Open dashboard

Getting started

Use the Rekaz Merchant API to read the catalog and transaction history, manage customers, and create reservations and subscriptions. It also provides Rekaz-hosted checkout links and signed webhooks for business events.

Public API URL

All merchant public endpoints use https://platform.rekaz.io/api/public.

Authentication

Every request requires Basic authentication, the __tenant header, and Accept: application/json. The Basic credential encodes the API key and secret. Keep both credentials on your server; never embed them in browser or mobile code.

Read transactions

Use GET https://platform.rekaz.io/api/public/transactions to list non-draft transactions, or GET https://platform.rekaz.io/api/public/transactions/{id} to fetch one transaction.

Transactions include customer details, totals, currency, items, payments, CreatedAt, and UpdatedAt. Status, payment status, source, payment type, and payment method values are returned as strings. All date-time values are UTC.

The list endpoint accepts CreatedMin, CreatedMax, UpdatedMin, UpdatedMax, Statuses, PaymentStatuses, CustomerId, BranchId, TransactionNumber, SortBy, SortDirection, SkipCount, and MaxResultCount. MaxResultCount cannot exceed 100.

Incremental transaction sync

For the first import, sort by UpdatedAt in ascending order and read every page. Save the greatest UpdatedAt value after processing the complete result set.

For later imports, send the saved timestamp as UpdatedMin, set SortBy to UpdatedAt and SortDirection to Asc, and paginate with SkipCount and MaxResultCount. UpdatedMin is inclusive, so transactions at the saved timestamp can appear again. Deduplicate by transaction Id and UpdatedAt, and make repeated processing safe.

Creating, editing, or deleting a pending payment updates the parent transaction's UpdatedAt value, so the next sync includes that transaction.

Transaction webhooks

TransactionCreatedEvent, TransactionUpdatedEvent, TransactionPaidEvent, TransactionRefundedEvent, and TransactionCancelledEvent notify you when transactions change. TransactionUpdatedEvent also covers pending payment creation, editing, and deletion.

Webhook deliveries include X-Rekaz-Signature. Verify the HMAC-SHA256 signature over the exact raw request body before processing it. Find the signing secret in Settings > API Keys > Webhook. See https://docs.rekaz.io/legacy/webhooks for receiver setup and secret rotation.

Integration scope

The Merchant API is for server-to-server integrations. Rekaz returns hosted checkout URLs where applicable. This API has no endpoints for card processing, refunds, invoice retrieval, or marking orders as externally paid.

Make your first authenticated request with https://docs.rekaz.io/legacy/quick-start. Browse the endpoint and request schemas at https://docs.rekaz.io/legacy/reference/.