/api/v1/businesses/register
auth: jwtFirst-user business registration with TaxCore verification. Validates the supplied PFX/PAC/UID against V-SDC, creates the business, promotes the calling user to Administrator, and returns fresh JWT tokens. No role guard — the caller has no businessId yet.
handlers: BusinessesController.registerBusiness
| name | required | default | description |
|---|---|---|---|
file bodymultipart .pfx | yes | — | PFX certificate file (.pfx / .p12). Converted RC2 → 3DES on the server before storage. |
name bodystring | yes | — | Business display name. |
tin bodystring | yes | — | Tax Identification Number. Must be unique across all businesses. |
pac bodystring | yes | — | PAC (Privileged Access Code) issued by TaxCore. |
uid bodystring | yes | — | 8-character uppercase alphanumeric UID assigned by TaxCore. Cross-checked against V-SDC `/status`. |
pfxPassword bodystring | yes | — | Passphrase for the uploaded PFX certificate. |
street bodystring | null | no | — | Optional street address. |
city bodystring | null | no | — | Optional city. |
country bodystring | null | no | — | ISO 3166-1 alpha-2 code (e.g. 'VU', 'AU'). |
currencyCode bodystring | no | VUV | ISO 4217 three-letter currency code. Defaults to 'VUV' when omitted. |
APIResponseDTO<{ business: PublicBusinessDTO; accessToken: string; refreshToken: string }>APIErrorAPIError/api/v1/businesses
auth: jwt (administrator)Create an additional business. Used after the first business is registered. TIN must be unique across all businesses.
handlers: BusinessesController.create
Request body type: CreateBusinessRequest
| name | required | default | description |
|---|---|---|---|
name bodystring | yes | — | Business display name. |
tin bodystring | yes | — | Tax Identification Number. Must be unique across all businesses. |
street bodystring | null | no | — | Street address. |
city bodystring | null | no | — | City. |
country bodystring | null | no | — | ISO 3166-1 alpha-2 code (e.g. 'VU'). |
currencyCode bodystring | no | VUV | ISO 4217 three-letter currency code. Defaults to 'VUV' when omitted. |
APIResponseDataObject<PublicBusinessDTO>APIErrorAPIError/api/v1/businesses
auth: jwtReturns the single business the authenticated user belongs to. Users without a businessId receive an empty list. Returned as an APIResponse list shape for FE consistency.
handlers: BusinessesController.list
No parameters.
APIResponseDataList<PublicBusinessDTO>/api/v1/businesses/:businessId
auth: jwt (administrator | update_business_settings)Partially update non-credential business settings — name, address fields, currencyCode, and the demo Xero tenant id used for Training routing. At least one field must be provided.
handlers: BusinessesController.updateSettings
| name | required | default | description |
|---|---|---|---|
businessId pathuuid | yes | — | Target business UUID. Must match the caller's JWT businessId — Administrators bypass via requireBusinessAccess. |
name bodystring | no | — | Updated display name (non-empty). |
street bodystring | null | no | — | Pass null to clear. |
city bodystring | null | no | — | Pass null to clear. |
country bodystring | null | no | — | ISO 3166-1 alpha-2 code, or null to clear. |
currencyCode bodystring | no | — | ISO 4217 three-letter currency code. |
demoXeroTenantId bodyuuid | null | no | — | Xero tenant id that routes invoices through V-SDC Training mode. Empty string is normalised to null. Pass null to disable Training routing. |
APIResponseDataObject<PublicBusinessDTO>APIErrorAPIError/api/v1/businesses/:businessId/taxcore-config
auth: jwt (administrator | update_taxcore_credentials)Update V-SDC credentials for a business. multipart/form-data — every field optional, at least one required. When `pac` is supplied, the server verifies it against V-SDC `/status` (mTLS) before persisting. When `businessUID` is also supplied, `status.uid` is cross-checked against it.
handlers: BusinessesController.updateTaxcoreConfig
| name | required | default | description |
|---|---|---|---|
businessId pathuuid | yes | — | Target business UUID. |
file bodymultipart .pfx | no | — | New PFX certificate. Converted RC2 → 3DES and written under CERT_STORAGE_DIR; only the UUID filename is stored in DB. Replaces any prior cert. |
password bodystring | null | no | — | PFX passphrase (also stored as VsdcPfxPassword). Null clears the field. Write-only — never returned. |
pac bodystring | null | no | — | PAC. Verified against V-SDC `/status` before being persisted. Null clears. Write-only. |
businessUID bodystring | null | no | — | 8-character uppercase alphanumeric UID. Cross-checked against status.uid when pac is also supplied. |
APIResponseDataObject<PublicBusinessDTO>APIErrorAPIErrorAPIError/api/v1/businesses/:businessId/default-certificate
auth: jwt (administrator | update_taxcore_credentials)Registration wizard step 2 shortcut. Creates a Certificate row against the business's default Location and mirrors the same fields into the legacy `Businesses.Vsdc*` columns so the consumer's fallback path keeps working.
handlers: BusinessesController.createDefaultCertificate
| name | required | default | description |
|---|---|---|---|
businessId pathuuid | yes | — | Target business UUID. |
file bodymultipart .pfx | yes | — | PFX certificate file. |
password bodystring | yes | — | PFX passphrase. |
pac bodystring | yes | — | PAC issued by TaxCore. |
uid bodystring | yes | — | 8-character uppercase alphanumeric UID. |
name bodystring | no | — | Optional certificate display name. Falls back server-side to the default Location's name. |
APIResponseDataObject<PublicCertificateDTO>APIErrorAPIError