| Requirement | Description |
|---|---|
| Admin invitation | An OpenSylo admin must invite your marketplace. You'll receive an email with a registration link. |
| Registration complete | Complete the multi-step onboarding (business info, phone verification, signatory details, documents). |
| OAuth credentials | After registration, your client_id and client_secret are available in the dashboard. The secret is shown only once at creation — store it securely. |
| Redirect URI(s) | One or more callback URLs registered with OpenSylo where authorization codes will be sent. |
| Webhook endpoint (optional) | An HTTPS endpoint on your server to receive loan lifecycle events from OpenSylo. |
| Webhook secret (optional) | An API secret configured on your marketplace for signing inbound webhooks you send to OpenSylo. |
https://opensylo.com/marketplace/register?token=inv_<token>client_id, client_secret), redirect URIs, and webhook settings. Credential generation and regeneration are handled entirely through the dashboard.Important: The client secret is shown only once at creation. Store it securely. If lost, regenerate it via the dashboard.
| Method | Used For | How to Obtain | Lifetime |
|---|---|---|---|
| OAuth Access Token | Data and Loan API endpoints | OAuth Authorization Code + PKCE flow | 1 hour |
| OAuth Refresh Token | Refreshing expired access tokens | Returned with initial token exchange | 30 days |
| Webhook Signature | Inbound webhooks (/api/v1/webhooks/marketplace/*) | HMAC-SHA256 using your API secret | Per-request |
| Scope | Description |
|---|---|
data.share.sales | Share sales and GMV data with OpenSylo |
data.share.fulfillment | Share order fulfillment and delivery metrics |
data.share.payouts | Share payout and cash flow information |
data.share.risk | Share account status and risk information |
data.share.profile | Share merchant business profile information |
credit.score.read | Access credit scores calculated by OpenSylo |
repayment.report | Report loan repayments collected from merchant sales |