Postman collection
One collection for the whole Partner API: authenticate as your organization, register customers, establish consent, send them to checkout and call the business APIs (contracts, payments, balance).
Before you start
client_id and client_secret). Create one in the Waffy business portal under Settings, API clients. The secret is shown only once, so copy it then. If you can't create a client, contact Waffy.Set it up in Postman
- Download the collection above and import it into Postman (Import, then choose the file).
- Sign in to this site and open the dashboard. Under Your API clients, press Environment on the client you want to use. This downloads
Waffy Partner API - {Dev|Stg|Prod}.postman_environment.jsonwith the URLs for that environment, yourclient_id,organization_code,org_account_idandorg_admin_usernamealready filled in. - Import the environment file, then select it in the environment dropdown (top right).
- Fill in the two secrets,
client_secretandorg_admin_password. They are never included in the download. - Run Authentication, Get Org Token. The token is saved for the other requests automatically.
Put your own values in the environment, not in the collection: one collection works for every environment, and each environment needs its own client credentials. Don't share a filled-in Prod environment file.
Environment variables
| Variable | Meaning |
|---|---|
id_base_url | Waffy ID base URL (token endpoint and the customer, OTP and consent endpoints) |
auth_base_url | Authentication service (profile calls) |
api_base_url | Business API (contracts, payments, balance) |
checkout_base_url | Hosted checkout page |
client_id | Your organization’s API client |
client_secret | Its secret (secret field) |
org_admin_username | Login of your organization admin, same as in the business portal |
org_admin_password | Its password (secret field) |
organization_code | Your organization’s short code |
org_account_id | Your organization’s account id, used by settle contract |
Environments
| Environment | Waffy ID | Auth | API | Checkout |
|---|---|---|---|---|
| Dev (sandbox) | https://id-dev.waffyapp.com | https://dev-auth.waffyapp.com | https://dev-api.waffyapp.com | https://external-dev.waffyapp.com |
| Stg | https://id-stg.waffyapp.com | https://auth-stg.waffyapp.com | https://api-stg.waffyapp.com | https://external-stg.waffyapp.com |
| Prod | https://id.waffyapp.com | https://auth.waffyapp.com | https://api.waffyapp.com | https://external.waffyapp.com |
Quick start
- Get an org token with
client_credentials. - Register or link the customer (
POST waffy-partner/customers). LeaveconsentMethodout for now. - Establish consent, one of three ways: chain it into step 2 with
"consentMethod": "sms", verify an OTP server to server (otp/sendthenotp/verify), or let the customer log in at checkout. - Get a payment ticket for the checkout redirect.
- Call the business APIs with a client admin token.
Each step is explained, with the token it needs and its errors, in Authentication.
What is in the collection
| Folder | Requests |
|---|---|
| Authentication | Get Org Token, Register / Link Customer, Register / Link Provider, Send OTP, Verify OTP, Send Consent Link (resend), Get Payment Ticket, Get Client Admin Token |
| Consent | View, Approve and Reject consent (reference only, for testing without a device) |
| Profile | Update Bank Account, Add User Address (as your organization) |
| Complex Contracts | create contract, create milestone, add parties, get contract details, get milestones, accept, reject, settle (client admin token) |
| payment | start payment url, create withdrawal (client admin token) |
| Balance | Balance, Balance History (client admin token) |
Using curl instead
Every request has a curl equivalent. Export the same names as the Postman variables once per session:
export ID_BASE_URL=https://id-dev.waffyapp.com # dev; use the stg/prod values above otherwise export API_BASE_URL=https://dev-api.waffyapp.com export AUTH_BASE_URL=https://dev-auth.waffyapp.com export CLIENT_ID=<your client_id> export CLIENT_SECRET=<your client_secret>
Older collection (deprecated)
The earlier demo collection uses the legacy /oauth/token authentication, which is deprecated. Use it only for an integration that has not moved to the Partner API yet. New integrations should use the collection above.