--- updatedAt: 2026-08-25T01:04:28.000Z agentTools: projectIndex: https://docs.rekaz.io/llms.txt --- # Getting started Use the Rekaz Merchant API to read the catalog and transaction history, manage customers, and create reservations and subscriptions. It also provides Rekaz-hosted checkout links and signed webhooks for business events. ## Public API URL All merchant public endpoints use . ## Authentication Every request requires Basic authentication, the `__tenant` header, and `Accept: application/json`. The Basic credential encodes the API key and secret. Keep both credentials on your server; never embed them in browser or mobile code. ## Read transactions Use GET to list non-draft transactions, or GET {id} to fetch one transaction. Transactions include customer details, totals, currency, items, payments, CreatedAt, and UpdatedAt. Status, payment status, source, payment type, and payment method values are returned as strings. All date-time values are UTC. The list endpoint accepts CreatedMin, CreatedMax, UpdatedMin, UpdatedMax, Statuses, PaymentStatuses, CustomerId, BranchId, TransactionNumber, SortBy, SortDirection, SkipCount, and MaxResultCount. MaxResultCount cannot exceed 100. ## Incremental transaction sync For the first import, sort by UpdatedAt in ascending order and read every page. Save the greatest UpdatedAt value after processing the complete result set. For later imports, send the saved timestamp as UpdatedMin, set SortBy to UpdatedAt and SortDirection to Asc, and paginate with SkipCount and MaxResultCount. UpdatedMin is inclusive, so transactions at the saved timestamp can appear again. Deduplicate by transaction Id and UpdatedAt, and make repeated processing safe. Creating, editing, or deleting a pending payment updates the parent transaction's UpdatedAt value, so the next sync includes that transaction. ## Transaction webhooks TransactionCreatedEvent, TransactionUpdatedEvent, TransactionPaidEvent, TransactionRefundedEvent, and TransactionCancelledEvent notify you when transactions change. TransactionUpdatedEvent also covers pending payment creation, editing, and deletion. Webhook deliveries include X-Rekaz-Signature. Verify the HMAC-SHA256 signature over the exact raw request body before processing it. Find the signing secret in Settings > API Keys > Webhook. See for receiver setup and secret rotation. ## Integration scope The Merchant API is for server-to-server integrations. Rekaz returns hosted checkout URLs where applicable. This API has no endpoints for card processing, refunds, invoice retrieval, or marking orders as externally paid. Make your first authenticated request with . Browse the endpoint and request schemas at .