Quick start
Create a testing token, list businesses, and read accounts for the slug the API returned.
This is the shortest path that stays on the testing API. It uses a personal access token. It does not use MCP.
Testing data
Create the token in the testing environment. Requests in this guide go to https://api-tst.nocfo.io. Do not substitute the production host or a production token while following these steps.
1. Create a token
Open login-tst.nocfo.io/auth/tokens and create a personal access token. The token acts as you. Treat it like a password. Do not commit it.
2. List businesses
curl --fail-with-body \
'https://api-tst.nocfo.io/v1/business/' \
-H 'Authorization: Token <your_token_here>'The JSON body has count and results. Each result includes slug. Keep a slug from this response. That value is the only business identifier the rest of this guide uses.
A missing or rejected token returns 401. Fix the header. Do not retry with a guessed slug.
3. List accounts for that business
curl --fail-with-body \
'https://api-tst.nocfo.io/v1/business/<slug>/account/' \
-H 'Authorization: Token <your_token_here>'<slug> is the value from step 2. This is a read. The operation is Accounts - List.
After these calls
- Keep the token out of source control. It only works on
https://api-tst.nocfo.io. - Send
Authorization: Tokenon every request. A one-hour JWT uses the same header. See Authentication. - On a POST that creates a resource, send a new
Idempotency-Keyfor that operation. See Idempotency. - Branch on the HTTP status and, when the body has it,
error_code. See Errors. - Use
https://api.nocfo.ioonly with a production token.
Acceptance checklist
- A request with a bad token returns 401 and does not return businesses.
GET /v1/business/returnsresults, and every later path uses aslugfrom that list.GET /v1/business/{business_slug}/account/uses the testing host.- Logs do not contain the token.
- A production URL is not used with the testing token.