OpenMercantil User API declares
3 security schemes
for authenticating requests.
An API key is passed in the cookie as ob_sess (cookieAuth).
An API key is passed in the header as X-API-Key (apiKey).
It accepts HTTP bearer tokens (opaque omk_* credential) (bearerAuth).
cookieAuth — Browser session cookie set after login at /mi-cuenta/login. Mutations also require X-CSRF-Token header (obtain via GET /api/v1/user/me).
apiKey — Optional opaque omk API credential for public GETs. Anonymous access remains valid; a credential with the operation's x-api-credential-scope (or public:read) s…
bearerAuth — Optional Authorization: Bearer transport for the same opaque omk API credential accepted by X-API-Key. It is not a JWT or OAuth access token.
Paths & Operations 65
Across 44 paths, the API surfaces 65 operations — 9 DELETE, 21 GET, 4 PATCH, 26 POST, 5 PUT. Each is listed below with its method, path, parameters, and response codes.
User 65
Authenticated Panel Pro endpoints — segments, lists, notes, tags, exports, audit. Requires session cookie (browser) and X-CSRF-Token header for mutations.
GET
/api/v1/user/me
Current authenticated user
getUserMe→ 200401
GET
/api/v1/user/org
Get the current organization, seats and visible members
The contract defines 89 schemas that model the data the API accepts and returns. The most detailed are ErrorResponse (35 properties), BillingInvoice (16 properties), KycPersonLookupResponse (16 properties), LegalReportAxis (15 properties). Each schema is shown below with its type and property counts.
LegalReportResponse
object
7 properties7 required
StripeSessionResponse
object
2 properties2 required
UserSegmentStoredFilters
object
Read-only decoded filtersjson from an existing segment. New writes must use UserSegmentFilters. Historic records may still contain removed keys such as forma o…
EmailDispatchResponse
object
2 properties2 required
OutboundWebhookEventTypeV1
string
Exact subscription allowlist for webhook payload contract 1.0. Unknown event types, wildcard subscriptions and unsupported schema versions fail closed. Adding…
PersonaOption
object
4 properties4 required
UserSegmentRunResponse
object
4 properties4 required
OutboundWebhookOneTimeResponse
object
5 properties5 required
LegalReportPaymentRequiredError
OrganizationMember
object
4 properties4 required
UserListListResponse
object
3 properties3 required
OrganizationCreatedResponse
object
2 properties2 required
UserOrganizationInviteRequest
object
2 properties1 required
VerificationDispatchResponse
object
2 properties2 required
WebhookWorkerHealth
object
4 properties3 required
UserTagCreatedResponse
object
2 properties2 required
OutboundWebhookEventCatalogV1
Exact account-visible list of events with a currently wired durable producer.
UserSegmentCreateRequest
object
6 properties2 required
BillingSubscription
object
Authenticated user's current subscription metadata.
14 properties
SupportErrorResponse
object
4 properties2 required
UserSegment
object
Saved account segment. Extra migration columns may be returned for backward compatibility.
11 properties
ApiCredential
object
13 properties8 required
CredentialRevokedResponse
object
2 properties2 required
BillingInvoicesResponse
object
3 properties3 required
OutboundWebhookContractedEventTypeV1
string
Versioned event names with a defined payload contract. Only names also present in OutboundWebhookEventTypeV1 are currently subscribable.
UserListDetail
LegalReportDocument
object
3 properties3 required
UserSegmentListResponse
object
3 properties3 required
OutboundWebhookUpdateRequest
object
3 properties
JsonValue
A JSON value used only inside explicitly documented extension maps.
UserNote
object
Private note visible only to its authenticated owner.
9 properties
OrganizationInviteCreatedResponse
object
7 properties7 required
UserNotesForTargetResponse
object
2 properties2 required
KycPersonLookupRequest
object
2 properties2 required
UserPersonaSelectedResponse
object
2 properties2 required
UserSegmentFilters
object
Corporate-only filters executed exclusively over the immutable companypublicv2 sidecar. At least one effective anchor is required: provincia, cnaeprefix, a cap…
8 properties
UserOrganizationResponse
object
5 properties
LegalReportAxis
object
One documentary axis in the redacted corporate legal-history projection. Presence records sourced events; it does not assert wrongdoing, solvency, current stat…
15 properties4 required
UserNoteListResponse
object
2 properties2 required
CompanySearchItem
object
12 properties4 required
BillingInvoice
object
Authenticated user's invoice metadata; URLs point to Stripe-hosted documents.
16 properties
UserOrganizationMemberRoleRequest
object
1 property1 required
KycPersonLookupResults
object
3 properties3 required
DeletedResponse
object
2 properties2 required
LegalReportRequest
object
The body carries only the CSRF fallback. Entitlement, pricing, beta status and the daily idempotency key are server-owned.
1 property
UserTagAssignmentRequest
object
2 properties2 required
UserListItem
object
Saved list item owned by the authenticated account.
6 properties
RequestBodyTooLargeError
object
2 properties2 required
ErrorResponse
object
Closed compatibility envelope for public/account errors. Route-specific schemas narrow these fields further where required.
35 properties1 required
UserAuditEntry
object
Account audit entry. Sensitive metadata is not part of the public contract.
5 properties
UserPersonaUpdateRequest
object
1 property1 required
UserSegmentPinResponse
object
1 property1 required
OutboundWebhookContractedEventCatalogV1
array
All event payload contracts known by this API version, including contracted-but-unwired events that cannot yet be subscribed.
ApiCredentialCreateRequest
object
3 properties1 required
ApiCredentialRotateRequest
object
3 properties
SupportReplyRequest
object
1 property1 required
UserNoteUpdateRequest
object
3 properties
UserExportRecord
object
Authenticated user's export history metadata.
5 properties
UserNoteCreateRequest
object
5 properties3 required
UserListCreatedResponse
object
2 properties2 required
UserTagListResponse
object
3 properties3 required
UserTagCreateRequest
object
2 properties1 required
UserExportListResponse
object
2 properties2 required
UserListUpdateRequest
object
4 properties
UserOrganizationNameRequest
object
1 property1 required
OrganizationInvite
object
5 properties5 required
KycPersonLookupResponse
object
16 properties3 required
KycPersonLookupHistoryResponse
object
4 properties4 required
ApiCredentialOneTimeResponse
object
7 properties6 required
SupportRequestErrorResponse
Support validation/ownership errors carry ok=false; shared body-reader and action-budget errors use the generic API error envelope.
UserSegmentUpdateRequest
object
5 properties
KycUsage
object
5 properties5 required
UserNoteCreatedResponse
object
2 properties2 required
OutboundWebhookCreateRequest
object
2 properties2 required
ExportUsageResponse
object
5 properties5 required
WebhookUpdatedResponse
object
2 properties2 required
UserSegmentCreatedResponse
object
2 properties2 required
UserList
object
Saved user list; migration columns may be appended.
9 properties
OkResponse
object
1 property1 required
UserAuditResponse
object
2 properties2 required
KycPersonLookupUsageResponse
object
5 properties1 required
UserPersonaResponse
object
3 properties3 required
UserListItemCreateRequest
object
3 properties2 required
UserListCreateRequest
object
4 properties1 required
UserTag
object
Private account tag and optional aggregate usage count.
6 properties
OutboundWebhook
object
9 properties6 required
UserMeResponse
object
7 properties4 required
KycLookupHistoryEntry
object
9 properties8 required
OutboundWebhookEventSubscriptionsV1
array
Events with a currently wired durable producer. Contracted-but-unwired event types are not subscribable. An empty input is normalized to alert.triggered; wildc…
Specification
The full machine-readable OpenAPI contract behind this narrative.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of OpenMercantil User API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.