Skip to main content

At a glance

  • Availability: Experimental (how to enable).
  • Authentication: OAuth 2.0 (client credentials).
  • Connection: Veryfront obtains machine-to-machine tokens from the client ID and secret in the project’s environment variables.
  • Provider documentation: Authentication reference.

Credentials

Set these per environment. See Connect an integration.

Setup

  1. Create an API key: As a Moss admin, go to Settings > Platform > API Keys in the Moss app and create a key. You receive a Key ID (kid_…) and a Secret Key (sk_…). Only admins can create API keys.
  2. Set environment variables: Set MOSS_CLIENT_ID to the Key ID and MOSS_CLIENT_SECRET to the Secret Key.
  3. Verify access: Run List Bank Accounts or List Expenses. Access tokens are minted automatically via the OAuth2 client_credentials grant at https://public-api.getmoss.com/oauth2/token (valid for 1 hour, scope ‘read’).

Provider notes

  • This connector requests the ‘read’ scope only; Moss write endpoints (creating suppliers, dimensions, or dimension items) require scope ‘write’ and are not included.
  • Rate limits: 180 read requests/minute and 20 write requests/minute per company.
  • The Search Bank Transactions and Search Receipt Files tools use POST search-query endpoints but are read-only.
Provider API reference.

Tools

Verify the connection

Call a read tool such as moss__list_expenses with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.