The Samloryx OS API gives a company's own integrations read access to what it has in the platform: the people and companies it deals with, its sites, documents and obligations, its matched tenders, and the catalogue of agents working for it. One key, three scopes, one company's data — never anybody else's.
curl https://api.samloryx.co.za/api/v1/me \
-H "X-API-Key: $SAMLORYX_API_KEY"{
"displayName": "Accounting sync",
"tenant": "Thabeng Civils",
"roles": ["API"],
"scopes": ["graph.read", "workspaces.read"]
}v1 is deliberately small. Everything in the left column is running and documented; nothing in the right column exists yet, and we would rather say so than have you plan around it.
application/problem+json with a correlation id.In the app, under Developers. They choose which of the three scopes it carries. The key is shown once.
Send the key in the X-API-Key header to api.samloryx.co.za. Anything outside the key's scopes is refused.
Revoking a key takes effect on the next request. Its usage history stays visible afterwards.
The API cannot do what the product would not let a person do — and in v1 it can do a good deal less: it reads. Approvals, authority levels and restricted actions stay inside the platform.