Install Jentic One Beta
Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the Karo Device File Interaction API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.
Two steps, two machines. Install the instance in a safe environment, then register your agent from wherever it runs.
Step 1: Jentic One Host machine
# On the machine that will host your Jentic One instance:
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fdatev-business.de%2Fdatev-business" | shStep 2: Agent machine
# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fdatev-business.de%2Fdatev-business" | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.
What an agent can do with Karo Device File Interaction API.
List the DATEV tenants your authenticated application can access
Import a cash-register transaction file under a chosen tenant
Retrieve the technical security equipment (TSE) logs recorded for a tenant
Select TSE logs by a cash register's serial number
Patterns agents use Karo Device File Interaction API for, with concrete tasks.
GET STARTED
★ Agent-Driven Cash-Register Imports
An AI agent moves point-of-sale data into DATEV for a bookkeeping client by first listing the tenants the application can reach, then uploading the day's cash-register file to the right one. The agent confirms the tenant before importing, so register data lands under the correct client without manual file handling.
List the available tenants, then import the day's cash-register file for the selected tenant id
TSE Log Retrieval for Audits
Pull the technical security equipment logs for a cash register when preparing for a German fiscal audit. Given a tenant and a register serial number, the API returns the TSE logs so a compliance tool can archive them and show that register transactions were recorded as the tax authority requires.
Retrieve the TSE logs for a given tenant and cash-register serial number for the latest fiscal period
Multi-Tenant Register Onboarding
Route imports across many bookkeeping clients by listing every tenant the application is authorised for and tracking which ones have register data in place. This gives an onboarding tool a per-tenant view before it starts importing files.
List all tenants the application can access and report which ones still have no cash-register file imported
3 endpoints — the karo device file interaction api lets datev partners import cash-register transaction files and read technical security equipment (tse) logs for a given tenant.
METHOD
PATH
DESCRIPTION
/tenants
List accessible tenants
/tenants/{tenant-id}/files/import
Import a cash-register file for a tenant
/tenants/{tenant-id}/tselogs/{serial-number}
Read TSE logs for a register by serial number
/tenants
List accessible tenants
/tenants/{tenant-id}/files/import
Import a cash-register file for a tenant
/tenants/{tenant-id}/tselogs/{serial-number}
Read TSE logs for a register by serial number
What agents get from Jentic-routed access to this vendor.
Setup
By hand you register an application with DATEV, implement the OAuth 2.0 device or hybrid flow, request the cash-register import scope, and manage token refresh before a single file moves. Through Jentic you connect once from the API Directory and your agent calls the three operations.
Permission scoping
There are only three operations, so you decide exactly which your agent may call, such as listing tenants and importing files but not reading logs. The tenant id and the cash-register serial number travel in the URL path, so a rule can bind the agent to a single tenant's operations.
Credential isolation
Your OAuth 2.0 token is stored encrypted on your own Jentic One instance and injected at execution time, never placed in the agent's prompt, logs, or context. You rotate or revoke it in one place without touching agent code.
Intent-based discovery
Agents search Jentic by intent such as 'import a cash-register file' or 'get TSE logs', and Jentic returns the matching DATEV Karo operation with its input schema so the agent calls the right endpoint without reading the reference docs.
Alternatives and complements available in the Jentic catalogue.
Specific to using Karo Device File Interaction API through Jentic.
What authentication does the DATEV Karo API use?
It uses OAuth 2.0: the spec declares two oauth2 schemes, a device flow and a hybrid flow, both carrying the business:karo:cashregisterimport scope. Your application obtains a token through one of those flows and sends it on every request. Through Jentic, your own Jentic One instance holds that token encrypted and attaches it at call time.
Can I import cash-register files for more than one tenant?
Yes. You first list the tenants your application can access, then call the import endpoint under a specific tenant id, so one integration can serve many bookkeeping clients. The TSE log endpoint is likewise scoped to a tenant and a cash-register serial number.
What are the rate limits for the DATEV Karo API?
The OpenAPI spec does not state rate limits. Check the official DATEV developer documentation at https://developer.datev.de/ for current limits and quotas before running bulk imports.
How do I connect the DATEV Karo API through Jentic?
Add the DATEV Karo Cash-Register API from the Jentic API Directory and complete the OAuth 2.0 connection once. Your agent then searches by intent such as 'import a cash-register file' and calls the matching operation. To run it on your own infrastructure, install Jentic One from its GitHub repo.
Can I control which DATEV operations my agent is allowed to call?
Yes. There are only three operations, so you grant your agent exactly the ones it needs, for example listing tenants and importing files while withholding log retrieval. The tenant id and serial number sit in the URL path, so a rule can bind the agent to a specific tenant's operations, and every call is logged.
Is there a DATEV Karo API MCP server?
You don't need an MCP server to use the DATEV Karo API with your agent. Jentic connects it directly from the API Directory: import it, complete the OAuth step once, and your agent can list tenants and import files without another server loading tool definitions into its context.
Know of an official OpenAPI document? Contribute it →
For Agents
Import cash-register transaction files into DATEV and retrieve technical security equipment (TSE) logs for a tenant. Lists accessible tenants and reads logs by cash-register serial number.
Use for: List the DATEV tenants I can access, Import a cash-register file for a tenant, I want to upload today's register transactions to DATEV, Get the TSE logs for a specific cash register
Not supported: Does not handle DATEV accounting postings, payroll, or tax filing. Use for importing cash-register files and retrieving TSE logs per tenant only.
The Karo Device File Interaction API lets DATEV partners import cash-register transaction files and read technical security equipment (TSE) logs for a given tenant. You list the tenants your application can reach, upload a register file for one of them, and pull back the TSE logs recorded against a specific cash register by its serial number. It targets the German fiscal-compliance workflow around electronic cash registers, where register data has to be captured and preserved for the tax authority.
This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.
Base layer of spec validity and structural soundness.
Aggregated quality score from linter diagnostics, weighted by severity.
Percentage of `$ref` references that resolve successfully.
Checks whether the API description parses successfully and conforms to its declared specification (e.g., OpenAPI).
Structural correctness score based on schema issues using logarithmic dampening.
Clarity, completeness, and ingestion readiness for developers and tooling.
How richly the API is illustrated with examples.
Percentage of examples that conform to their schemas.
Percentage of operations with complete response definitions (success, client error, server error).
Health of API ingestion, bundling, and resolution within Jentic pipelines.
Semantic breadth, depth, and agent comprehension for AI systems.
Coverage of descriptions across API elements.
Coverage of RFC 9457 Problem Details for error responses.
Coverage, uniqueness, and casing consistency of operationIds for AI inference.
Coverage of summaries across operations/tags/info.
Functional utility, complexity comfort, and AI orchestration readiness.
Agent comfort level based on API operational and structural complexity.
Trust, risk posture, and security compliance.
Average quality of security schemes based on authentication method strength (weakest link for OAuth2).
Findability, semantic richness, and reasoning readiness.
Clarity and depth of descriptions across API elements.
Score it yourself
Every API in the directory is allowlisted, so you can re-score it with no key required.
npx @jentic/api-scorecard-cli score <openapi-url>