The Petronyx API is the same one our web and mobile apps use: stations, shifts, stock sheets, pricing and staff, behind one consistent interface.
curl -X POST https://api.petronyx.net/api/v1/auth/login \
-H "content-type: application/json" \
-d '{"email":"you@company.com","password":"your-password"}'From zero to your first call.
Base URL https://api.petronyx.net/api/v1
- 01
Sign in
Post a workspace user's email and password. You get an access token, a refresh token and the expiry in seconds.
curl -X POST https://api.petronyx.net/api/v1/auth/login \ -H "content-type: application/json" \ -d '{"email":"you@company.com","password":"your-password"}' - 02
Answer the two-factor challenge
If the user has two-factor sign-in on, login returns a challenge and a short-lived session instead of tokens. Send the six-digit code to finish.
curl -X POST https://api.petronyx.net/api/v1/auth/verify-mfa \ -H "content-type: application/json" \ -d '{ "email": "you@company.com", "session": "<session from the login response>", "challengeName": "SOFTWARE_TOKEN_MFA", "code": "123456" }' - 03
Call the API
Requests are scoped to the user's company automatically. List the stations they can see.
curl https://api.petronyx.net/api/v1/stations \ -H "authorization: Bearer $ACCESS_TOKEN"
Conventions you can rely on.
One envelope
Every success returns success, data and optional meta. Every error returns success false, a status code and a requestId.
Bearer tokens
Sign in for an access token and a refresh token. Send the access token in the Authorization header.
Versioned paths
The version is part of the URL, so a breaking change ships as a new version rather than under your integration.
Strict input
Payloads are validated and unknown fields are rejected, so typos fail loudly instead of silently.
Rate limits
Sign-in is rate limited. Back off and retry when you receive HTTP 429.
Traceable errors
Quote the requestId from an error response when you contact us and we can find the exact call.
{
"success": false,
"statusCode": 400,
"requestId": "6f1c...",
"timestamp": "2026-10-02T08:15:00.000Z",
"path": "/api/v1/stations",
"method": "POST",
"error": {
"statusCode": 400,
"message": ["name must be a string"],
"error": "Bad Request"
}
}Ready for the details?
Every resource group, authentication flow and response format in one reference.