Docs

General · Tools

API collections

Postman collections for every Monato API, generated from the same OpenAPI specs as the API reference.

These Postman collections cover every Monato API. They are generated from the same OpenAPI specs as the API reference, so each request, parameter and example matches the reference.

Download

Each API reference page also links to its OpenAPI spec as JSON, for example the Fincore API reference.

Import in Postman

  1. Download the collection you need and the Monato Sandbox environment.
  2. In Postman, select Import and drop both files.
  3. Select the Monato Sandbox environment in the top-right corner.
  4. Fill in the credentials you received during onboarding. Leave the base URLs as they are unless Monato gives you different ones.
  5. Open a request and select Send.
Note:

The collections contain no credentials. Every secret in the environment starts empty and is marked as secret, so Postman masks it.

Environment variables

Variable Default Used by
fincoreBaseUrl https://apicore.stg.finch.lat Fincore
fincoreApiKey Set by you (secret) Fincore, sent as x-api-key
clientId Set by you Fincore path parameter clientId and token request
clientSecret Set by you (secret) Fincore token request
directDebitBaseUrl https://stg.directdebit.monato.com Direct Debit
directDebitApiKey Set by you (secret) Direct Debit, sent as X-API-Key
finBaseUrl https://dev-api.finco.lat Billpay, Gift Cards, Cash, Lottery
finAccessToken Set by you (secret) Billpay, Gift Cards, Lottery, sent as Authorization: Bearer
cashClientId Set by you Cash, sent as X-Client-Id
cashApiSecret Set by you (secret) Cash request signing
remittancesBaseUrl Empty Remittances

The Fincore, Cash, Gift Cards and Lottery defaults come from the servers in each spec. The Direct Debit default is the sandbox URL from the Direct Debit environments guide. The Billpay default is the sandbox URL from the Billpay quickstart.

What the collections do for you

Fincore: bearer token on demand

Most Fincore endpoints need a bearer token. Retrieve client credentials and Create authentication token use only your x-api-key.

Before every other request, the collection’s pre-request script calls Create authentication token with clientId and clientSecret, then stores the token in the collection variable fincoreToken. It reuses the token until one minute before expires_at. expires_at has no UTC offset and is in Mexico City time (UTC-6), so the script parses it as UTC-6.

Cash: request signing

Every Cash request needs three headers. The collection’s pre-request script adds them:

Header Value
X-Client-Id cashClientId
X-Timestamp Current Unix timestamp in seconds
X-Signature Hex-encoded HMAC-SHA256 of timestamp + "." + requestBody, signed with cashApiSecret

Several request examples

When a spec gives more than one request body example for an endpoint, the collection has one request per example, named after it. For example, Fincore Register an instrument for a client · Add debit card and · Add CLABE.

Idempotency keys

When a spec defines an optional header, such as Idempotency-Key on Fincore money out, the request includes it with the spec’s example value but turns it off. Turn it on and set your own key when you need it. See Idempotency.

Keep the collections up to date

The collections are generated from openapi/. After a spec changes, run this from the repository root and commit the result:

Regenerate the collections
node src/lib/openapi-postman.ts