1. Endpoint reference
1.1 Canonical endpoint index for the Portal team
User = active Merchant Administrator or Developer using a user PAT. Admin = Merchant Administrator using that PAT. App = DLT Merchant Portal ecosystem application using Basic credentials and X-DLT-Application. Paths below are origin-relative; detailed sections define validation and responses.
| Method | Full path | Access | Input summary | Success | Details | Validation |
|---|---|---|---|---|---|---|
| POST | /api/v1/auth/login |
App + user password | username, password |
200, PAT/expiry/login user | 3.2 | Rules |
| POST | /api/v1/auth/logout |
User | No body | 200, message; current PAT revoked | 3.2 | Rules |
| POST | /api/v1/auth/reset-password/reset-link |
Public | email, reset_url |
200, account-independent message | 3.4, 13.1 | Rules |
| POST | /api/v1/auth/reset-password/new-password |
Public + reset proof | email, token, password, password_confirmation |
200, message; log in afterward | 3.4, 13.1 | Rules |
| GET | /api/v1/portal/me |
User | None | 200, profile | 5 | Rules |
| PATCH | /api/v1/portal/me |
User | At least one of first/last name/email | 200, profile, possibly pending email | 5 | Rules |
| POST | /api/v1/portal/me/email/verify |
User | Six-digit string otp |
200, verified profile | 5.2 | Rules |
| POST | /api/v1/portal/me/email/resend |
User | No body | 200, data:null |
5.2 | Rules |
| PUT | /api/v1/portal/me/password |
User | Current/new/confirmation passwords | 200, reauthentication required | 5.1 | Rules |
| GET | /api/v1/portal/merchant |
User | None | 200, merchant profile | 6.1 | Rules |
| PATCH | /api/v1/portal/merchant |
Admin | At least one editable business field | 200, merchant profile | 6.1 | Rules |
| GET | /api/v1/portal/merchant/logo |
User | None | 200, data.url nullable |
6.1 | Rules |
| POST | /api/v1/portal/merchant/logo |
Admin | Multipart file |
200, data.url |
6.1 | Rules |
| DELETE | /api/v1/portal/merchant/logo |
Admin | No body | 204, empty body | 6.1 | Rules |
| GET | /api/v1/portal/merchant/machine-clients |
User | page, per_page |
200, paginated metadata | 6.2 | Rules |
| POST | /api/v1/portal/merchant/machine-clients |
Admin | label, reason, current_password |
201, client and delivery metadata | 6.2 | Rules |
| POST | /api/v1/portal/merchant/machine-clients/{client}/rotate |
Admin | Issue fields + overlap_minutes |
201, replacement and delivery metadata | 6.2 | Rules |
| POST | /api/v1/portal/merchant/machine-clients/{client}/revoke |
Admin | reason, current_password |
200, revoked metadata | 6.2 | Rules |
| POST | /api/v1/portal/merchant/credential-deliveries/{delivery}/consume |
Issuing Admin | current_password |
200, one-use credential document | 6.2 | Rules |
| GET | /api/v1/portal/merchant/integration-keys |
User | None | 200, presence metadata | 6.3 | Rules |
| PUT | /api/v1/portal/merchant/integration-keys/{keyType} |
Admin | value, reason, current_password |
200, presence metadata | 6.3 | Rules |
| DELETE | /api/v1/portal/merchant/integration-keys/{keyType} |
Admin | JSON reason, current_password |
204, empty body | 6.3 | Rules |
| GET | /api/v1/portal/team/members |
User | page, per_page |
200, paginated members | 7.3 | Rules |
| PATCH | /api/v1/portal/team/members/{member}/role |
Admin | role |
200, updated member | 7.3 | Rules |
| DELETE | /api/v1/portal/team/members/{member} |
Admin | No body | 204, membership removed | 7.3 | Rules |
| GET | /api/v1/portal/team/invitations |
Admin | page, per_page, optional status |
200, paginated invitations | 7.2 | Rules |
| POST | /api/v1/portal/team/invitations |
Admin | email, role |
201, invitation + sent |
7.2 | Rules |
| POST | /api/v1/portal/team/invitations/{invitation}/resend |
Admin | No body | 200, invitation + sent |
7.2 | Rules |
| DELETE | /api/v1/portal/team/invitations/{invitation} |
Admin | No body | 204, invitation revoked | 7.2 | Rules |
| POST | /api/v1/portal/team/invitations/accept |
App + emailed proof | New/existing account acceptance body | 200, member; no PAT | 7.2, 13.1 | Rules |
| GET | /api/v1/portal/collections/transactions |
User | Required environment + optional list filters/pagination | 200, paginated transactions | 8.1 | Rules |
| GET | /api/v1/portal/collections/transactions/{transaction} |
User | Required environment |
200, transaction | 8.1 | Rules |
| GET | /api/v1/portal/collections/transactions/{transaction}/history |
User | Required environment + pagination | 200, paginated history + coverage | 9.1 | Rules |
| GET | /api/v1/portal/collections/transactions/{transaction}/history/{history} |
User | Required environment |
200, history item | 9.1 | Rules |
| GET | /api/v1/portal/collections/metrics |
User | Environment/currency/from/to; optional timezone/brand | 200, summary | 10.1–10.2 | Rules |
| GET | /api/v1/portal/collections/charts |
User | Summary filters + required interval |
200, buckets and overall totals | 10.3 | Rules |
Use {client} from a machine-client metadata item's ownership id, not oauth_client_id; {delivery} and {invitation} are UUIDs. {member} is the user ID from the member list. {transaction} is the internal numeric transaction id, not the merchant reference. {history} is the evidence ULID from the history list. {keyType} is exactly authentication_token or secret_key. Do not send these route IDs again in JSON/query overrides.
The signed email-verification URL in section 5.2 is a DLT web capability outside /api/v1, supplied by email rather than constructed by the Portal. This index covers the DLT APIs consumed by Merchant Portal. Merchant-owned application authentication is documented separately in the Merchant integrations guide.