
API integration for Qonto
We build your Qonto connector
We link your product to the Qonto API to pull your transactions, reconcile your invoices and trigger your transfers with no manual entry.
- Senior product team
- banking integrations in production
- from scoping to monitoring
What does the Qonto API provide and why connect your business bank account to your software?
Qonto is an online business bank used by hundreds of thousands of French companies. Its API lets your application read accounts, transactions and supporting documents, and trigger transfers. You integrate it to automate bank reconciliation in an accounting tool, feed a real-time cash flow dashboard, or trigger an action in your software as soon as a client payment is received. Access can be limited to your own Qonto account or opened to your clients via OAuth if you are connecting accounts of multiple companies.
What our clients build on the Qonto API
Automatic bank reconciliation
Every payment received is matched to the right invoice in your tool. Your teams stop ticking off lines by hand at month end.
Real-time cash dashboard
Balances, inflows and outflows consolidated in your application, with a thirty or sixty day projection.
Payment chasing driven by the bank
As soon as the payment is detected, the dunning sequence stops. You no longer chase a customer who already paid.
Bank to accounting chain
Qonto operations feed Pennylane or your accounting software, receipts attached. One flow, two tools up to date.
What it changes in how you run the business
Engineering in service of a measurable outcome: less data entry, readable cash flow, a faster close.
No more double entry
Banking data lands in your tools on its own. The time spent copying statements leaves your teams' schedules.
Cash flow you can see coming
Your balances and incoming payments are always current, not fifteen days late. You decide on today's numbers.
Fewer errors, fewer disputes
Automatic reconciliation removes data entry gaps and reminders sent by mistake, whose real cost is the customer relationship.
A shorter close
Receipts are already attached when the accountant arrives. Month-end back and forth shrinks noticeably.
How we ship your Qonto connector
Scoping
Which flows, what volume, what frequency, which authentication mode. We list the edge cases before writing a line of code.
Development
Typed connector, rate limit handling, retry queue, isolated secrets. A demo every week.
Acceptance testing
Replay of your real data, gap checks down to the cent, and testing the API failure scenarios.
Monitoring
Alerts on sync failures, a call log, a connector health dashboard. You know a flow is broken before your customers do.
What the Qonto API allows
- Accounts and balances
- Reading the organisation's bank accounts, with authorised and book balances kept separate. The basis of any cash dashboard.
- Transactions and attachments
- Operation history, filterable by account, status and period. Every transaction carries its receipts, labels and cash flow category.
- Transfers and requests
- Creating single or bulk transfers, and requests submitted for approval. A transfer is always confirmed by a human with strong authentication.
- Webhooks and customer invoicing
- Real-time notification of new operations, plus handling of customer invoices, quotes and credit notes issued from Qonto.
The vocabulary of the Qonto API
- OAuth scope
- A named permission attached to a token (organization.read, payment.write, card.write). Qonto documents 29 of them: a clean integration asks only for the ones it needs, and that list is something you can hand to an IT director.
- transactions.created
- The transactions webhook event, emitted when an operation appears. It is what triggers reconciliation, instead of polling the API on a timer.
- Idempotency key
- The header that guarantees a replayed instruction does not create two transfers. The response is cached for 30 minutes: beyond that, a replay creates a new resource, so the retry queue needs a lock of its own.
- SCA
- Strong customer authentication, required by PSD2. Some operations (international transfer, trusted beneficiary, card limit) cannot be approved by a machine.
- Consent revocation
- The event emitted when a customer cuts the access granted to your application. Handling it beats discovering the outage through a run of authentication failures in production.
- QSealC
- The electronic seal certificate required if you act as a third-party provider under PSD2, with signed requests. Outside that case, an API key or OAuth is enough.
The real constraints of the Qonto API
Two authentication modes, two uses
The API key suits your own organisation. To reach your customers' accounts, you have to go through OAuth 2.0 and register your application with Qonto.
Rate limiting and pagination
The API applies rate limiting and paginates transaction lists. A historical sync is designed as batches with retry handling, not as a single request.
No transfer without human approval
The API creates transfers and requests, but final approval goes through the SCA of an authorised user. That is a regulatory constraint, not a flaw: build it into the flow from the design stage.
Banking data comes with a framework
Encryption at rest and in transit, access logging, secret compartmentalisation, a defined retention period. We set that framework during scoping, not after go-live.
Qonto API or bank aggregation?
Two ways to read accounts from your application. The right one depends on who holds the accounts, not on the technology.
| Criterion | Qonto APIDirect access | PSD2 aggregationBridge, Powens, Tink |
|---|---|---|
| Banks covered | Qonto accounts only | Most French banks |
| Depth of data | Labels, cash-flow categories, attached receipts | Description, amount, date, rarely the receipt |
| Outbound transfers | Yes, single and bulk | Varies by provider and by bank |
| Real time | Yes, signed webhooks | Periodic refresh |
| Access renewal | Token refreshed server-side | Consent to renew on a regular basis |
| Cost of access | Included in the Qonto plan | Subscription to the aggregation provider |
| The right case | All your accounts are at Qonto | Your users bank in different places |
The two combine: the Qonto API for your own accounts, aggregation for your customers'. It is a scoping trade-off, not a permanent choice.
What we measure on a Qonto integration
The other banking APIs
If your accounts are not all at Qonto, these options are worth discussing during scoping.
QontoWe build your Qonto connectorThis page
Revolut BusinessMulti-currency accounts and international payments, a similar API in spirit.We combine Qonto with
The stack that surrounds Qonto on our projects.
Qonto integration: your questions
Three steps: generate the credentials in your Qonto space (login and secret key, or an OAuth application if you connect third-party accounts), build a connector that reads accounts and transactions while handling pagination and rate limiting, then wire up the webhooks to receive new operations in real time rather than polling the API. The sensitive part is not the API call, it is the retry handling and matching the data to your business model.
A first useful flow, typically syncing transactions into a dashboard, ships in two to three weeks. A complete chain with reconciliation, receipts and transfers is closer to six to eight weeks depending on how complex your invoicing model is. We scope the perimeter up front and give you a firm estimate before we start.
Yes, the API lets you create single or bulk transfers, as well as transfer requests submitted for approval. Final approval, however, always requires the SCA of an authorised user: no automated process can move money on its own. So we design the flow around that human step.
Yes, and it is the most requested use case. We build the flow that pushes Qonto operations with their receipts into Pennylane or your accounting software, handling account mapping and the cases where figures diverge.
The Qonto API gives direct, rich access to your own Qonto accounts. An aggregation API such as Bridge or Powens covers several banks but with a thinner data perimeter and regular reconnections imposed by DSP2. If all your accounts are with Qonto, the Qonto API is the right choice. If your users bank in different places, you need aggregation.
A Qonto integration project?
Let's talk. 30 minutes to scope your need, check what the API actually allows and tell you honestly what is feasible.
Discuss my Qonto project