marketplace-doc
    • Data Ingestion
    • Errors
    • Introduction
    • Loan API & Deduction Lifecycle
    • Getting Started
    • OAuth
    • Webhooks
    • Embedded Journey
    • OpenSylo Marketplace Integration API
      • OAuth 2.0
        • Start OAuth authorization
        • Exchange authorization code or refresh token
        • Revoke a token
        • Discover OAuth capabilities
      • Data Ingestion
        • Submit single merchant data
        • Submit bulk merchant data
        • Poll batch processing status
        • Get merchant credit score
        • Data ingestion health check
      • Sales & Events
        • Submit a sales event
        • Submit a repayment event
        • Submit an account flag
      • Loan API
        • Get active loans for a merchant
        • Get loan status
        • Validate deduction amounts
        • Bulk loan status
      • Inbound Webhooks
        • Repayment events
        • Settlement events
      • Outbound Webhooks
        • loan.approved
        • loan.disbursed
        • loan.repayment_updated
        • loan.nearly_complete
        • loan.completed
        • loan.defaulted
        • merchant.created
        • kyc.submitted
        • kyc.approved
        • kyc.rejected
        • funding_request.created
        • funding_request.fulfilled
        • funding_request.rejected
      • Embedded Journey (Marketplace API)
        • Create (or fetch) a merchant
        • Get merchant status (KYC, credit score, funding requests)
        • Update business KYC information
        • Add directors (bulk)
        • Attach a KYC document
        • Submit KYC for review
        • Submit sales data for credit scoring
        • Create a funding request
        • Mint an embed token for the hosted journey
      • Schemas
        • TokenRequest
        • TokenResponse
        • OAuthError
        • ClientMetadataResponse
        • MerchantIdentity
        • SalesPerformance
        • RevenueConsistency
        • FulfillmentMetrics
        • PayoutCashFlow
        • PlatformDependency
        • HistoricalCredit
        • BehavioralRisk
        • MonthlyHistoryEntry
        • MerchantDataRequest
        • CreditScore
        • LoanEligibilityResult
        • MerchantDataResponse
        • BulkMerchantDataRequest
        • AsyncBulkProcessingResponse
        • BatchStatusResponse
        • SalesEventRequest
        • RepaymentEventRequest
        • AccountFlagRequest
        • MerchantInfo
        • LenderInfo
        • RepaymentInfo
        • LoanTermsInfo
        • ActiveLoan
        • ActiveLoansSummary
        • ActiveLoansResponse
        • LoanStatusRepayment
        • LoanStatusResponse
        • ValidateDeductionsRequest
        • DeductionItem
        • DeductionSummary
        • ValidateDeductionsResponse
        • BulkLoanStatusRequest
        • BulkLoanStatusItem
        • BulkStatusSummary
        • BulkLoanStatusResponse
        • WebhookMarketplace
        • WebhookMerchant
        • WebhookLoan
        • DeductionDetails
        • SourceTransaction
        • LoanBalance
        • RepaymentDeductedWebhook
        • FailureDetails
        • RepaymentFailedWebhook
        • ReversalDetails
        • RepaymentReversedWebhook
        • SettlementDetails
        • SettlementSummaryByStatus
        • SettlementSummary
        • SettlementLoanIncluded
        • BankTransferDetails
        • SettlementCreatedWebhook
        • SettlementTransferredWebhook
        • TransferDetails
        • WebhookAckResponse
        • OutboundLoan
        • OutboundMerchant
        • OutboundLender
        • LoanTerms
        • RepaymentTerms
        • ScheduleInstallment
        • LoanApprovedPayload
        • DisbursementDetails
        • DisbursedRepayment
        • LoanDisbursedPayload
        • ChangeDetail
        • LoanRepaymentUpdatedPayload
        • RepaymentStatus
        • NearlyCompleteRecommendation
        • LoanNearlyCompletePayload
        • CompletionSummary
        • LoanCompletedPayload
        • DefaultDetails
        • CollectionInstructions
        • LoanDefaultedPayload
        • ApiError
        • RateLimitError
        • EmbedCreateMerchantRequest
        • EmbedCreateMerchantResponse
        • EmbedBusinessKyc
        • EmbedDirectorInfo
        • EmbedBulkDirectors
        • EmbedDirectorListItem
        • EmbedDocumentUpload
        • EmbedSalesDataAccepted
        • EmbedCreateFundingRequest
        • EmbedFundingRequestIntent
        • EmbedMerchantStatusResponse
        • EmbedTokenResponse
        • MarketplaceMerchantRef
        • MerchantCreatedPayload
        • KycStatusPayload
        • FundingRequestEventPayload
    • OpenSylo Marketplace API
      • OAuth 2.0
        • Start OAuth authorization
        • Exchange code or refresh token
        • Revoke a token
        • OAuth discovery / client metadata
      • Data Ingestion
        • Submit single merchant data
        • Submit bulk merchant data
        • Get merchant credit score
        • Integration health check
      • Loan API
        • Get active loans for a merchant
        • Get loan status
        • Validate deduction amounts
        • Bulk loan status check
      • Inbound Webhooks
        • Send repayment webhook
        • Send settlement webhook
      • Schemas
        • TokenRequest
        • TokenResponse
        • RevokeRequest
        • ClientMetadataResponse
        • MerchantIdentity
        • SalesPerformance
        • RevenueConsistency
        • FulfillmentMetrics
        • PayoutCashFlow
        • PlatformDependency
        • HistoricalCredit
        • BehavioralRisk
        • MerchantDataRequest
        • ScoreBreakdown
        • CreditScore
        • MerchantDataResponse
        • BulkMerchantDataRequest
        • BulkMerchantDataResponse
        • CreditScoreResponse
        • HealthResponse
        • ActiveLoansResponse
        • LoanStatusResponse
        • ValidateDeductionsRequest
        • ValidateDeductionsResponse
        • BulkLoanStatusRequest
        • BulkLoanStatusResponse
        • RepaymentWebhookRequest
        • SettlementWebhookRequest
        • WebhookAckResponse
        • OAuthError
        • ApiError

    Getting Started

    Prerequisites#

    Before you begin integration, ensure you have the following:
    RequirementDescription
    Admin invitationAn OpenSylo admin must invite your marketplace. You'll receive an email with a registration link.
    Registration completeComplete the multi-step onboarding (business info, phone verification, signatory details, documents).
    OAuth credentialsAfter registration, your client_id and client_secret are available in the dashboard. The secret is shown only once at creation — store it securely.
    Redirect URI(s)One or more callback URLs registered with OpenSylo where authorization codes will be sent.
    Webhook endpoint (optional)An HTTPS endpoint on your server to receive loan lifecycle events from OpenSylo.
    Webhook secret (optional)An API secret configured on your marketplace for signing inbound webhooks you send to OpenSylo.

    Step 1 — Accept the Invitation#

    You will receive an email from OpenSylo with a registration link:
    https://opensylo.com/marketplace/register?token=inv_<token>
    The invitation token is valid for 7 days and can only be used once. Complete the registration form to create your marketplace account and activate your credentials.

    Step 2 — Retrieve Your Credentials#

    After registration, log in to the OpenSylo Dashboard to view and manage your OAuth credentials (client_id, client_secret), redirect URIs, and webhook settings. Credential generation and regeneration are handled entirely through the dashboard.
    Important: The client secret is shown only once at creation. Store it securely. If lost, regenerate it via the dashboard.

    Authentication Summary#

    MethodUsed ForHow to ObtainLifetime
    OAuth Access TokenData and Loan API endpointsOAuth Authorization Code + PKCE flow1 hour
    OAuth Refresh TokenRefreshing expired access tokensReturned with initial token exchange30 days
    Webhook SignatureInbound webhooks (/api/v1/webhooks/marketplace/*)HMAC-SHA256 using your API secretPer-request

    Available Scopes#

    When requesting OAuth authorization, include the scopes your integration needs:
    ScopeDescription
    data.share.salesShare sales and GMV data with OpenSylo
    data.share.fulfillmentShare order fulfillment and delivery metrics
    data.share.payoutsShare payout and cash flow information
    data.share.riskShare account status and risk information
    data.share.profileShare merchant business profile information
    credit.score.readAccess credit scores calculated by OpenSylo
    repayment.reportReport loan repayments collected from merchant sales

    Next Steps#

    1.
    Implement the OAuth 2.0 flow to obtain merchant consent and tokens
    2.
    Submit merchant data via the Data Ingestion API
    3.
    Set up webhook handlers for loan lifecycle events
    4.
    Use the Loan API to query active loans and validate deductions
    5.
    Test everything in the sandbox environment before going live
    Modified at 2026-04-08 18:18:53
    Previous
    Loan API & Deduction Lifecycle
    Next
    OAuth
    Built with