Partner API

Postman collection

One collection for the whole Partner API: authenticate as your organization, register customers, establish consent, send them to checkout and call the business APIs (contracts, payments, balance).

Before you start

Your organization needs an API client (a client_id and client_secret). Create one in the Waffy business portal under Settings, API clients. The secret is shown only once, so copy it then. If you can't create a client, contact Waffy.

Set it up in Postman

  1. Download the collection above and import it into Postman (Import, then choose the file).
  2. Sign in to this site and open the dashboard. Under Your API clients, press Environment on the client you want to use. This downloads Waffy Partner API - {Dev|Stg|Prod}.postman_environment.json with the URLs for that environment, your client_id, organization_code, org_account_id and org_admin_username already filled in.
  3. Import the environment file, then select it in the environment dropdown (top right).
  4. Fill in the two secrets, client_secret and org_admin_password. They are never included in the download.
  5. Run Authentication, Get Org Token. The token is saved for the other requests automatically.

Put your own values in the environment, not in the collection: one collection works for every environment, and each environment needs its own client credentials. Don't share a filled-in Prod environment file.

Environment variables

VariableMeaning
id_base_urlWaffy ID base URL (token endpoint and the customer, OTP and consent endpoints)
auth_base_urlAuthentication service (profile calls)
api_base_urlBusiness API (contracts, payments, balance)
checkout_base_urlHosted checkout page
client_idYour organization’s API client
client_secretIts secret (secret field)
org_admin_usernameLogin of your organization admin, same as in the business portal
org_admin_passwordIts password (secret field)
organization_codeYour organization’s short code
org_account_idYour organization’s account id, used by settle contract

Environments

EnvironmentWaffy IDAuthAPICheckout
Dev (sandbox)https://id-dev.waffyapp.comhttps://dev-auth.waffyapp.comhttps://dev-api.waffyapp.comhttps://external-dev.waffyapp.com
Stghttps://id-stg.waffyapp.comhttps://auth-stg.waffyapp.comhttps://api-stg.waffyapp.comhttps://external-stg.waffyapp.com
Prodhttps://id.waffyapp.comhttps://auth.waffyapp.comhttps://api.waffyapp.comhttps://external.waffyapp.com

Quick start

  1. Get an org token with client_credentials.
  2. Register or link the customer (POST waffy-partner/customers). Leave consentMethod out for now.
  3. Establish consent, one of three ways: chain it into step 2 with "consentMethod": "sms", verify an OTP server to server (otp/send then otp/verify), or let the customer log in at checkout.
  4. Get a payment ticket for the checkout redirect.
  5. Call the business APIs with a client admin token.

Each step is explained, with the token it needs and its errors, in Authentication.

What is in the collection

FolderRequests
AuthenticationGet Org Token, Register / Link Customer, Register / Link Provider, Send OTP, Verify OTP, Send Consent Link (resend), Get Payment Ticket, Get Client Admin Token
ConsentView, Approve and Reject consent (reference only, for testing without a device)
ProfileUpdate Bank Account, Add User Address (as your organization)
Complex Contractscreate contract, create milestone, add parties, get contract details, get milestones, accept, reject, settle (client admin token)
paymentstart payment url, create withdrawal (client admin token)
BalanceBalance, Balance History (client admin token)

Using curl instead

Every request has a curl equivalent. Export the same names as the Postman variables once per session:

bash
export ID_BASE_URL=https://id-dev.waffyapp.com      # dev; use the stg/prod values above otherwise
export API_BASE_URL=https://dev-api.waffyapp.com
export AUTH_BASE_URL=https://dev-auth.waffyapp.com
export CLIENT_ID=<your client_id>
export CLIENT_SECRET=<your client_secret>

Older collection (deprecated)

The earlier demo collection uses the legacy /oauth/token authentication, which is deprecated. Use it only for an integration that has not moved to the Partner API yet. New integrations should use the collection above.

Download the legacy demo collection