REST API · OpenAPI schema

Build on PrivateCore

A REST API and one principle: it runs on your instance, never on a server shared with other customers. Online, that is the server rented for you; with the Mac mini, it is the machine at your counter. The keys are yours, and you revoke them in one click.

What the API lets you do

  • Connect your custom tools: an Airtable base, a Slack, a legacy ERP, a homegrown Grafana dashboard.
  • Automate what you repeat: generate the month's recurring invoices, trigger a follow-up when a quote stays unsigned for 7 days, sync stock with a supplier.
  • Build internal apps: a mobile app for the floor team, a booking widget on your showcase site, a custom multi-site dashboard for management.
  • Audit and export: pull your entire accounting as JSON, generate a French FEC ledger export on demand, mirror your database into your own data warehouse.

Two call examples

TypeScript

fetch
TypeScript
const base = 'https://votre-instance';
const headers = { Authorization: `Bearer ${process.env.PRIVATECORE_API_KEY}` };

// List customers (key with read:crm scope)
const { items, next_cursor } = await fetch(`${base}/api/public/v1/clients?limit=50`, { headers })
  .then((r) => r.json());

Python

requests
Python
import os
import requests

base = "https://votre-instance"
headers = {"Authorization": f"Bearer {os.environ['PRIVATECORE_TOKEN']}"}

# Export the FEC ledger for the current financial year
fec = requests.get(f"{base}/api/fec/export", params={"year": 2026}, headers=headers)
open("fec_2026.txt", "wb").write(fec.content)

Authentication

Scoped, revocable API keys, with an expiry date if you want one.

  • Creation: one key per integration, from the Developer area of your instance. You pick its scopes (read customers, bookings, and so on).
  • Never readable afterwards: the key is shown once, when it is created. Your instance keeps only a SHA-256 fingerprint. If you lose it, you revoke it and create another.
  • Tracking: each key keeps its last-used date, so you can spot the ones nobody uses any more.
  • Instant revocation: one click. The token becomes invalid immediately.

Rate limits

No billed quota. Each key is limited to 60 requests per minute (adjustable on the instance), so a runaway script does not slow the interface down for other users.

Beyond that, the API answers 429 with a Retry-After header: the script waits a minute and resumes.

Documentation & status

  • Full docs: /docs on your instance (OpenAPI reference generated from the code).
  • Changelog: every backend release exposes an /api/v1/changelog endpoint.
  • OpenAPI: OpenAPI 3.1 spec available in the clear at /api/openapi.json. Compatible with Postman, Insomnia, third-party code generators.
  • Status: the API exposes health checks (/health, /health/ready) that a monitoring tool can query.

Ready to take back control?

A bespoke install, an answer from the founder, and a Mac Mini you buy yourself or we deliver configured.