canonical: https://jentic.com/apis/quiltt.dev/quiltt-dev

# Quiltt API

Financial data platform API for managing profiles, connections, accounts, transactions, and integrations with financial data providers. The API exposes 17 endpoints secured with bearer authentication.

## For AI agents

Programmatically issue session token, revoke current session. Covers 17 operations with bearer authentication.

## Scope

Does not handle communications, crm, or developer tools - use for payments only.

## Capabilities

- Issue session token
- Revoke current session
- Validate API key
- Create profile
- List all profiles

## Use cases

### Payments Operations

Use the Quiltt API to perform payments operations programmatically. The API provides 17 endpoints covering core functionality including issue session token, revoke current session, validate API key.

Example prompt: Call POST `/v1/users/sessions` to issue session token

### Automated Accounts Management

Automate accounts operations by combining multiple Quiltt API endpoints. Agents can revoke current session and then validate API key in a single workflow.

Example prompt: Call DELETE `/v1/users/session` to revoke current session, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Quiltt API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle bearer tokens manually.

Example prompt: Search Jentic for 'issue session token', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| POST | `/v1/users/sessions` | Issue session token |
| DELETE | `/v1/users/session` | Revoke current session |
| POST | `/v1/introspect/api_key` | Validate API key |
| POST | `/v1/introspect/session_token` | Validate session token |
| POST | `/v1/introspect/processor_token` | Validate processor token |
| POST | `/v1/profiles` | Create profile |
| GET | `/v1/profiles` | List all profiles |
| GET | `/v1/profiles/{id}` | Get profile |

## Key resources

- **Accounts** — Operations related to Accounts
- **Authentication** — Operations related to Authentication
- **Connections** — Operations related to Connections
- **Institutions** — Operations related to Institutions
- **Profiles** — Operations related to Profiles

## Why Jentic

- **Setup:** Wiring Quiltt by hand means learning its bearer auth, targeting the api.quiltt.io host, and handling session, introspection, and profile calls with your own retries. Through Jentic you install once, import Quiltt from the API Directory, store the token once, and your agent calls it.
- **Permission scoping:** Quiltt puts the profile id in the URL path (`/v1/profiles/{id}`), so a rule can pin your agent to one profile: it reads that profile and nothing else. You choose the operations it may call, so destructive ones like deleting a session are not included unless you add them.
- **Credential handling:** Your Quiltt token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'create a Quiltt profile' or 'introspect an API key', and Jentic returns the matching Quiltt operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Stripe** — Alternative payments API
- **Adyen** — Alternative payments API
- **Square** — Complementary payments API
- **Paypal** — Complementary payments API

## FAQ

### What authentication does the Quiltt API use?

The Quiltt API uses a Bearer token in the Authorization header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I issue session token with the Quiltt API?

Yes. Use the POST `/v1/users/sessions` endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Quiltt API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I issue session token through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'issue session token'. Jentic returns the matching Quiltt API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Quiltt API have?

The Quiltt API exposes 17 endpoints covering accounts, authentication, connections operations.

### Can I limit what my agent is allowed to do with the Quiltt API?

Yes. Because you run Jentic One yourself, your own rules decide which Quiltt operations and credentials the agent may use, and it can call nothing else. Since Quiltt puts the profile id in the URL path (`/v1/profiles/{id}`), you can pin the agent to a single profile so it reads that profile and nothing more. You choose which operations to expose, so destructive calls such as revoking a session with DELETE `/v1/users/session` stay off limits unless you add them.
