Autobooks Developer Tools: A Primer for Financial Institutions
Autobooks Developer tools let a small business connect its own software to its Autobooks account without compromising online banking security.
Picture it:
Your small business customer uses a home-grown customer management tool to track customer details such as service dates, a history of services provided, and customer contact information. The business paid a developer consultant to create the system. The only thing missing from this tool? A way to connect to Autobooks to send invoices, check payment status, or update product lists.
Now the business can do just that. Autobooks Developer tools let a small business connect its own software to its Autobooks account to maximize efficiency without compromising online banking security.
Overview
The Developer section in the Autobooks menu gives the business three things: API Keys, Webhooks and Documentation.
Most people who use this section will be developers, or a business owner working with one. FI staff do not need to know how to write code. You need to know what the tools do, who can use them, and where to send questions.
Key terms
|
Term |
What it means |
|---|---|
|
API |
Application Programming Interface. A defined set of rules that lets one piece of software request information or actions from another. |
|
API key |
Credentials that let a business's software call the Autobooks API. The software reaches out to Autobooks to view or create invoices, customers and products, and to email invoices. |
|
Webhook |
An automatic notification. Autobooks sends a message to the business's own web address the moment something happens. Today the only event is Payment incoming, sent when a customer initiates a payment. |
|
Client ID |
Identifies an API key. |
|
OpenAPI spec |
A downloadable file describing the full API. Developers import it into tools such as Postman. |
The API and webhooks work in opposite directions. With the API, the business's software asks Autobooks for something. With a webhook, Autobooks tells the business's software that something happened. A common comparison: checking the mailbox every hour versus getting a text when a package arrives. The webhook is the text.
Benefits for the business
The developer tools are for businesses that use their own software or website and want it to work with Autobooks automatically. Businesses that don't can ignore the feature; everything else in Autobooks works the same.
- Less manual entry. The business's own systems, such as a job management or order system, can create invoices, customers and products in Autobooks directly instead of someone re-keying them.
- Immediate payment notifications. A webhook tells the business's system when a customer initiates a payment, so it can mark an order paid or start fulfillment without someone checking the Payments page.
- Control over security. Each connected system gets its own key. Two keys per API key allow replacement without downtime, and keys can be deleted instantly. Only the primary administrator can access the developer section.
- Self-service for developers. In-app documentation, copyable code samples and a safe test panel let a developer build and test the connection without requiring heavy support.
Benefits for the financial institution
- A stronger offering for tech-savvy business clients. Businesses that run their own software or employ developers have a reason to use your Autobooks offering instead of a standalone tool.
- Deeper engagement. A business whose systems are connected to Autobooks is more likely to retain their banking relationship with you.
- Low support burden. Documentation, testing and troubleshooting guidance live inside the app, so your staff do not need API expertise. Technical questions go to Autobooks.
- A reason to enable Autobooks Pro. The Developer section is available only when your institution has Autobooks Pro turned on.
How it works
Setup follows five steps, usually done by the business owner and their developer together:
- Create an API key. The primary administrator creates one key per connected system, such as job management or ordering software. Every key gets the same seven permissions covering invoices, customers and products.
- Save the client ID and keys. The administrator shares them securely with the developer, never by regular email or text. Keys remain viewable on the key's page later.
- Create a webhook. The administrator enters the HTTPS web address the developer provides. Autobooks will send a Payment incoming notification there when a customer initiates a payment.
- Send a test event. A test confirms the developer's server receives messages. Test messages use sample data, not real payments.
- Go live. The developer's software begins using the connection.
A few details worth knowing:
- Two keys per API key. Both work at once, so the business can replace (rotate) one while software runs on the other. A replaced or deleted key stops working immediately.
- Safe testing. The Try it here panel lets developers test calls. Tests that view data use the real account; tests that create, change or send are checked but not carried out.
- Missed notifications. If the business's software misses a webhook notification, the payment is still recorded in Autobooks on the Payments list.
- Limits. Each API key can make 1 call per second.
Security and online banking
The Developer tools connect a business's software to its Autobooks invoicing data only. They do not open a path to their online banking login, account balances or money movement.
What a connection can and cannot reach
- Limited scope. Every API key has the same seven permissions, and all of them cover invoices, customers, and products and services: viewing, creating, updating, and emailing invoices. None of the permissions involve bank accounts, balances, transfers, or online banking credentials.
- One-way, one event. Webhooks only send notifications out from Autobooks. Today the only notification is Payment incoming. A webhook cannot be used to send instructions into Autobooks.
Who controls access
- One person per business. Only the business's primary administrator can create, view, or remove keys and webhooks. Sub-administrators and other users cannot open the section.
- Instant shut-off. The administrator can rotate or delete a key at any time. The old key stops working immediately, so an exposed key can be shut off right away.
- Separate keys per system. Each connected system gets its own key, so turning one off does not affect the others.
How connections are protected
- Secret keys exchanged for short-lived tokens. Software uses its client ID and secret key to get an access token, which expires after 15 minutes.
- Encrypted delivery only. Webhook addresses must use HTTPS. Unsecured (http) addresses cannot be entered.
- Verifiable messages. Each webhook has a signing public key the business's software can use to confirm a notification really came from Autobooks.
- Rate limits. Each API key is limited to 1 call per second.
- Safe testing. Test calls that would create, change, or send anything are checked but not carried out. Test webhook messages use sample data, not real payments.
Availability and access
|
Item |
Details |
|---|---|
|
Who can use it |
Only the primary administrator of the business's Autobooks account. Sub-administrators and other users cannot see or open the Developer section. |
|
FI requirement |
Your institution must have Autobooks Pro enabled. |
|
Where |
Autobooks web app on desktop and mobile browsers, and inside online banking. Not available in accounting-only mode. |
|
Events available |
Payment incoming (customer has initiated a payment to the business). |
|
Documentation |
Inside the app at Developer > Documentation. |