shipping.ParcelPresets, merchant scope. - POST
/api/shipping/parcel-presets/{id}/restoredeprecated Parcel presets: restores a previously deleted preset. Requires: Shipping.ParcelPresets, Shipping.ParcelPresets.Update, merchant scope. - GET
/api/shipping/originsdeprecated Ship-from origins: retrieves a paged list of origins. Requires: Shipping.Origins, merchant scope. - POST
/api/shipping/originsdeprecated Ship-from origins: creates an origin. A merchant's first origin becomes its default. Requires: Shipping.Origins, Shipping.Origins.Create, merchant scope. - GET
/api/shipping/origins/continuationdeprecated Ship-from origins: retrieves a continuation-token paged list of origins. Requires: Shipping.Origins, merchant scope. - GET
/api/shipping/origins/continuation/countdeprecated Ship-from origins: counts the origins matching the input. Requires: Shipping.Origins, merchant scope. - DELETE
/api/shipping/origins/{id}deprecated Ship-from origins: deletes an origin by id. Requires: Shipping.Origins, Shipping.Origins.Delete, merchant scope. - GET
/api/shipping/origins/{id}deprecated Ship-from origins: retrieves a single origin by id. Requires: Shipping.Origins, merchant scope. - PUT
/api/shipping/origins/{id}deprecated Ship-from origins: updates an origin by id. Requires: Shipping.Origins, Shipping.Origins.Update, merchant scope. - GET
/api/shipping/origins/{id}/accessdeprecated Ship-from origins: reports whether the caller may access the origin. Requires: Shipping.Origins, merchant scope. - GET
/api/shipping/origins/{id}/namedeprecated Ship-from origins: returns an origin's display name. Requires: Shipping.Origins, merchant scope. - POST
/api/shipping/origins/{id}/restoredeprecated Ship-from origins: restores a previously deleted origin. Requires: Shipping.Origins, Shipping.Origins.Update, merchant scope. - POST
/api/shipping/rate-quotesdeprecated Shipping rate quotes: quotes carrier rates for one lane. Requires: Shipping.RateQuotes, merchant scope.
Payments
Surcharging
Merchant credit-card surcharge configuration and notice filing.
- POST
/api/surcharging/configurationsdeprecated Surcharging: Creates a merchant's initial surcharge configuration. Requires: Surcharging.Configuration.Manage, merchant scope. - PUT
/api/surcharging/configurationsdeprecated Surcharging: Updates a merchant's rate, channel restrictions, and network policies. Requires: Surcharging.Configuration.Manage, merchant scope. - GET
/api/surcharging/configurations/force-enable/availabledeprecated Surcharging: Whether the non-production waiting-period bypass is available in this host. Requires: Surcharging.Admin.ForceEnable, merchant scope. - POST
/api/surcharging/configurations/noticesdeprecated Surcharging: Records a filed card-brand notice and starts the waiting period. Requires: Surcharging.Notice.File, merchant scope. - GET
/api/surcharging/configurations/{merchantId}deprecated Surcharging: Returns a merchant's surcharge configuration, or null when none exists. Requires: Surcharging.Configuration.View, merchant scope. - PATCH
/api/surcharging/configurations/{merchantId}deprecated Surcharging: Changes individual fields of a merchant's surcharge configuration (JSON Merge Patch, RFC 7396). Requires: Surcharging.Configuration.View, Surcharging.Configuration.Manage, merchant scope. - POST
/api/surcharging/configurations/{merchantId}/disabledeprecated Surcharging: Disables surcharging for a merchant. Requires: Surcharging.Configuration.Manage, merchant scope. - POST
/api/surcharging/configurations/{merchantId}/enabledeprecated Surcharging: Enables surcharging for a merchant. Requires: Surcharging.Configuration.Manage, merchant scope. - POST
/api/surcharging/configurations/{merchantId}/force-enabledeprecated Surcharging: Activates surcharging without waiting out the mandatory notice period. Requires: Surcharging.Admin.ForceEnable, merchant scope. - POST
/api/surcharging/configurations/{merchantId}/notices/{noticeId}/amenddeprecated Surcharging: Corrects the reference number of one filed notice without re-filing it. Requires: Surcharging.Notice.File, merchant scope. - DELETE
/api/surcharging/configurations/{merchantId}/promotion-holddeprecated Surcharging: Releases the promotion hold, so the next activation sweep promotes the merchant if the waiting period has elapsed. Requires: Surcharging.PromotionHold.Manage, merchant scope. - POST
/api/surcharging/configurations/{merchantId}/promotion-holddeprecated Surcharging: Withholds a merchant's promotion out of the notice waiting period until the hold is released. Requires: Surcharging.PromotionHold.Manage, merchant scope. - GET
/api/surcharging/configurations/{merchantId}/state-policiesdeprecated Surcharging: Returns a merchant's per-state restriction table. Requires: Surcharging.Configuration.View, merchant scope. - PUT
/api/surcharging/configurations/{merchantId}/state-policiesdeprecated Surcharging: Replaces a merchant's per-state restriction table (operator action). Requires: Surcharging.Admin.GlobalSettings, merchant scope. - GET
/api/surcharging/configurations/{merchantId}/state-policies/effectivedeprecated Surcharging: Returns a merchant's effective per-state surcharge posture. Requires: Surcharging.Admin.GlobalSettings, merchant scope. - POST
/api/surcharging/quotedeprecated Surcharging: Quotes surcharge eligibility for a card BIN prefix and amount. Requires: Surcharging.Configuration.View, merchant scope.
Payments
Tokens
Payment token vault and card-on-file management.
- GET
/api/tokensdeprecated List payment tokens No permission required. - POST
/api/tokensdeprecated Create payment token No permission required. - POST
/api/tokens/can-delete-asyncdeprecated Reports whether a token can be deleted outright. No permission required. - POST
/api/tokens/create-from-transaction-asyncdeprecated Creates a reusable token from the payment method a previous transaction stored. No permission required. - POST
/api/tokens/create-standalone-asyncdeprecated Creates a token from card or check details, with no transaction attached. No permission required. - POST
/api/tokens/deactivate-asyncdeprecated Deactivates a payment token. No permission required. - POST
/api/tokens/list/continuationdeprecated Retrieves a continuation-based page of PaymentTokens. No permission required. - POST
/api/tokens/list/continuation/countdeprecated Counts the PaymentTokens that match a filter. No permission required. - POST
/api/tokens/list/continuation/summary-countsdeprecated Counts PaymentTokens for several filters at once. No permission required. - POST
/api/tokens/reactivate-asyncdeprecated Re-enables a token that was deactivated. No permission required. - POST
/api/tokens/regenerate-asyncdeprecated Issues a replacement token that supersedes an existing one. No permission required. - POST
/api/tokens/resolve-payment-token-asyncdeprecated Looks up a payment token by its public identifier within a merchant. No permission required. - DELETE
/api/tokens/{id}deprecated Delete payment token No permission required. - GET
/api/tokens/{id}deprecated Get payment token No permission required. - PUT
/api/tokens/{id}deprecated Update payment token No permission required. - POST
/api/tokens/{id}/redactdeprecated Erases the stored card or bank account details behind a token. No permission required.
Payments
Transactions
Payment transaction processing, search, settlement, and reporting.
- GET
/api/transactionsdeprecated List transactions Requires: Transactions.Reports, merchant scope. - POST
/api/transactionsdeprecated Create transaction Requires: Transactions.Payments.Create, merchant scope. - POST
/api/transactions/from-hpp-sessiondeprecated Creates a transaction from a consumed hosted payment page session. No permission required. - POST
/api/transactions/get-by-idempotency-key-asyncdeprecated Looks up a transaction by the idempotency key the caller supplied. Requires: Transactions.Reports.View, merchant scope. - POST
/api/transactions/get-transaction-by-id-asyncdeprecated Retrieves a single transaction by its identifier. Requires: Transactions.Reports, merchant scope. - POST
/api/transactions/get-unsettled-transaction-summary-by-processor-profile-asyncdeprecated Summarizes the unsettled transactions on a merchant's processor profile. Requires: Transactions.Reports, merchant scope. - POST
/api/transactions/list/continuationdeprecated Retrieves a continuation-based page of Transactions. Requires: Transactions.Reports, merchant scope. - POST
/api/transactions/list/continuation/countdeprecated Counts the Transactions that match a filter. No permission required. - POST
/api/transactions/list/continuation/summary-countsdeprecated Counts Transactions for several filters at once. Requires: Transactions.Reports, merchant scope. - GET
/api/transactions/{id}deprecated Get transaction by ID Requires: Transactions.Reports, merchant scope. - PUT
/api/transactions/{id}/tagsdeprecated Updates only the tags on a transaction without touching other fields. Requires: Transactions.Reports, merchant scope. - GET
/api/transactions/batch-filedeprecated Gets a filtered, paged list of batch files. No permission required. - POST
/api/transactions/batch-file/uploaddeprecated Uploads a CSV batch file for transaction processing. No permission required. - DELETE
/api/transactions/batch-file/{id}deprecated Deletes a batch file and its associated blob storage content. No permission required. - GET
/api/transactions/batch-file/{id}deprecated Gets a batch file by its unique identifier. No permission required. - POST
/api/transactions/batch-file/{id}/canceldeprecated Cancels a batch file that is pending or in progress. No permission required. - GET
/api/transactions/batch-file/{id}/downloaddeprecated Downloads the original uploaded CSV batch file. No permission required. - GET
/api/transactions/batch-file/{id}/export-resultsdeprecated Exports batch processing results as a CSV file. No permission required. - POST
/api/transactions/batch-file/{id}/trigger-processingdeprecated Triggers asynchronous processing of a batch file. No permission required. - GET
/api/transactions/batch-sequencedeprecated Read the current batch-number state for a merchant + processor without issuing a value. Requires: Transactions.Settlement.ManageBatchNumber, merchant scope. - POST
/api/transactions/batch-sequencedeprecated Override the next batch number for a merchant + processor. Requires: Transactions.Settlement.ManageBatchNumber, merchant scope. - POST
/api/transactions/{id}/fraud-review/approvedeprecated Approve a held transaction, releasing it to continue into authorization. Requires: Transactions.FraudReview.Disposition, merchant scope. - POST
/api/transactions/{id}/fraud-review/declinedeprecated Decline a held transaction, rejecting the payment. Requires: Transactions.FraudReview.Disposition, merchant scope. - POST
/api/transactions/by-merchant/{merchantId}/{transactionId}/operationsdeprecated Execute a follow-up operation on an existing transaction. No permission required. - POST
/api/transactions/{id}/operationsdeprecated Legacy single-id route retained for backward compatibility. No permission required. - POST
/api/transactions/{id}/partial-approval/acceptdeprecated Accept a partial approval, keeping the reduced authorization. Requires: Transactions.PartialApproval.Acknowledge, merchant scope. - POST
/api/transactions/{id}/partial-approval/split-tenderdeprecated Start a split tender to collect the shortfall on a partial approval. Requires: Transactions.PartialApproval.Acknowledge, merchant scope. - POST
/api/transactions/{id}/partial-approval/voiddeprecated Void a partial approval, reversing the reduced authorization. Requires: Transactions.PartialApproval.Acknowledge, merchant scope. - GET
/api/transactions/reports/merchant-summarydeprecated Rolls up the window's transactions by merchant. Requires: Transactions.Reports.Summary, merchant scope. - GET
/api/transactions/reports/paytype-summarydeprecated Rolls up the window's transactions by payment type. Requires: Transactions.Reports.Summary, merchant scope. - POST
/api/transactions/settlement-overridedeprecated Apply a manual settlement-status override to one or more transactions. Requires: Transactions.Settlement.Override, merchant scope. - GET
/api/transactions/settlement-reports/batches/{settlementBatchId}deprecated Returns the full detail of one settlement batch, including the per-payment-type breakdown. Requires: Transactions.Settlement.ViewHistory, merchant scope. - GET
/api/transactions/settlement-reports/historydeprecated Returns a page of settlement batches matching the supplied filters, newest run first. Requires: Transactions.Settlement.ViewHistory, merchant scope. - POST
/api/transactions/settlements/merchants/{merchantId}/triggerdeprecated Trigger settlement for a specific merchant. Requires: Transactions.Settlement.Trigger, merchant scope. - GET
/api/transactions/settlements/open-batchesdeprecated Returns the merchant's open batch summary. Requires: Transactions.Settlement.View, merchant scope. - POST
/api/transactions/settlements/triggerdeprecated Trigger settlement for all eligible merchants. Requires: Transactions.Settlement.Trigger, merchant scope. - GET
/api/transactions/{id}/split-tenderdeprecated Get the split tender a payment belongs to. Requires: Transactions.Reports, merchant scope. - POST
/api/transactions/{id}/split-tender/continuationsdeprecated Add a payment to a split tender, collecting part of its remaining balance. Requires: Transactions.Payments.Create, merchant scope.
Payments
Transaction Statistics
The filtered transaction-statistics aggregate: count and total amount over every transaction matching a filter, grouped by transaction type, by payment type and by result code.
Reporting & Operations
Usage
Metered usage reporting: period summaries, the underlying ledger entries, and the SKU definitions they are metered against.
- GET
/api/usage/reports/dimensional-summarydeprecated Get a paged dimensional rollup for a SKU. Requires: Usage.Reports, merchant scope. - GET
/api/usage/reports/merchant-ledgerdeprecated Get paginated merchant ledger entries. Requires: Usage.Reports, merchant scope. - GET
/api/usage/reports/merchant-summarydeprecated Get a merchant's usage summary for a given period. Requires: Usage.Reports, merchant scope. - GET
/api/usage/reports/reseller-merchant-breakdowndeprecated Get per-merchant usage breakdown for a reseller. Requires: Usage.Reports, merchant scope. - GET
/api/usage/reports/reseller-summarydeprecated Get a reseller's aggregated usage summary across all their merchants. Requires: Usage.Reports, merchant scope. - GET
/api/usage/reports/skusdeprecated List all registered SKU definitions. Requires: Usage.Skus, merchant scope. - GET
/api/usage/entitlementsdeprecated List entitlements with optional filters using continuation-token paging. Requires: Usage.PlatformDefaults, merchant scope. - POST
/api/usage/entitlementsdeprecated Create a new entitlement. No permission required. - GET
/api/usage/entitlements/effectivedeprecated Resolves the effective entitlement at a given scope. Requires: Usage.PlatformDefaults, merchant scope. - DELETE
/api/usage/entitlements/{id}deprecated Delete an entitlement. No permission required. - GET
/api/usage/entitlements/{id}deprecated Get an entitlement by ID. Requires: Usage.PlatformDefaults, merchant scope. - PUT
/api/usage/entitlements/{id}deprecated Update an existing entitlement. No permission required. - GET
/api/usage/reports/ledger/exportdeprecated Export merchant ledger entries. Requires: Usage.Reports.Export, merchant scope. - GET
/api/usage/reports/summary/exportdeprecated Export the merchant SKU summary. Requires: Usage.Reports.Export, merchant scope.
Identity & Access
User Favorites
Per-user favorites API. All reads/writes are scoped to the operating user (impersonated user when impersonating, current user otherwise).
- DELETE
/api/favorites/userdeprecated Remove (unpin) a favorite for the operating user. Requires: Favorites.Manage, merchant scope. - GET
/api/favorites/userdeprecated Lists the operating user's favorites. Requires: Favorites.Manage, merchant scope. - POST
/api/favorites/userdeprecated Pin an entity as a favorite for the operating user. Requires: Favorites.Manage, merchant scope. - GET
/api/favorites/user/countdeprecated Count the operating user's favorites across every entity type. Requires: Favorites.Manage, merchant scope. - GET
/api/favorites/user/idsdeprecated List the entity ids the operating user has favorited for a single entity type. Requires: Favorites.Manage, merchant scope.
Identity & Access
Users
Back-office user administration: creating and maintaining users, assigning their roles and organization units, and managing their active sessions.
- GET
/api/account/link-userdeprecated GetAllList for User No permission required. - GET
/api/identity/usersdeprecated List users Requires: AbpIdentity.Users, host scope. - POST
/api/identity/usersdeprecated Create new user Requires: AbpIdentity.Users, AbpIdentity.Users.Create, host scope. - GET
/api/identity/users/all-claim-typesdeprecated GetAllClaimTypes for User Requires: AbpIdentity.Users, host scope. - GET
/api/identity/users/approximate-countdeprecated Gets the approximate total count of users based on the provided input. Requires: AbpIdentity.Users, host scope. - GET
/api/identity/users/assignable-rolesdeprecated Get assignable roles Requires: AbpIdentity.Users, host scope. - GET
/api/identity/users/available-organization-unitsdeprecated GetAvailableOrganizationUnits for User Requires: AbpIdentity.Users, host scope. - GET
/api/identity/users/by-email/{email}deprecated Find user by email Requires: AbpIdentity.Users, host scope. - GET
/api/identity/users/by-username/{username}deprecated Find user by username Requires: AbpIdentity.Users, host scope. - GET
/api/identity/users/continuation-listdeprecated Retrieves a paged list of users using continuation tokens for efficient pagination. Requires: AbpIdentity.Users, host scope. - GET
/api/identity/users/download-tokendeprecated GetDownloadToken for User Requires: AbpIdentity.Users, host scope. - GET
/api/identity/users/export-as-csvdeprecated GetListAsCsvFile for User No permission required. - GET
/api/identity/users/export-as-exceldeprecated GetListAsExcelFile for User No permission required. - GET
/api/identity/users/external-login-Providersdeprecated GetExternalLoginProviders for User Requires: AbpIdentity.Users, AbpIdentity.Users.Import, host scope. - POST
/api/identity/users/import-external-userdeprecated Import external user Requires: AbpIdentity.Users, AbpIdentity.Users.Import, host scope. - POST
/api/identity/users/import-users-from-filedeprecated ImportUsersFromFile for User Requires: AbpIdentity.Users, AbpIdentity.Users.Import, host scope. - GET
/api/identity/users/lookup/organization-unitsdeprecated GetOrganizationUnitLookup for User Requires: AbpIdentity.Users, host scope. - GET
/api/identity/users/lookup/rolesdeprecated GetRoleLookup for User Requires: AbpIdentity.Users, host scope. - DELETE
/api/identity/users/{id}deprecated Delete user Requires: AbpIdentity.Users, AbpIdentity.Users.Delete, host scope. - GET
/api/identity/users/{id}deprecated Get user by ID Requires: AbpIdentity.Users, host scope. - PUT
/api/identity/users/{id}deprecated Update user Requires: AbpIdentity.Users, AbpIdentity.Users.Update, host scope. - GET
/api/identity/users/{id}/accessdeprecated Checks if the user has access to the specified entity. Requires: AbpIdentity.Users, host scope. - PUT
/api/identity/users/{id}/change-passworddeprecated UpdatePassword for User Requires: AbpIdentity.Users, AbpIdentity.Users.Update, host scope. - GET
/api/identity/users/{id}/claimsdeprecated GetClaims for User Requires: AbpIdentity.Users, host scope. - PUT
/api/identity/users/{id}/claimsdeprecated Update user claims Requires: AbpIdentity.Users, AbpIdentity.Users.Update, host scope. - PUT
/api/identity/users/{id}/lock/{lockoutEnd}deprecated Lock user account Requires: AbpIdentity.Users, AbpIdentity.Users.Update, host scope. - GET
/api/identity/users/{id}/namedeprecated Gets the display name of a user by ID. Requires: AbpIdentity.Users, host scope. - GET
/api/identity/users/{id}/organization-unitsdeprecated Get user organization units Requires: AbpIdentity.Users, host scope. - POST
/api/identity/users/{id}/restoredeprecated Restores a deleted user by ID. Requires: AbpIdentity.Users, host scope. - GET
/api/identity/users/{id}/rolesdeprecated Get user roles Requires: AbpIdentity.Users, host scope. - PUT
/api/identity/users/{id}/rolesdeprecated Update user roles Requires: AbpIdentity.Users, AbpIdentity.Users.Update, host scope. - GET
/api/identity/users/{id}/two-factor-enableddeprecated GetTwoFactorEnabled for User Requires: AbpIdentity.Users, host scope. - PUT
/api/identity/users/{id}/two-factor/{enabled}deprecated SetTwoFactorEnabled for User Requires: AbpIdentity.Users, AbpIdentity.Users.Update, host scope. - PUT
/api/identity/users/{id}/unlockdeprecated Unlock user account Requires: AbpIdentity.Users, AbpIdentity.Users.Update, host scope. - GET
/api/account/sessionsdeprecated List sessions No permission required. - DELETE
/api/account/sessions/{id}deprecated Revoke for Sessions No permission required. - GET
/api/account/sessions/{id}deprecated Get session No permission required.
Payments
Wallets
Digital wallet setup and runtime: provider registrations and their platform credentials, Apple Pay certificate provisioning, merchant sessions, encrypted token receipt and the domain association file, Paze certificates and public JWKS, and the checkout snapshot a payment page reads to decide which wallets to offer.
- GET
/.well-known/apple-developer-merchantid-domain-associationdeprecated Apple Pay: serve the domain association file. No permission required. - DELETE
/api/payment-tokenization/apple-pay/domain-association-filedeprecated Apple Pay: clear the domain association file (admin). No permission required. - PUT
/api/payment-tokenization/apple-pay/domain-association-filedeprecated Apple Pay: upload the domain association file (admin). No permission required. - GET
/api/payment-tokenization/apple-pay/domain-association-file/downloaddeprecated Apple Pay: download the domain association file (admin). Requires: PaymentTokenization.PaymentTokenizations, merchant scope. - POST
/api/payment-tokenization/apple-pay/paymentdeprecated Apple Pay: receive the encrypted Apple Pay token. No permission required. - POST
/api/payment-tokenization/apple-pay/sessiondeprecated Apple Pay: create an Apple Pay merchant session. No permission required. - DELETE
/api/payment-tokenization/wallet-providers/apple-pay/certificates/api-keydeprecated Apple Pay: remove the App Store Connect API key. Requires: PaymentTokenization.SettingManagement, merchant scope. - PUT
/api/payment-tokenization/wallet-providers/apple-pay/certificates/api-keydeprecated Apple Pay: upload the App Store Connect API key. Requires: PaymentTokenization.SettingManagement, merchant scope. - GET
/api/payment-tokenization/wallet-providers/apple-pay/certificates/api-key/statusdeprecated Apple Pay: check whether the API key is uploaded. Requires: PaymentTokenization.SettingManagement, merchant scope. - POST
/api/payment-tokenization/wallet-providers/apple-pay/certificates/{type}/completedeprecated Apple Pay: complete a manual certificate request. Requires: PaymentTokenization.SettingManagement, merchant scope. - GET
/api/payment-tokenization/wallet-providers/apple-pay/certificates/{type}/csrdeprecated Apple Pay: download the pending CSR. Requires: PaymentTokenization.SettingManagement, merchant scope. - POST
/api/payment-tokenization/wallet-providers/apple-pay/certificates/{type}/generatedeprecated Apple Pay: generate or regenerate a platform certificate. Requires: PaymentTokenization.SettingManagement, merchant scope. - POST
/api/payment-tokenization/wallet-providers/apple-pay/certificates/{type}/initiatedeprecated Apple Pay: start a manual certificate signing request. Requires: PaymentTokenization.SettingManagement, merchant scope. - DELETE
/api/payment-tokenization/wallet-providers/apple-pay/certificates/{type}/pendingdeprecated Apple Pay: cancel a pending certificate request. Requires: PaymentTokenization.SettingManagement, merchant scope. - GET
/api/payment-tokenization/wallet-providers/apple-pay/certificates/{type}/statusdeprecated Apple Pay: get certificate status. Requires: PaymentTokenization.SettingManagement, merchant scope. - GET
/api/payment-tokenization/checkout-snapshot/{providerType}/{merchantId}deprecated Checkout Snapshot: returns the storefront-safe snapshot for the (provider, merchant) pair. No permission required. - GET
/.well-known/paze/{environment}/jwks.jsondeprecated Paze: public JWKS for an environment. No permission required. - POST
/api/payment-tokenization/wallet-providers/paze/certificates/{environment}/completedeprecated Paze: complete the Production round-trip by merging a CA-signed certificate. Requires: PaymentTokenization.SettingManagement, merchant scope. - GET
/api/payment-tokenization/wallet-providers/paze/certificates/{environment}/csrdeprecated Paze: download the pending CSR (Production). Requires: PaymentTokenization.SettingManagement, merchant scope. - POST
/api/payment-tokenization/wallet-providers/paze/certificates/{environment}/generatedeprecated Paze: generate or regenerate a certificate. Requires: PaymentTokenization.SettingManagement, merchant scope. - DELETE
/api/payment-tokenization/wallet-providers/paze/certificates/{environment}/pendingdeprecated Paze: cancel a pending CSR round-trip. Requires: PaymentTokenization.SettingManagement, merchant scope. - GET
/api/payment-tokenization/wallet-providers/paze/certificates/{environment}/publicdeprecated Paze: download the active public certificate to register with Paze. Requires: PaymentTokenization.SettingManagement, merchant scope. - GET
/api/payment-tokenization/wallet-providers/paze/certificates/{environment}/statusdeprecated Paze: get the live lifecycle status. Requires: PaymentTokenization.SettingManagement, merchant scope. - GET
/api/payment-tokenization/wallet-providers/paze/jwks/{environment}deprecated Paze: admin preview of an environment's JWKS, for verifying it before registering the URL with Paze. Requires: PaymentTokenization.SettingManagement, merchant scope. - GET
/api/payment-tokenization/wallet-providers/paze/jwks/{environment}/downloaddeprecated Paze: download an environment's JWKS as a `.json` file attachment (admin, from the Settings panel). Requires: PaymentTokenization.SettingManagement, merchant scope. - GET
/api/payment-tokenization/wallet-providersdeprecated Get a list of WalletProviderRegistrations Requires: PaymentTokenization.PaymentTokenizations, merchant scope. - POST
/api/payment-tokenization/wallet-providersdeprecated Create a WalletProviderRegistration Requires: PaymentTokenization.PaymentTokenizations, PaymentTokenization.PaymentTokenizations.Create, merchant scope. - POST
/api/payment-tokenization/wallet-providers/list/continuationdeprecated Retrieves a continuation-based page of WalletProviderRegistrations. Requires: PaymentTokenization.PaymentTokenizations, merchant scope. - POST
/api/payment-tokenization/wallet-providers/list/continuation/countdeprecated Counts the WalletProviderRegistrations that match a filter. Requires: PaymentTokenization.PaymentTokenizations, merchant scope. - POST
/api/payment-tokenization/wallet-providers/list/continuation/summary-countsdeprecated Counts WalletProviderRegistrations for several filters at once. Requires: PaymentTokenization.PaymentTokenizations, merchant scope. - GET
/api/payment-tokenization/wallet-providers/platform/{providerType}deprecated Reads the primary platform-level registration for a wallet provider. Requires: PaymentTokenization.PaymentTokenizations, merchant scope. - GET
/api/payment-tokenization/wallet-providers/providersdeprecated Lists every wallet provider this environment supports. Requires: PaymentTokenization.PaymentTokenizations, merchant scope. - DELETE
/api/payment-tokenization/wallet-providers/{id}deprecated Delete a WalletProviderRegistration Requires: PaymentTokenization.PaymentTokenizations, PaymentTokenization.PaymentTokenizations.Delete, merchant scope. - GET
/api/payment-tokenization/wallet-providers/{id}deprecated Get a WalletProviderRegistration Requires: PaymentTokenization.PaymentTokenizations, merchant scope. - PUT
/api/payment-tokenization/wallet-providers/{id}deprecated Update a WalletProviderRegistration Requires: PaymentTokenization.PaymentTokenizations, PaymentTokenization.PaymentTokenizations.Update, merchant scope. - GET
/api/payment-tokenization/wallet-providers/{id}/accessdeprecated Check WalletProviderRegistration access Requires: PaymentTokenization.PaymentTokenizations, merchant scope. - DELETE
/api/payment-tokenization/wallet-providers/{id}/domainsdeprecated Removes domains from a merchant's wallet registration. Requires: PaymentTokenization.PaymentTokenizations, PaymentTokenization.PaymentTokenizations.Update, merchant scope. - GET
/api/payment-tokenization/wallet-providers/{id}/namedeprecated Get a WalletProviderRegistration name by id Requires: PaymentTokenization.PaymentTokenizations, merchant scope. - POST
/api/payment-tokenization/wallet-providers/{id}/restoredeprecated Restore a deleted WalletProviderRegistration Requires: PaymentTokenization.PaymentTokenizations, PaymentTokenization.PaymentTokenizations.Update, merchant scope. - POST
/api/payment-tokenization/wallet-providers/{id}/syncdeprecated Refreshes a registration from the wallet provider. Requires: PaymentTokenization.PaymentTokenizations, PaymentTokenization.PaymentTokenizations.Update, merchant scope.