Skip to main content

What it is

These examples call the production host. While you build, replace https://api-harmony.compago.com with https://demo-api-harmony.compago.com and use a key from the Demo dashboard. See Environments.
The Developer API is Compago’s read-only API for merchants. It exposes what your organization has sold and what it has configured, so you can reconcile against your accounting system, feed a data warehouse, or build an internal dashboard on your own data. Everything lives under /api/developer/v1 and authenticates with the API key you already use.
This version reads. It does not write. Every endpoint is a GET. There is nothing here that creates, updates, archives or deletes, and the API returns 404 for any other method. Creating payments stays on the payment-acceptance endpoints; managing your catalogue, links and subscriptions stays in the dashboard.

Payments

Every payment you have taken, with its card, customer and hold state.

Subscriptions

Recurring agreements, their dunning state and billing history.

Catalogue

Payment links and the products behind them.

Organization

Your profile, team, salespeople and promotions.

Core concepts

Pagination, rate limits and error handling.

Authentication

Creating and using an API key.

Two API surfaces

Both use the same x-api-key header and the same host. They are separate contracts and evolve independently. The payment-acceptance endpoints are unchanged and are not deprecated. If your integration only creates checkouts, you do not need to move.
The v1 in the path is a promise: when a breaking change is needed, it ships as v2 alongside this one rather than changing what your integration already reads.

Getting started

1

Create an API key

In the dashboard, go to Configuraciones, then Desarrollador. Copy the key immediately: it is shown once. See Authentication.
2

Confirm it works

A 200 with your organization’s name means you are connected. A 403 with MERCHANT_ONLY means the key belongs to a manufacturer organization, which this API does not serve. A 403 with KEY_NOT_SCOPED means the key predates organization binding: create a new one.
3

Read something real

4

Handle pagination and rate limits before you go live

Read Pagination and Rate limits. Both have copy-paste helpers.

What you can see

An API key is bound to exactly one organization: the one it was created in. Every list is filtered to that organization in the database query itself, and an id belonging to anyone else returns 404, not 403, so this API cannot be used to discover whether an id exists. Three things are deliberately absent:
  • Card numbers and stored tokens. A saved card is referenced only by its id. You get the last four digits, the network, the funding source and the issuing bank, and nothing that could be used to charge the card elsewhere.
  • Salesperson credentials. Password hashes and device tokens are never read from the database by this API, let alone returned.
  • The other side of a promotion. When a promotion funds one of your payments you see your own fee, not the funding organization’s take.
Available to merchant organizations. Manufacturer organizations receive 403 MERCHANT_ONLY: a manufacturer’s view of a payment is subject to a customer-data gate that this API does not implement.

Environments

Keys are per environment. A demo key will not authenticate against production.