Developers
From zero to your first API response in five steps.
Want to connect ChatGPT, Claude or another assistant without writing code? Start with Connect your AI.
BMC enables API access for each company. Until it is active, the client area does not show the Developers section. If you do not see it, write to plataforma@bm.consulting with the company name.
The account holder (OWNER) or an administrator (ADMIN) of the company can create, edit, rotate and revoke tokens. Other users see the list but cannot change it.
bmc_live_…: it is shown only once. Confirm with I have saved it.Store the token in a secrets manager or an environment variable. Do not write it in code or commit it to a repository. The same token works for the REST API and for the MCP server.
In the Credentials list each token has a switch to turn it off and on again, and the actions Edit, Rotate (replaces the secret immediately; the old one stops working) and Revoke (permanent). The month's consumption is under the API usage tab.
This call lists your contacts. It requires the contacts:contacts.read permission, so the token needs at
least the Read level on the Contacts resource.
export BMC_TOKEN="bmc_live_…" curl -X GET "https://app.bm.consulting/api/v1/contacts?limit=50" \
-H "Authorization: Bearer $BMC_TOKEN" const res = await fetch("https://app.bm.consulting/api/v1/contacts?limit=50", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.BMC_TOKEN}`,
},
});
if (!res.ok) throw new Error(`${res.status} ${await res.text()}`);
const data = await res.json(); import os
import requests
res = requests.get(
"https://app.bm.consulting/api/v1/contacts?limit=50",
headers={"Authorization": f"Bearer {os.environ['BMC_TOKEN']}"},
timeout=30,
)
res.raise_for_status()
data = res.json()
A successful response returns 200 and JSON. On this route the list comes in contacts
together with the pagination fields. If the token cannot see personal data, the tax ID, phone and other personal
data come back masked.
{
"contacts": [
{
"id": "…",
"firstName": "Ana",
"lastName": "García",
"fullName": "Ana García",
"email": "ana@example.com",
"nif": "A******21",
"isActive": true
}
],
"total": 1,
"page": 1,
"limit": 50,
"pages": 1
}
A 401 means the token is invalid, expired or revoked. A 403 means the token lacks the
route's permission or the call comes from a disallowed IP. See Errors.
Accounting routes carry the company in the path (/books/{companyId}/…). The
companyId is the company's identifier at BMC. To see which companies your token reaches, call
GET /auth/whoami, which requires no permission:
curl "https://app.bm.consulting/api/v1/auth/whoami" \
-H "Authorization: Bearer $BMC_TOKEN" {
"token": { "id": "…", "prefix": "bmc_live_…", "name": "Monthly treasury report", "kind": "API" },
"accountId": "cm…a1",
"accountIds": ["cm…a1", "cm…b2", "cm…c3"],
"audience": "client",
"scopes": ["…"],
"permissions": ["…"],
"piiAccess": false,
"expiresAt": null,
"groupIds": ["cm…b2"]
} accountId: the token's primary account (quota and limits).accountIds: every company it reaches today, primary first, with group subsidiaries already included. Any of them is a valid companyId.groupIds: the groups chosen as a whole.
A companyId outside that list gets 403 or 404, with no data from another company.
Base URL: https://app.bm.consulting/api/v1