API reference
Account and API keys
Who you are, your API keys, your connected apps and your language.
8 actions · base URL https://api.bizisy.com/v1 · generated from the same definitions as the API.
Who am I#
POST/v1/platform/whoamiRead
Returns the signed-in user, their organization, roles and the audiences (me/manage) they can use, and whether Bizisy billing exists yet (billing). user.language is the language the person chose (null: they follow the company), org.language the company default (null: each browser's language). Call this first to orient yourself.
- Who can call it
- Manage key any Manage role
Me key anyone - MCP tool
platform_whoamion My Workplace, HR Assistant- Method
POSTwith a JSON body, orGETwith the input as query parameters
Input
No input: send {}.
Returns
8 fields
userobjectrequired4 fields
idstringrequiredemailstringrequireddisplay_namestringrequiredlanguagestring | nullrequired
orgobjectrequired4 fields
idstringrequiredslugstringrequirednamestringrequiredlanguagestring | nullrequired
rolesstring[]requiredaudiences"me" | "manage"[]requiredperson_idstring | nullrequiredbillingbooleanrequiredBilling exists (Settings → Billing,
platform_billing_* tools); false while billing has not started for anyone, with nothing to set up.documentsbooleanrequiredDocuments and file storage exist on this server (documents_* and
platform_storage_* tools).pausedobject | nullrequiredSet while the company is paused for unpaid invoices (or missing billing details): only owners and admins can sign in, in the web app, to pay (Settings → Billing), save a card or export data; every other call is refused until every overdue invoice is paid.
3 fields
reason"unpaid" | "details_missing"requiredsincestringrequireddelete_onstring | nullrequiredSet once Bizisy closed the company for it: the data is deleted on this date unless every overdue invoice is paid (or the details added) before.
Errors
validation_failed unauthenticated forbidden not_found rate_limited internal
curl https://api.bizisy.com/v1/platform/whoami \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-d '{}'const res = await fetch('https://api.bizisy.com/v1/platform/whoami', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os
import requests
res = requests.post(
"https://api.bizisy.com/v1/platform/whoami",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}"},
json={},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": {
"user": {
"id": "usr1",
"email": "ana@acme.test",
"display_name": "Ana Ferreira",
"language": null
},
"org": {
"id": "o1",
"slug": "acme",
"name": "Acme Lda",
"language": "pt-PT"
},
"roles": [
"owner"
],
"audiences": [
"me",
"manage"
],
"person_id": "p1",
"billing": true,
"documents": true,
"paused": null
}
}List my sign-in methods#
POST/v1/platform/sign_in_methods.listRead
Lists the ways you can sign in to this organization: password, Google and Microsoft, each with linked (connected to your login) and available (offered on the sign-in page: Bizisy offers it and the organization has it on), plus whether your email address is confirmed (email_verified, null when unknown). Google or Microsoft is connected by the person from My profile in the web app.
- Who can call it
- Me key anyone
- MCP tool
platform_sign_in_methods_liston My Workplace- Method
POSTwith a JSON body, orGETwith the input as query parameters
Input
No input: send {}.
Returns
methodsobject[]required3 fields
provider"password" | "google" | "microsoft"requiredlinkedbooleanrequiredavailablebooleanrequired
email_verifiedboolean | nullrequired
Errors
validation_failed unauthenticated forbidden not_found rate_limited internal
curl https://api.bizisy.com/v1/platform/sign_in_methods.list \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-d '{}'const res = await fetch('https://api.bizisy.com/v1/platform/sign_in_methods.list', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os
import requests
res = requests.post(
"https://api.bizisy.com/v1/platform/sign_in_methods.list",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}"},
json={},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": {
"methods": [
{
"provider": "password",
"linked": true,
"available": true
},
{
"provider": "google",
"linked": true,
"available": true
},
{
"provider": "microsoft",
"linked": false,
"available": false
}
],
"email_verified": true
}
}List my API keys#
POST/v1/platform/api_keys.listRead
Lists your own API keys (never the secret).
- Who can call it
- Manage key any Manage role
Me key anyone - MCP tool
platform_api_keys_liston My Workplace, HR Assistant- Method
POSTwith a JSON body, orGETwith the input as query parameters
Input
No input: send {}.
Returns
An array of objects with 7 fields
An array of objects:
idstringrequirednamestringrequiredaudience"me" | "manage"requiredlast4stringrequiredcreated_atstringrequiredlast_used_atstring | nullrequiredrevokedbooleanrequired
Errors
validation_failed unauthenticated forbidden not_found rate_limited internal
curl https://api.bizisy.com/v1/platform/api_keys.list \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-d '{}'const res = await fetch('https://api.bizisy.com/v1/platform/api_keys.list', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os
import requests
res = requests.post(
"https://api.bizisy.com/v1/platform/api_keys.list",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}"},
json={},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": [
{
"id": "k1",
"name": "Claude Code",
"audience": "manage",
"last4": "cdef",
"created_at": "2026-10-04T10:00:00.000Z",
"last_used_at": null,
"revoked": false
}
]
}Revoke an API key#
POST/v1/platform/api_keys.revokeDestructive
Revokes one of your API keys immediately. Clients using it lose access.
- Who can call it
- Manage key any Manage role
Me key anyone - MCP tool
platform_api_keys_revokeon My Workplace, HR Assistant- Preview
?dry_run=trueruns every check and saves nothing- Retries
- An Idempotency-Key replays the first result
Input
idstringrequired
Returns
idstringrequiredrevokedtruerequired
Errors
validation_failed unauthenticated forbidden not_found conflict rate_limited internal
curl https://api.bizisy.com/v1/platform/api_keys.revoke \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{"id":"k1"}'const res = await fetch('https://api.bizisy.com/v1/platform/api_keys.revoke', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
'Idempotency-Key': crypto.randomUUID(),
},
body: JSON.stringify({
"id": "k1"
}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os, uuid
import requests
res = requests.post(
"https://api.bizisy.com/v1/platform/api_keys.revoke",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}", "Idempotency-Key": str(uuid.uuid4())},
json={
"id": "k1",
},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": {
"id": "k1",
"revoked": true
}
}List connected apps#
POST/v1/platform/connections.listRead
Lists the AI apps (MCP clients) connected to Bizisy by signing in: their name, where they come from, Me or Manage, when connected and last used. Your own by default; in Manage, owners and admins may pass everyone=true for the whole company (with who connected each). Tokens are never shown. A connection disconnects on its own after 30 days without use.
- Who can call it
- Manage key any Manage role
Me key anyone - MCP tool
platform_connections_liston My Workplace, HR Assistant- Method
POSTwith a JSON body, orGETwith the input as query parameters
Input
everyonebooleanOwners and admins in Manage: the whole company.
Returns
An array of objects with 12 fields
An array of objects:
idstringrequiredclient_namestringrequiredclient_kind"cimd" | "dcr"requiredclient_hoststring | nullrequiredFor apps that publish their identity (e.g. claude.ai): the host it is published on.
redirect_hoststringrequiredredirect_kind"web" | "local" | "app"requiredaudience"me" | "manage"requiredcreated_atstringrequiredlast_used_atstring | nullrequiredexpires_atstring | nullrequiredDisconnects on its own if unused until then (renewed on every use).
minebooleanrequireduserobject | nullrequiredWho connected it (only in the everyone view).
3 fields
idstringrequirednamestringrequiredemailstringrequired
Errors
validation_failed unauthenticated forbidden not_found rate_limited internal
curl https://api.bizisy.com/v1/platform/connections.list \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-d '{"everyone":true}'const res = await fetch('https://api.bizisy.com/v1/platform/connections.list', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"everyone": true
}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os
import requests
res = requests.post(
"https://api.bizisy.com/v1/platform/connections.list",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}"},
json={
"everyone": True,
},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": [
{
"id": "g1",
"client_name": "Claude",
"client_kind": "cimd",
"client_host": "claude.ai",
"redirect_host": "claude.ai",
"redirect_kind": "web",
"audience": "manage",
"created_at": "2026-10-05T10:00:00.000Z",
"last_used_at": "2026-10-05T11:00:00.000Z",
"expires_at": "2026-11-04T11:00:00.000Z",
"mine": true,
"user": {
"id": "usr1",
"name": "Ana Ferreira",
"email": "ana@acme.test"
}
}
]
}Disconnect an app#
POST/v1/platform/connections.revokeDestructive
Disconnects a connected AI app at once: its tokens stop working and it must ask again to reconnect. Your own connections; owners and admins may disconnect anyone's, but only in the web app (over MCP or an API key, your own only). Take id from platform_connections_list.
- Who can call it
- Manage key any Manage role
Me key anyone - Keys and apps
- Only your own connections (owners and admins disconnect others in the app).
- MCP tool
platform_connections_revokeon My Workplace, HR Assistant- Preview
?dry_run=trueruns every check and saves nothing- Retries
- An Idempotency-Key replays the first result
Input
idstringrequired1–64 characters.
Returns
idstringrequiredrevokedtruerequired
Errors
validation_failed unauthenticated forbidden not_found conflict rate_limited internal
curl https://api.bizisy.com/v1/platform/connections.revoke \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{"id":"g1"}'const res = await fetch('https://api.bizisy.com/v1/platform/connections.revoke', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
'Idempotency-Key': crypto.randomUUID(),
},
body: JSON.stringify({
"id": "g1"
}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os, uuid
import requests
res = requests.post(
"https://api.bizisy.com/v1/platform/connections.revoke",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}", "Idempotency-Key": str(uuid.uuid4())},
json={
"id": "g1",
},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": {
"id": "g1",
"revoked": true
}
}AI setup status#
POST/v1/platform/ai.onboarding.statusRead
For the caller only, in this audience: whether the "Connect your AI" journey applies to them (eligible: owners and admins in Manage, everyone in Me) and should show first (show), their own connected apps here with when each first called Bizisy, first made a change and the last tool it used, and the latest change or preview one of their apps made (Activity summary and links). The Bizisy app polls it while someone connects an assistant. Never shows other people's apps or activity.
- Who can call it
- Manage key any Manage role
Me key anyone - MCP tool
platform_ai_onboarding_statuson My Workplace, HR Assistant- Method
POSTwith a JSON body, orGETwith the input as query parameters
Input
No input: send {}.
Returns
8 fields
eligiblebooleanrequiredManage: owners and admins. Me: everyone.
showbooleanrequiredThe journey is still open for you: eligible, no connected app of your own here yet, not put off.
redirectbooleanrequiredManage Home opens the journey first: only for a company created since the journey shipped, once per person (until they have seen it), with no connected app and no API key in use.
stateobjectrequired3 fields
viewed_atstring | nullrequiredassistant"claude" | "chatgpt" | "cursor" | "vscode" | "gemini" | "other"requiredskipped_atstring | nullrequired
appsobject[]required9 fields
idstringrequiredclient_namestringrequiredassistant"claude" | "chatgpt" | "cursor" | "vscode" | "gemini" | "other"requiredconnected_atstringrequiredlast_used_atstring | nullrequiredfirst_call_atstring | nullrequiredIts first tool call.
first_write_atstring | nullrequiredIts first applied change.
last_toolobject | nullrequired2 fields
idstringrequiredtitlestringrequired
last_tool_atstring | nullrequired
first_call_atstring | nullrequiredfirst_write_atstring | nullrequiredlatestobject | nullrequired6 fields
activity_idstringrequiredsummarystringrequiredpreviewbooleanrequiredA preview (dry run): nothing was saved.
appstring | nullrequiredatstringrequiredlinksobject[]required2 fields
labelstringrequiredpathstringrequired
Errors
validation_failed unauthenticated forbidden not_found rate_limited internal
curl https://api.bizisy.com/v1/platform/ai.onboarding.status \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-d '{}'const res = await fetch('https://api.bizisy.com/v1/platform/ai.onboarding.status', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os
import requests
res = requests.post(
"https://api.bizisy.com/v1/platform/ai.onboarding.status",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}"},
json={},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": {
"eligible": true,
"show": false,
"redirect": false,
"state": {
"viewed_at": "2026-10-05T10:00:00.000Z",
"assistant": "claude",
"skipped_at": null
},
"apps": [
{
"id": "g1",
"client_name": "Claude",
"assistant": "claude",
"connected_at": "2026-10-05T10:02:00.000Z",
"last_used_at": "2026-10-05T10:03:00.000Z",
"first_call_at": "2026-10-05T10:02:30.000Z",
"first_write_at": "2026-10-05T10:05:00.000Z",
"last_tool": {
"id": "org.setup.apply",
"title": "Apply a company setup"
},
"last_tool_at": "2026-10-05T10:05:00.000Z"
}
],
"first_call_at": "2026-10-05T10:02:30.000Z",
"first_write_at": "2026-10-05T10:05:00.000Z",
"latest": {
"activity_id": "01k0000000000000000000000a",
"summary": "Applied company setup: 3 people created",
"preview": false,
"app": "Claude",
"at": "2026-10-05T10:05:00.000Z",
"links": [
{
"label": "People",
"path": "/manage/people"
}
]
}
}
}Change my language#
POST/v1/platform/language.set_mineWrite
Sets the language Bizisy uses for you: the web app (Me and Manage, on every device and in every company you belong to) and the emails you receive. Languages: en (English), pt-PT (Português), es-ES (Español), de-DE (Deutsch), fr-FR (Français), it-IT (Italiano). null = follow the company default (or, without one, the browser's language). Any signed-in person, for themselves only. platform_whoami returns the current choice (user.language) and the company default (org.language).
- Who can call it
- Manage key any Manage role
Me key anyone - MCP tool
platform_language_set_mineon My Workplace, HR Assistant- Preview
?dry_run=trueruns every check and saves nothing- Retries
- An Idempotency-Key replays the first result
Input
language"en" | "pt-PT" | "es-ES" | "de-DE" | "fr-FR" | "it-IT"requiredOne of en, pt-PT, es-ES, de-DE, fr-FR, it-IT, or null to follow the company default.
Returns
language"en" | "pt-PT" | "es-ES" | "de-DE" | "fr-FR" | "it-IT"required
Errors
validation_failed unauthenticated forbidden not_found conflict rate_limited internal
curl https://api.bizisy.com/v1/platform/language.set_mine \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{"language":"de-DE"}'const res = await fetch('https://api.bizisy.com/v1/platform/language.set_mine', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
'Idempotency-Key': crypto.randomUUID(),
},
body: JSON.stringify({
"language": "de-DE"
}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os, uuid
import requests
res = requests.post(
"https://api.bizisy.com/v1/platform/language.set_mine",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}", "Idempotency-Key": str(uuid.uuid4())},
json={
"language": "de-DE",
},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": {
"language": "de-DE"
}
}Something missing or wrong on this page? Write to hello@bizisy.com.