Getting started
This page gets you from nothing to a working API call. You need a neoo company (dataset) and permission to create API keys in it.
1. Create an API key
In the app, open the company and go to System → Management → API Keys, then click Create API Key. Give the key a label that says what uses it, for example “Payroll export”.
The key starts with ak_ and is shown once. Copy it straight away and store it in your integration’s secret store. If you lose it, delete it and create a new one.
A key belongs to the user who created it and can do exactly what that user can do in this one company. For an integration it is usually best to create a dedicated user with a role that allows only what the integration needs, and create the key as that user. See Users & roles for who can create keys.
2. Find your base URL
Every endpoint lives under your dataset’s base URL:
https://apineo.z83.ch/client/{dataset}
{dataset} is the company’s dataset name. It is the name shown in the app’s address bar after /client/. For a dataset called acme, listing vendor transactions is:
GET https://apineo.z83.ch/client/acme/arap/transactions/vendor
3. Make your first call
Send the key in the X-API-Key header on every request. Start by checking the key works for your dataset:
curl -X POST https://apineo.z83.ch/client/acme/auth/validate_api \
-H "X-API-Key: ak_your_key_here"
{ "success": 1 }
If the key is wrong you get 401, and if it has no access to that dataset you get 403. Both come with a message saying why.
Now read some data. This searches vendors by name:
curl "https://apineo.z83.ch/client/acme/arap/vendor?name=swisscom" \
-H "X-API-Key: ak_your_key_here"
[
{
"id": 1001,
"name": "Swisscom (Schweiz) AG",
"vendornumber": "V-1042",
"city": "Bern",
"zipcode": "3050",
"country": "CH"
}
]
The id is what other endpoints expect when they ask for a vendor_id.
4. Send data
Requests with a body use JSON:
curl -X POST https://apineo.z83.ch/client/acme/arap/transaction/vendor \
-H "X-API-Key: ak_your_key_here" \
-H "Content-Type: application/json" \
-d '{ "type": "transaction", "vendor_id": 1001, "invDate": "2026-09-01", "curr": "CHF", "recordAccount": "2000", "lines": [ { "account": "6500", "amount": 250 } ] }'
{ "id": 15659 }
That call saved a draft vendor bill. Book a vendor bill walks through this properly, including tax, attachments and approval.
Keep your key safe
- Only call the API from a server. Never put a key in a browser app, a mobile app or a public repository.
- Use one key per integration, so you can switch one off without affecting the others.
- Deleting a key in System → Management → API Keys stops it immediately.
- Every change made with a key shows up in the audit log as via API key, against the user the key belongs to.
Next
Read Core concepts. It is short, and it explains the conventions that trip up most integrations.