/api/v1/accounting/myob/start
auth: jwt (administrator)Begin a MYOB AccountRight Live OAuth2 authorisation flow. Generates PKCE + state, returns the MYOB authorisation URL. Rate-limited (10/min open bucket).
handlers: MyobAuthController.start
No parameters.
APIResponseDataObject<MyobStartResponse>APIErrorAPIError/api/v1/accounting/myob/callback
auth: noneMYOB OAuth callback. Validates state, exchanges the code, upserts a MyobConnections row per discovered company file, then 302-redirects (desktop) or serves a 200 text/html bridge page (mobile) opening `vsms://auth/myob/{success|failure}`.
handlers: MyobAuthController.callback
| name | required | default | description |
|---|---|---|---|
code querystring | no | — | OAuth authorisation code returned by MYOB. |
state querystring | no | — | PKCE state issued by `/start`. |
error querystring | no | — | Set by MYOB on failure or user denial. |
redirecttext/html/api/v1/accounting/myob/status
auth: jwtMYOB connection summary — whether a connection exists, the file list, and the current `autoFiscaliseInvoices` flag.
handlers: MyobAuthController.status
No parameters.
APIResponseDataObject<MyobStatusResponse>APIError/api/v1/accounting/myob/files
auth: jwtList every MYOB company file authorised for the caller's business, each carrying `isActive` indicating the current sync target.
handlers: MyobAuthController.listFiles
No parameters.
APIResponseDataList<MyobFileSummary>/api/v1/accounting/myob/files/:myobFileId/activate
auth: jwt (administrator)Switch the active MYOB company file for the caller's business. Fires `MYOB_FILE_ACTIVATED` audit.
handlers: MyobAuthController.activateFile
| name | required | default | description |
|---|---|---|---|
myobFileId pathstring | yes | — | MYOB company file ID (1–100 chars). |
APIResponseDataObject<MyobFileSummary>APIError/api/v1/accounting/myob/connection
auth: jwt (administrator)Soft-deactivate all MYOB connections for the caller's business (`IsActive=0`). Rows are retained for history. Fires `MYOB_DISCONNECTED` audit.
handlers: MyobAuthController.disconnect
No parameters.
APIResponseDataObject<{ deactivatedCount: number }>