REST API, version 1

The Petronyx API is the same one our web and mobile apps use: stations, shifts, stock sheets, pricing and staff, behind one consistent interface.

Sign in
curl -X POST https://api.petronyx.net/api/v1/auth/login \
  -H "content-type: application/json" \
  -d '{"email":"you@company.com","password":"your-password"}'

From zero to your first call.

Base URL https://api.petronyx.net/api/v1

  1. 01

    Sign in

    Post a workspace user's email and password. You get an access token, a refresh token and the expiry in seconds.

    curl -X POST https://api.petronyx.net/api/v1/auth/login \
      -H "content-type: application/json" \
      -d '{"email":"you@company.com","password":"your-password"}'
  2. 02

    Answer the two-factor challenge

    If the user has two-factor sign-in on, login returns a challenge and a short-lived session instead of tokens. Send the six-digit code to finish.

    cURL
    curl -X POST https://api.petronyx.net/api/v1/auth/verify-mfa \
      -H "content-type: application/json" \
      -d '{
        "email": "you@company.com",
        "session": "<session from the login response>",
        "challengeName": "SOFTWARE_TOKEN_MFA",
        "code": "123456"
      }'
  3. 03

    Call the API

    Requests are scoped to the user's company automatically. List the stations they can see.

    curl https://api.petronyx.net/api/v1/stations \
      -H "authorization: Bearer $ACCESS_TOKEN"

Conventions you can rely on.

One envelope

Every success returns success, data and optional meta. Every error returns success false, a status code and a requestId.

Bearer tokens

Sign in for an access token and a refresh token. Send the access token in the Authorization header.

Versioned paths

The version is part of the URL, so a breaking change ships as a new version rather than under your integration.

Strict input

Payloads are validated and unknown fields are rejected, so typos fail loudly instead of silently.

Rate limits

Sign-in is rate limited. Back off and retry when you receive HTTP 429.

Traceable errors

Quote the requestId from an error response when you contact us and we can find the exact call.

Error response
{
  "success": false,
  "statusCode": 400,
  "requestId": "6f1c...",
  "timestamp": "2026-10-02T08:15:00.000Z",
  "path": "/api/v1/stations",
  "method": "POST",
  "error": {
    "statusCode": 400,
    "message": ["name must be a string"],
    "error": "Bad Request"
  }
}

Webhooks are planned.

Event notifications are not available yet. Tell us which events your integration needs and we will factor them in.

Talk to the partnerships team

Integration access

Building an integration for ATG gauges, forecourt controllers or payments? We arrange access and test workspaces with integration partners directly.

Partner program

Ready for the details?

Every resource group, authentication flow and response format in one reference.