vsmsconnect — API — myob

← all endpoints

GET/api/v1/accounting/myob/start auth: jwt (administrator)

Begin a MYOB AccountRight Live OAuth2 authorisation flow. Generates PKCE + state, returns the MYOB authorisation URL. Rate-limited (10/min open bucket).

handlers: MyobAuthController.start

Inputs

No parameters.

Outputs

200
APIResponseDataObject<MyobStartResponse>
`{ authorizationUrl }`.
409
APIError
BUSINESS_CONTEXT_REQUIRED.
429
APIError
Rate limit exceeded.
GET/api/v1/accounting/myob/callback auth: none

MYOB OAuth callback. Validates state, exchanges the code, upserts a MyobConnections row per discovered company file, then 302-redirects (desktop) or serves a 200 text/html bridge page (mobile) opening `vsms://auth/myob/{success|failure}`.

handlers: MyobAuthController.callback

Inputs

namerequireddefaultdescription
code query
string
no—OAuth authorisation code returned by MYOB.
state query
string
no—PKCE state issued by `/start`.
error query
string
no—Set by MYOB on failure or user denial.

Outputs

302
redirect
Desktop UA — redirect to `${MYOB_FRONTEND_WEB_BASE_URL}/auth/myob/{success|failure}`.
200
text/html
Mobile UA — HTML bridge to deep link with web fallback.
GET/api/v1/accounting/myob/status auth: jwt

MYOB connection summary — whether a connection exists, the file list, and the current `autoFiscaliseInvoices` flag.

handlers: MyobAuthController.status

Inputs

No parameters.

Outputs

200
APIResponseDataObject<MyobStatusResponse>
Connection summary including `connected`, `activeFile`, `files[]`, `autoFiscaliseInvoices`.
409
APIError
BUSINESS_CONTEXT_REQUIRED.
GET/api/v1/accounting/myob/files auth: jwt

List every MYOB company file authorised for the caller's business, each carrying `isActive` indicating the current sync target.

handlers: MyobAuthController.listFiles

Inputs

No parameters.

Outputs

200
APIResponseDataList<MyobFileSummary>
Company file list.
POST/api/v1/accounting/myob/files/:myobFileId/activate auth: jwt (administrator)

Switch the active MYOB company file for the caller's business. Fires `MYOB_FILE_ACTIVATED` audit.

handlers: MyobAuthController.activateFile

Inputs

namerequireddefaultdescription
myobFileId path
string
yes—MYOB company file ID (1–100 chars).

Outputs

200
APIResponseDataObject<MyobFileSummary>
Newly active file.
404
APIError
File not found for this business.
DELETE/api/v1/accounting/myob/connection auth: jwt (administrator)

Soft-deactivate all MYOB connections for the caller's business (`IsActive=0`). Rows are retained for history. Fires `MYOB_DISCONNECTED` audit.

handlers: MyobAuthController.disconnect

Inputs

No parameters.

Outputs

200
APIResponseDataObject<{ deactivatedCount: number }>
Number of rows deactivated.