ProLasku.fi API Documentation
Welcome to the ProLasku.fi API documentation. This API provides a robust and flexible way to interact with the ProLasku.fi system, allowing for seamless integration and automation of content management, e-commerce, invoicing, and inventory tasks.
Introduction
The ProLasku.fi API is designed to be simple yet powerful, providing developers with the tools to enhance their applications with content management capabilities. Whether you're building a website, a mobile app, a POS integration, or a complex enterprise system, our API can help you manage content efficiently and securely.
Features
- REST-like API Calls — Intuitive endpoint structure using GET/SET/CHECK pattern
- No Dependencies — The API is designed to work independently, requiring no additional dependencies for basic operations
- Super Fast — Optimized for performance with a 50-row query limit ensuring quick responses
- Extensible — Flexible architecture supporting multi-tenant, multi-language, multi-currency, and multi-location setups
- Highly Secured — 512-bit encryption key with API key authentication, input sanitization, and scripting protections
Getting Started
To start using the ProLasku.fi API, follow these basic steps:
- API Key: Obtain your unique API key from the admin panel. Create / Access API Credentials
- Authentication: Include your API key in the
Authorization1 header (Base64-encoded) with each request
- Make a Request: Send HTTP POST requests to the API endpoints with required parameters
- Handle Responses: Process the JSON responses — standard format includes
INFO (pagination metadata) and OUTPUT (data array)
PHP Example
$curl = new Curl();
$curl->setHeader('Authorization1', base64_encode($API_KEY));
$curl->post('https://yourdomain.fi/public_api/get_products/', [
'username' => $API_USERNAME,
'password' => $API_PASSWORD,
]);
$response = json_decode($curl->response, true);
Attribution: Optional user_email on Setter Calls
Applications calling setter endpoints (set_product, set_stock, set_order, …) may include an optional user_email body parameter to identify which of their own users made the call. When a valid email is provided, activity logs and stock movements attribute the write to API-{username} - {user_email} (e.g. API-Shop_1 - [email protected]); when omitted, the actor stays API-{username}. See API Credential Creation Guide — Identifying the Application User.
Basic Requirements
- Internet Connectivity — Stable connection to the ProLasku.fi API servers
- API Credentials — Valid API key and account credentials (Create / Access API Credentials)
- HTTP Client — Any tool capable of making HTTP POST requests (cURL, PHP Curl Class, Postman, etc.)
- PHP 8.0.2+ — Server-side compatibility (tested up to PHP 8.4)
Available Public Endpoints
Products
Product Tags
Categories, Brands & Taxonomy (Inventory)
Customers
Orders
Stock & Inventory
Purchase Orders
Suppliers
POS / Cash Register
Reference Data
Additional Endpoints
These endpoints are available but do not yet have dedicated documentation pages:
| Method |
Endpoint |
Description |
| POST |
set_order_update |
Update an existing order |
| POST |
set_order_cash_register |
Create/update cash register order |
| POST |
set_delivery_note_cashregister |
Create delivery note for cash register |
| POST |
set_customer_register_wp |
Register a new club member (WordPress) |
| POST |
set_customer_update_profile_wp |
Update club member profile (WordPress) |
| POST |
set_voucher_used |
Mark a voucher as used |
| POST |
set_firebase_token |
Register Firebase push notification token |
| POST |
set_push_notification |
Send push notification |
| POST |
delete_purchase_order_line |
Delete a purchase order line |
| POST |
delete_customer |
Delete a customer |
| POST |
get_stockcurrent_full |
Full stock current data (unfiltered) |
| POST |
get_firebase_token |
Retrieve Firebase tokens |
| POST |
get_html_aboutus |
Retrieve About Us HTML content |
| POST |
get_html_appguide |
Retrieve App Guide HTML content |
| POST |
get_html_moreinfo |
Retrieve More Info HTML content |
| POST |
get_html_privacypolicy |
Retrieve Privacy Policy HTML content |
Mobile App Authentication (User QR on top of account API credentials)
Mobile applications authenticate the account with the normal API credentials
(either authentication mode), then log a specific CMS user in with a
per-user login token — the single token string encoded in the user's QR code
(Users → Mobile app tab, Employees editor, or the user's own Profile page).
verify_user takes the account credentials plus user_token and returns the
user's profile (never passwords).
| Method |
Endpoint |
Description |
| POST |
verify_user |
Verify a mobile-app user token (on top of account API auth) and return the user profile (never passwords) |
Validation & Utility Endpoints
| Method |
Endpoint |
Description |
| POST |
check_authorization_header |
Validate API authorization header |
| POST |
check_post_data |
Validate POST request data |
| POST |
check_get_data |
Validate GET request data |
| POST |
check_request_type |
Check allowed request methods |
Response Format
All endpoints return JSON in the following structure:
{
"INFO": {
"start": 0,
"limit": 50,
"count": 25,
"total_count": 150
},
"OUTPUT": [ ... ]
}
Maximum 50 rows per request. Use start and limit parameters for pagination.
Error Handling
"UN-AUTHORIZED!"
HTTP status codes are used for error responses (e.g., 404 Not Authorized for invalid credentials).
Security Considerations
- Input Sanitization — All user input is properly escaped and sanitized server-side
- Scripting Protections — Additional safeguards sanitize scripting vectors in requests and responses
- API Key Authentication — All requests require a valid API key in the authorization header
- Encryption — Data protected with 512-bit encryption keys
For detailed information on individual endpoints, request/response parameters, and advanced usage, refer to the endpoint-specific documentation pages linked above.