Developer
One credential for REST, webhooks and AI assistants.
Trabalance's API is the same door the product uses: creating an invoice through it runs numbering, approvals, journal posting and settlement exactly as the dashboard does. Nothing you can do through the API is something a user of that business could not do — a credential only ever narrows the rights of the person it is bound to.
Two ways in
| Credential | Who uses it | How you get it |
|---|---|---|
| API key (`tk_live_…`) | A business calling the API for itself, or a partner the business hands a key to. Machine-to-machine. | A Super Administrator mints it in Settings → API keys & webhooks. |
| OAuth 2.0 app | Your product, authorised by users of many different businesses. | Create the app in the developer portal; users authorise it; you exchange the code for tokens. |
Both resolve to the same thing on our side: a user, their business, and their rights today. If that user is demoted, every credential bound to them loses the same rights — a key does not outlive its owner's permissions.
What's in v1
| Resource | Scope | What you can do |
|---|---|---|
| /api/v1/customers | sales_customers | List, read, create, statement of account |
| /api/v1/vendors | purchases_vendors | List, read, create, statement of account |
| /api/v1/invoices | sales_invoices | List, read, create, download the PDF |
| /api/v1/items | ops_products | List, read, create, update, stock, pricing |
| /api/v1/receipts | sales_receipts | Money in against invoices — list, read, record |
| /api/v1/payments | purchases_payments | Money out against bills — list, read, record |
| /api/v1/bank-feeds | finance_banking | Cash-flow accounts, push statement lines |
| /api/v1/webhooks | the Webhooks key option | Event catalogue, subscribe, unsubscribe, ping |
/api/v1/webhooks is the odd one out: it is reached with a capability grant on an API key rather than a data scope, and it is how Zapier, Make and any app manage their own subscriptions. Everything else is a data resource behind a feature code.
Only what is verified end-to-end is published. More resources arrive as they pass the same gate — the discovery document (GET /api/v1) is always the source of truth for what exists.
The OpenAPI document is generated from the request contracts the API validates with; the SDKs and llms.txt are generated from the OpenAPI document. If a page here disagrees with https://api.trabalance.com/api/v1/openapi.json, the document is right.
Where to start
Getting started
Mint a key, make your first call in two minutes.
OAuth applications
Build an app that any Trabalance business can connect.
Webhooks
Signed, retried, logged deliveries for every event that matters.
No code at all
Zapier and Make run on the same API, with the same producers behind them.
Resources
Customers, invoices, items, money in and out, bank feeds.
AI assistants (MCP)
Connect an assistant to a business's books, with real permissions.