New here? The Quickstart walks you from creating
OAuth credentials to your first successful API call in about 10 minutes.
/mcp/v1 and the MCP OAuth metadata.
Access-device validation also lives under /public/v1, but it is a separate
device contract. QR gates, badge scanners, and door controllers use
/public/v1/access/* with device-key authentication.
Route families
What you can call
Rather than maintaining a duplicate endpoint list here, use the API Reference tab — it is generated from the OpenAPI contract and always matches the live surface. The API covers these domains:
Invoice and payment list/detail resources remain read-focused. Public API write
actions for reminders, invoice copies, payment requests, subscription action
requests, memberships, products, and credits use guarded DTOs and reject raw
pricing/provider internals. Invoice PDF access returns metadata for an existing
generated PDF and a short-lived download URL; it does not create or regenerate
invoice PDFs.
Response shape
OAuth token responses use the standard OAuth shape:/public/v1/access/* response and auth contract. See the
Webhooks page for outbound webhook management
resources, which do use the Bearer Public API envelope.
Rate limits
Bearer Public API resource requests are currently limited per Public API client to 10 requests per second. Successful and failed authenticated resource responses include rate-limit data inmeta.rateLimit and both standard and
legacy rate-limit headers: