Skip to main content
LedgerFlow API
Developer documentation

Build against a predictable gateway.

The public contract is OpenAPI 3.2.1 JSON. Each installed plugin may further restrict allowed methods and provider paths.

Authentication & scopes

Send X-API-Key. Keys are tenant-bound, can be scoped to specific service plugin IDs, can expire, and can be rotated/revoked. Raw key material is displayed once.

Request IDs & errors

Every response carries X-Request-ID. API errors use application/problem+json with stable code, HTTP status, detail and request ID.

Limits

Your plan controls requests/second and monthly included requests. 429 responses include Retry-After. JSON writes are limited to 1 MB and bounded depth/collection sizes. Provider responses are also capped by plugin policy.

Idempotency & retries

For POST/PUT/PATCH/DELETE, use an Idempotency-Key when a write may be retried. Identical requests replay the stored result; changing the request while reusing the key returns 409. Retry transport/5xx failures with bounded exponential backoff only when the operation is safe to repeat.

Usage & billing

Successful and failed provider attempts are metered with request ID, service/endpoint, status, latency, provider cost and configured customer charge. Included usage and overage behavior come from the current subscription plan.

Pagination

The platform gateway does not invent pagination for provider APIs. Provider-specific pagination parameters and response fields must be documented by the installed service/plugin.

Versioning & deprecation

Breaking contract changes require a new API/plugin version or a documented migration. Deprecation notices should identify the replacement, deprecation date and planned sunset date.

Webhooks

Customer webhook endpoints use HTTPS and encrypted signing secrets. Verify signatures/timestamps and deduplicate delivery IDs. Deliveries use bounded retry/backoff, dead-letter handling and manual replay.

Support & escalation

Keep the request ID, UTC timestamp, service/plugin ID and HTTP status. Do not send API keys, provider secrets, passwords or raw session data to support. Use the Contact page or your documented support channel.

Available API services

ServiceVersionBase routeState
No public API services are installed yet.

Never include API keys or provider secrets in examples, URLs, support notes, or logs. For escalation, keep the request ID, UTC timestamp, service ID and HTTP status.