
Your website shows the wrong quantities, your accountant retypes invoices into another tool, your in-house application knows nothing about your customers: your software does not talk, and your staff bridge the gap by hand. The API & webhooks module of Almawarid opens your data to your developers with clear rules: what a key can read, what it can write, and how often.
Systems that do not talk, and people who retype
A growing company often ends up with three or four tools: a website or online shop, a custom-built business application, a tracking spreadsheet, and the management software. Between them there is only one bridge: someone retyping. Entry errors pile up, figures drift apart from one tool to the next, and nobody knows which one to trust.
Connecting two systems is also frightening, and rightly so: an access key handed to a contractor, or forgotten in a website's code, can become an open door to your stock and invoices. You need to connect without exposing everything.
An API that follows the same rules as your screens
The Almawarid API is a REST API over HTTPS using JSON. It covers invoicing (invoices, quotes, pro formas, sales orders, delivery notes, credit notes, payments and customers), stock and purchasing (products with real-time quantities, movements, warehouses, stock counts, suppliers, purchases) and HR (employees, read-only payslips, contracts, attendance, salary advances). Every call goes through the same checks as the screen: a numbered invoice never returns to draft, an exit that would make stock negative is refused, and each write either completes in full or does not happen.
Security is set by default. A newly opened key can only read; read and write mode is switched on at your request. An employee's token can only do what their screen allows. Calls are capped at 20 per minute and 500 per day per token. And instead of polling the API in a loop, your system can receive webhooks: an HMAC-SHA256 signed call to an HTTPS address when an invoice is paid, when its status changes or when a customer is created.
How it works, in five screens
- Get started in 3 steps: the module is switched on at your request, then the documentation page shows your token and copy-ready examples in cURL, Python and PHP.
- Get your token: a single header is enough, Authorization: Token followed by the token, to be kept secret like a password.
- Endpoints: the list of routes by area, each with the access level required, its parameters, and a sample request and response.
- Webhooks: the section showing how to declare, through an API call, an HTTPS address and the events you want; the signing secret is shown only once, and the webhook list gives each one's last status and failures.
- API responses: the table of response codes, from 200 to 429, with what to do for each one.
What you gain
- A website that tells the truth. Quantities and prices are read in real time, not from yesterday's export.
- Less retyping. A customer or document created elsewhere goes straight into Almawarid, with the same checks as on screen.
- Keys that stay in their lane. Read-only by default, employee rights respected, a call cap per token.
- Integrations that react. Webhooks tell your system when an invoice is paid, without constant polling.
- Readable documentation. Examples in cURL, Python and PHP, and an error table that says what to do.
Who is it for?
The module is for companies with a developer, an IT contractor or a business application to connect. Everyday use of Almawarid, mobile app, desktop station or biometric time clocks, does not need it. For a WooCommerce shop, the E-commerce module handles synchronisation with no development at all.
- Companies with a custom website or application
- Business software publishers and integrators
- Distributors connected to their resellers
- Groups consolidating several tools
- IT departments feeding a dashboard
Frequently asked questions
Do I need this module for the mobile app or the desktop station?
No. The app, the Desktop station and biometric time clocks work without it. The module is only for connecting your own tools.
Can a stolen key change my data?
A new key is read-only: it can neither create nor modify. Write mode is only switched on at your request, and each token stays limited to the rights of the user who created it. Never publish a token in the visible code of a web page.
Which events trigger a webhook?
Three today: invoice paid, invoice status changed, customer created. Delivery is a single attempt with a short timeout; a webhook that fails 20 times in a row disables itself, and the API lets you catch up on a missed event.
What are the call limits?
20 calls per minute and 500 per day per token, reads and writes combined. Beyond that the API answers 429 and you need to space out your calls. Lists are paged by 100, up to 200 per page.
Can a payslip be created through the API?
No, by design: payslips can be read through the API but are produced on screen, where pay scales, absences and advances are checked.
See the API & webhooks module on your own business
Come to the demo with your developer and the list of data your website or software needs to read or write: together we check, route by route, what the API already covers.
- The demo. An advisor shows you the API & webhooks module on your own business, online and on your screen, and answers your questions. Request a demo.
- The trial version. It is switched on with an advisor during the demo, on your own account: your real products, your real customers, and 14 days to work in it. Create your account to request it.
- The customisation workshops. During the trial, we adapt the screens, documents and settings with you to the way you work. These workshops are free.
The API & webhooks module is switched on on request: ask for it during the demo, the advisor gives you its price, and you only pay if you decide to continue. The base plans are on the pricing page (in French).
Ask for the demo on WhatsAppRequest a demo