Paystone
Paystone is a Canadian payment processing and customer-engagement company headquartered in London, Ontario, positioning itself as one of the country's largest bank-independent payment processors. It sells card-present terminals, online checkout and hosted payment pages, virtual terminals, invoicing, and recurring billing to Canadian small and mid-sized businesses, and layers loyalty, gift-card, and reputation-marketing products on top of the payment rails. Paystone owns DataCandy, a long-standing Canadian gift-card and loyalty platform, and it is DataCandy that carries Paystone's public, self-serve, documented API surface: a live API Platform (Hydra/JSON-LD) REST API at api.paystone.com covering merchants, clients, contacts, gift/loyalty/ prepaid/promo account types, transactions, member and balance portals, and webhooks, authenticated with JWT bearer tokens and documented through an interactive Swagger UI. Paystone's core card-acquiring and payment-gateway processing is delivered as a merchant product rather than a publicly self-serve developer API, so the honest developer story here is the DataCandy gift-and-loyalty platform API, not a public payments/acquiring API.
Paystone publishes 1 API on the APIs.io network: DataCandy API. Tagged areas include Payments, Canada, Payment Processing, Acquiring, and Gift Cards.
The Paystone catalog on APIs.io includes 1 event-driven AsyncAPI specification.
Paystone’s developer surface includes authentication, documentation, API reference, pricing, engineering blog, signup flow, and 20 more developer resources.
Kin Score
APIs 1
Individual APIs this provider publishes, each with its own machine-readable definition.
Paystone DataCandy API
The public, documented REST API for Paystone's DataCandy gift-card and loyalty platform, built on API Platform (Hydra/JSON-LD) and served from api.paystone.com. It exposes 28 do...
MCP Servers 1
Model Context Protocol servers that expose these APIs to AI agents.
paystone-mcp.yml
MCP SERVEREvent Specifications 1
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Paystone Datacandy Webhooks
ASYNCAPISecurity Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 3
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 4
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 6
Pagination, idempotency, versioning, errors, and events
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Operate 2
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 1
Properties that don't map to a standard resource type