Sign inBook a demoStart a pilot
DEVELOPER PLATFORM · V1 PREVIEW

Read your company's data from your own systems.

The Samloryx OS API gives a company's own integrations read access to what it has in the platform: the people and companies it deals with, its sites, documents and obligations, its matched tenders, and the catalogue of agents working for it. One key, three scopes, one company's data — never anybody else's.

Read the integration guideAPI reference
Your first call
curl https://api.samloryx.co.za/api/v1/me \
  -H "X-API-Key: $SAMLORYX_API_KEY"
200 OK
{
  "displayName": "Accounting sync",
  "tenant": "Thabeng Civils",
  "roles": ["API"],
  "scopes": ["graph.read", "workspaces.read"]
}
WHERE IT STANDS

What you can build on today, and what you cannot.

v1 is deliberately small. Everything in the left column is running and documented; nothing in the right column exists yet, and we would rather say so than have you plan around it.

Available now
  • Read-only REST API — nine endpoints over the Business Graph, tenders, workspaces and the agent catalogue.
  • Scoped API keys — created and revoked by an owner or admin; shown once; only a digest is stored.
  • Tenant isolation — a key reads the company it was created in and nothing else.
  • One error format — every failure is application/problem+json with a correlation id.
  • Usage you can see — every authorised call is counted per key; refused calls are not.
  • Webhook endpoints — register an HTTPS URL, receive a signed test delivery, verify the signature.
  • An OpenAPI document — import it into Postman or generate a client from it.
Not built yet
  • Writing data — API keys cannot create, change or delete anything.
  • Invoking agents or workflows — the catalogue can be read; nothing can be run.
  • Event webhooks — today the only delivery is the test ping. Nothing is sent when your data changes.
  • File contents — document records are readable; the files are not.
  • Paging and filtering — a list returns its newest 200 rows at most.
  • SDKs, a sandbox, OAuth and MCP — none exist. Use the REST API with a key.
HOW ACCESS WORKS

The company holds the key, in every sense.

1 · An owner creates the key

In the app, under Developers. They choose which of the three scopes it carries. The key is shown once.

2 · You call the API

Send the key in the X-API-Key header to api.samloryx.co.za. Anything outside the key's scopes is refused.

3 · They can end it at any time

Revoking a key takes effect on the next request. Its usage history stays visible afterwards.

The API cannot do what the product would not let a person do — and in v1 it can do a good deal less: it reads. Approvals, authority levels and restricted actions stay inside the platform.

Start with the guideTalk to us about an integration