Reference REST API dazo-whitelist-api — Meta Marketing API engine Konco. Endpoint ini dipanggil oleh dazo-whitelist (web app) via wrapper App\Src\MyApi / FacebookApi dengan authentication multi-lapis.
Dokumentasi interaktif OpenAPI/Scramble dapat diakses di browser:
http://127.0.0.1:8081/docs/api(local)
Base URL
http://127.0.0.1:8081/apiAuthentication
Setiap endpoint (kecuali yang “Publik”) memakai dua lapis middleware:
| Layer | Middleware | Validasi |
|---|---|---|
| Passport | auth:api | Validasi Authorization: Bearer {token} — token didapat dari handshake |
| Public key | myapi | Validasi header public-key == auth()->user()->public_key |
Dapatkan token (handshake)
curl -X POST "http://127.0.0.1:8081/api/application/token" \
-H "x-client-key: <UUID aplikasi>" \
-H "x-timestamp: 2026-08-21T10:26:52+07:00" \
-H "x-signature: <base64 RSA SHA-256 signature>"Response:
{ "data": { "access_token": "eyJ0eXAiOi..." } }Lihat Authentication & Token dan RSA Handshake deep-dive.
Request normal (setelah handshake)
curl "http://127.0.0.1:8081/api/facebook/businesses" \
-H "Authorization: Bearer <token>" \
-H "public-key: <public_key.pem content>" \
-H "Accept: application/json"Grouping endpoint
| Grup | Endpoint | Middleware | Halaman |
|---|---|---|---|
| Authentication & Token | /api/application/* | Publik + auth:api,myapi (exchange) | application-token |
| Facebook OAuth & BM | /api/facebook/* | auth:api,myapi / Publik | facebook-oauth-bm |
| Marketing Operations | /api/facebook/ad-accounts/*/campaigns, */adsets, */ads | auth:api,myapi | marketing-operations |
| Account & Spend Cap | /api/account/* | auth:api,myapi | spend-cap-balance |
| Transfer Balance | /api/transfer-balance/* | auth:api,myapi | transfer-balance |
Metode HTTP
| Method | Penggunaan |
|---|---|
GET | List/single data |
POST | Create / action / mutation |
DELETE | Hapus/disconnect |
Response envelope
Response API engine mengikuti pola konsisten:
{
"status": true,
"message": "Berhasil",
"data": { }
}Pada error:
{
"status": false,
"message": "Pesan error"
}Status code
| Status | Arti |
|---|---|
200 | Sukses |
400 | Validasi gagal / signature timestamp invalid |
401 | Unauthorized / public-key mismatch / token expired |
404 | App invalid / signature invalid |
500 | Internal error / Meta Graph error |
Error umum
| Pesan | Penyebab |
|---|---|
Invalid Timestamp | Timestamp di luar ±10 menit |
Invalid Signature | RSA signature tidak cocok payload |
Invalid app | x-client-key tidak dikenal / public_key kosong |
Invalid Public Key | Header public-key mismatch (middleware myapi) |
401 Unauthorized | Bearer token invalid/expired |
Graph returned an error: (#17) User request limit reached | Meta rate limit |
Sub-halaman API
- Authentication & Token — handshake RSA, token exchange, info aplikasi
- Facebook OAuth & BM — OAuth URL, accounts, business managers, import, ad accounts
- Marketing Operations — campaigns, adsets, ads, status, budget, insight
- Spend Cap & Balance — balance, topup, withdraw, refund, spendcap, sync
- Transfer Balance — transfer saldo antar-akun
Langkah berikutnya
- Pahami dulu RSA Handshake sebelum memanggil endpoint.
- Baru mengenal API? Baca Authentication & Token.