Skip to content

Developer API

Manage Eza Cloud from your code

Use the Eza Cloud REST API to manage organisations, projects, apps, deployments, databases, domains, environment variables and PayEdge configurations.

  • REST API
  • JSON responses
  • API keys
  • Webhooks
api-status
API statussupported actions availableendpoint reference publishes as contracts ship
API availability

Built around supported Eza actions

The Eza Cloud REST API is available for supported dashboard and CLI actions. Endpoint-level reference pages will be published as each contract is tested and released.

API resources

Resources available through the API

Reference material is released resource by resource, with implementation details that match the production contract.

Organisations

Manage organisation settings, billing contacts and team members.

Projects

Group apps by client, product or environment.

Apps

Create apps, configure Git deployment and manage runtime settings.

Deployments

Start deploys, inspect state, read logs and roll back to an earlier deploy.

Databases

Create managed databases and retrieve connection details.

Domains

Add custom domains and check verification or certificate status.

Environment variables

Add runtime or build-time configuration without placing secrets in Git.

Object storage

Manage S3-compatible buckets and access keys.

PayEdge

Create configurations, initiate STK pushes, check payment status and manage webhooks.

Authentication

Authenticate with an API key

Create an API key in your Eza Cloud organisation settings. API authentication details, including the header format and key permissions, are published with each production endpoint.

Keep API keys out of source control. Store them in encrypted environment variables.

Webhooks

Receive events when Eza state changes

Use webhooks when your system needs to react to Eza events without polling the API. Event names, delivery guarantees and retry behaviour are documented with each released event.

Verify PayEdge webhooks

PayEdge uses the Eza-Signature header. Verify the signature with HMAC-SHA256 and the webhook signing secret. Reject timestamps older than five minutes.

HTTP header
Eza-Signature: t=<timestamp>,v1=<signature>
Read PayEdge webhook verification

OpenAPI

Use the OpenAPI definition

A versioned OpenAPI definition will be published when it matches production endpoints, request fields and response objects.

Not published yet

Need help with the API

Start with the API availability notes and published endpoint references. For API support, email support@eza.co.ke. For security reports, email security@eza.co.ke.