Flychain Engineering
Overview
Read-only financial reporting for Flychain partners and providers.
Flychain Reporting API 1.0.0
Section titled “Flychain Reporting API 1.0.0”Read-only access to the books Flychain keeps, so figures can be sourced directly from us instead of from an accounting system. There are two kinds of caller: a partner, whose platform reads the providers in its partner relationship, and a provider, reading its own books.
Two levels. A provider is the business as a client of Flychain. A business entity is a legal entity whose books we keep, and reports are produced at that level, because that is the level a set of books exists at. Most providers are a single legal entity; the distinction exists so a figure is never an accidental blend of two. Both identifiers are stable UUIDs for the life of the account.
Scope comes from the key. A partner key is scoped to your partner relationship; a
provider key is scoped to that one provider. Either way the key carries the scope, so
no partner or organization identifier appears in any path. Every endpoint is a GET;
there is nothing in this API that can modify data on our side.
Not every operation is open to both. Each one below opens by naming the kinds of
key it serves: the income statement and the two discovery endpoints take either, while
the balance sheet and cash flow families are provider-key only — eight of the fourteen
operations. guides/authentication carries the full table.
Amounts are integers in cents (USD). We hold monetary values in cents internally to avoid floating-point rounding in financial calculations, and expose them the same way so no precision is lost in transit.
Read the guides alongside this reference. data-semantics in particular carries the
things a schema cannot state: what is_closed means versus is_complete, why
accounting basis is a property of the entity rather than a request parameter, and how
requested ranges are clamped to the date an entity’s books begin.
Authentication
Section titled “Authentication”PartnerApiKey
Section titled “PartnerApiKey”A partner API key, sent as Authorization: Bearer <api_key>.
The key is scoped to your partner relationship: it can read only the providers in that relationship, and a request for anything outside it is rejected. Keys are read-only and there is no OAuth flow, no token refresh and no per-provider consent step.
You issue, rotate and revoke your own keys from your Flychain partner dashboard —
see guides/authentication, which also covers rotating without downtime.
Security scheme type: http
ProviderApiKey
Section titled “ProviderApiKey”A provider API key, sent as Authorization: Bearer <api_key> — the same header a
partner key uses, and a key is only ever one kind or the other.
The key is scoped to a single provider: it reads that provider’s own books and nothing else, and a request naming any other provider or business entity is answered as though that id did not exist. Keys are read-only, and there is no OAuth flow, no token refresh and no per-provider consent step.
A provider’s Flychain account must be active and enrolled in the API programme
before its keys are accepted. Neither is a credential problem, so both are
reported as 403 rather than 401 — rotating the key will not help. See
guides/authentication for issuing and rotating keys.
Security scheme type: http