Developers
One ledger.
Every way in.
The REST API, the CLI and the MCP server run the same code the dashboard runs, with the same checks, on keys that carry only the scopes you grant.
- REST and JSON
- /api/v1
- MCP transports
- stdio · HTTP
- Signed webhooks
- HMAC-SHA256
terminal
$ npm install -g cynco-cli$ export CYNCO_API_KEY=cak_…$ cynco tb --period 2026-03$ cynco extract ./receipt.jpg --type receipt$ cynco invoices create --customer-id cust_abc123 \ --currency MYR --due-date 2026-04-15 --items @items.json$ curl -X POST https://app.cynco.io/api/v1/invoices \ -H "Authorization: Bearer $CYNCO_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "customerId": "cust_abc123", "currency": "MYR", "status": "draft", "lineItems": [ { "description": "Bookkeeping, March", "quantity": 1, "unitPrice": 1200 } ] }'{ "mcpServers": { "cynco": { "command": "cynco", "args": ["mcp", "serve"] } }}Three ways in
REST API
JSON over HTTPS under /api/v1. Authenticate with an API key or an OAuth access token.
Authorization: Bearer cak_…CLI
The cynco command runs reports, reads documents and manages records from the terminal, with JSON output for scripts.
npm install -g cynco-cliMCP server
120 tools for agents over stdio or Streamable HTTP, with the same checks as the dashboard.
https://mcp-stegona.cynco.io/mcp
The details
What a request carries, and what it can and cannot do.
- Keys
- API keys start with cak_ and OAuth access tokens with cynco_at_. Each key carries only the scopes you grant it.
- Same rules as the app
- Every call runs the code the dashboard runs: tenant scoping, closed periods and approval all apply.
- Webhooks
- Each delivery carries X-Cynco-Signature and X-Cynco-Timestamp, an HMAC-SHA256 over the timestamp and the body.
- CLI output
- Tables in a terminal. Clean JSON with --json or --agent, or CSV with -o csv, when piped.
- MCP
- Tools for the ledger, invoicing, bills, the bank, assets, agreements and the data room, plus prompts, resources and interactive apps.