Proteside Docs

API overview

Automate Proteside stores, scripts, alerts and PCI DSS reports with the v1 REST API, and receive events via webhook.

The public v1 API gives you programmatic access to almost everything you do in the dashboard. Use it to integrate Proteside with your CI/CD, SIEM, ticketing tool or partner dashboard, and use webhooks to react to events without polling the API.

What you can automate

  • Stores: create a store, get the SDK key and installation snippet, adjust the SDK configuration, rotate the key and check whether the SDK is installed.
  • Payment pages: register the checkout URLs the SDK should protect.
  • Scripts: list the inventory and authorize or block scripts with a justification (PCI DSS 4.0, requirement 6.4.3).
  • Rules: create, enable, disable and delete block or allow rules by domain, URL or hash.
  • Approval policies: create, simulate and apply policies that decide on scripts automatically.
  • Alerts: list, view, resolve and reopen alerts.
  • PCI DSS reports: generate and download reports in JSON, PDF or CSV, and schedule weekly or monthly delivery.
  • Webhooks: register endpoints, Slack and Microsoft Teams channels, and send test events.
  • Partners: create child organizations, act on them and track each one's usage.

Before you start

ItemValue
Base URLhttps://app.proteside.com/api/v1
TransportHTTPS, JSON request bodies and responses
Field namessnake_case
AuthenticationAuthorization: Bearer ps_live_…
Rate limit120 requests per minute per organization

There's no test environment

Every token issued is ps_live_ and every call acts on your production data. To experiment, use a staging store and tokens with read-only scopes.

The API is designed for server-to-server calls: authenticated routes don't respond to CORS, so calls made directly from the browser are blocked. Keep the token on your backend.

Quick start

Create a token

In Settings → API, click New token, give it a name, check the read-only shortcut and click Create token. Copy the token in the Copy your token now window: it's shown only once. The full walkthrough is in Tokens and scopes.

Make your first request

List your organization's stores:

export PROTESIDE_TOKEN="ps_live_Ab3dEf6hIj9kLm2nOp5qRs8t_..."

curl -s "https://app.proteside.com/api/v1/stores?limit=2" \
  -H "Authorization: Bearer $PROTESIDE_TOKEN"

Read the response

Lists always come in data, with next_cursor to fetch the next page (null when there are no more):

{
  "data": [
    {
      "id": "0c1d2e3f-1111-4222-8333-444455556666",
      "org_id": "7f3c1e2a-0b4d-4c8e-9f10-2a3b4c5d6e7f",
      "name": "My Store",
      "domain": "mystore.com",
      "country": "BR",
      "timezone": "America/Sao_Paulo",
      "status": "active",
      "sdk_key": "pk_live_3f9c0a1b2c3d4e5f60718293a4b5c6d7",
      "safe_slug": "mystore-ps3fa9c1",
      "emergency_contact": null,
      "created_at": "2026-09-27T10:01:00.000Z",
      "updated_at": "2026-09-27T10:01:00.000Z",
      "sdk_config": {
        "mode": "monitor",
        "payment_methods": ["pix", "card"],
        "release_channel": "stable"
      }
    }
  ],
  "next_cursor": null
}

The X-RateLimit-Limit and X-RateLimit-Remaining headers show how much of the per-minute limit you have left. See Conventions for pagination, errors and limits.

OpenAPI specification

The full API contract is at https://app.proteside.com/api/v1/openapi.json (OpenAPI 3.1, public, no token required). Import that address into Postman, Insomnia or your language's client generator. This documentation's endpoint reference is generated from it.

When this documentation and the spec disagree, what's described here prevails: the conceptual pages document the API's actual behavior, including the places where the spec is still out of date.

Next steps

Endpoint reference

On this page