Welcome back
Get started
Recent requests
View allNo requests yet. Send one from the Playground.
Updates
Keys your services use to call the Cloudfloat API. Treat them like passwords.
Your account isn't linked to a platform yet. Ask your Cloudfloat contact to enable API access.
Key created
Copy it now — for your security it won't be shown again.
Requests are sent with this key instead of the temporary one. Clear it to switch back.
Nothing to paste: requests are signed with a temporary key issued to your sign-in. It expires after an hour and is reissued automatically, and it never appears in your key list.
The ABNs you quote for, with your own names, tags and buyer contacts. The Playground suggests them for any ABN field. Nothing here is checked against a business register.
Totals cover the last 30 days; recent calls appear as they happen.
Recent requests
Where Cloudfloat sends transaction.* events, and every one we sent.
Endpoint
Signing secret created
Copy it into your receiver now: it won't be shown again. To get a new one later, roll the secret.
The current secret stops working immediately: every webhook after this is signed with the new one, so update your receiver straight away.
A public HTTPS address on port 443. After saving, send a test event to check your endpoint receives it.
Checking a webhook's signature
Every webhook carries X-Cloudfloat-Timestamp and
X-Cloudfloat-Signature. Recompute the signature over the raw body with
your signing secret, compare it in constant time, and reject anything that doesn't
match:
expected = "sha256=" + HMAC_SHA256(signing_secret,
timestamp + "." + raw_body).hex()
Deliveries
transaction.* event we send your endpoint shows up here, grouped by quote.Test data this environment understands. Run a quote end to end — scoring, checkout, payout and webhooks — without asking anyone to set up a business.
Synthetic buyer ABNs
A made-up ABN that picks its own credit outcome: GOOD passes, BAD is declined. The real ABR and CreditorWatch aren't asked: for this pattern the environment answers with a test business profile and a credit grade, and Cloudfloat's normal scoring turns that into the outcome you chose — about a minute after the quote is created.
CCcheck digits
999test marker
T0 bad · 1–9 good
RRRRRrandom
Your test buyers
Manage in BusinessesRules worth knowing
- Reuse your saved test buyers. Every new ABN becomes one more test business on this environment — a business record, a credit assessment and a limit — so start from the ones you've saved. A buyer gives the same outcome every time.
- A reused buyer keeps its owner. Whoever first completes checkout on an ABN owns that business, exactly as in production; pay again on it as the same email. Take a new ABN only when the scenario needs a buyer nobody has paid for yet, such as a first-time guest.
- Buyers only. The pattern stands in for the business being assessed. The supplier ABN can be anything; see the auto-payout supplier below for one that pays out by itself.
- Not in production. Production has no stub and treats these as unknown ABNs.
Generate your own anywhere — the check digits follow the standard ABN rule:
W = [10, 1, 3, 5, 7, 9, 11, 13, 15, 17, 19]
def abn_valid(abn):
d = [int(c) for c in abn]; d[0] -= 1
return len(abn) == 11 and sum(w * x for w, x in zip(W, d)) % 89 == 0
def synth(good, rnd):
t = rnd.randint(1, 9) if good else 0
tail = f"999{t}{rnd.randrange(100000):05d}"
return next(a for cc in range(10, 100) if abn_valid(a := f"{cc:02d}{tail}"))
Auto-payout supplier
Name this business as the Supplier ABN and the money goes all the way to the supplier without anyone at Cloudfloat approving it — so a single test quote produces every webhook you'll receive in production. Watch them arrive on the Webhooks page.
People who can use this organisation's portal. API keys belong to the organisation, so they keep working when someone leaves.