> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentaos.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List businesses

> Every business you manage, with its status and your share. Not paginated: returns a plain array. The platform is always the caller's own account; an owner or admin of it.

<Info>
  Every field on this resource is camelCase on the wire. See [Naming convention](/api-reference/introduction#naming-convention).
</Info>

<Note>
  Returns a plain array, not the paginated envelope. These are the businesses **you** manage as a platform. To act as one of them on any other endpoint, send its `id` in the [`AgentaOS-Account` header](/api-reference/introduction#acting-for-a-business).
</Note>

<Columns cols={2}>
  <Card title="Platforms" icon="building" href="/connect/overview">
    What a platform is, and who does what.
  </Card>

  <Card title="SDK: businesses.list()" icon="code" href="/sdk/pay-businesses">
    The same call from TypeScript.
  </Card>
</Columns>


## OpenAPI

````yaml GET /gateway/businesses
openapi: 3.1.0
info:
  title: AgentaOS Gateway API
  version: 1.0.0
  description: >-
    The AgentaOS REST API: payment links, checkouts, subscriptions, customers,
    invoices, and the unified transactions feed. This is the same API the
    TypeScript SDK (`@agentaos/pay`) and the `agenta` CLI call underneath.


    ## Money model


    - **Decimal currency units (`number`)**: a plain `amount` field (on a create
    body, a Payment Link, a Checkout's `amount_override`, or an Invoice's
    `amount`/`fiat_amount`/`tax_amount`) is in currency units. `49.99` means EUR
    49.99, never cents.

    - **Integer minor units (`number`)**: exactly one field breaks that rule:
    `unitAmountMinor` on a Subscription. It is an integer count of the smallest
    currency unit (`1999` means EUR 19.99), named with a `Minor` suffix
    specifically so it is never confused with a plain `amount`. The `money`
    object on Transactions and the `earnings` object on a retrieved Invoice are
    also integer minor units, computed server-side.

    - **String, on webhooks**: the `amount` inside a webhook payload's `data`
    object is a string (e.g. `"49.99"`), since JSON numbers silently drop
    trailing zeros and this value must round-trip exactly for accounting.


    ## Naming convention


    Most response fields mirror the underlying database column and are
    `snake_case` (`created_at`, `seller_mode`, `buyer_email`, ...). A small
    number of computed convenience fields are camelCase with no snake_case
    equivalent: `checkoutUrl` on Checkouts and Payment Links, `sellerMode` on
    Payment Links specifically, `money` on Transactions, and `earnings` on a
    single retrieved Invoice. Two resources (Subscriptions and Customers) are
    fully camelCase end to end.


    ## Pagination


    Every list endpoint takes `limit` and `offset` and returns `{ items, total,
    hasMore }`. `hasMore` is computed server-side (`offset + items.length <
    total`); never derive it client-side.
  contact:
    name: AgentaOS
    url: https://agentaos.ai
  license:
    name: Proprietary
    url: https://agentaos.ai
servers:
  - url: https://api.agentaos.ai/api/v1
    description: Production
security:
  - ApiKeyAuth: []
tags:
  - name: Payment Links
    description: >-
      Reusable, shareable payment products: a fixed amount and description
      behind one URL.
  - name: Checkouts
    description: >-
      One attempt to collect one payment, standalone or built from a payment
      link. Wire path is `/gateway/sessions`; the SDK and CLI call this resource
      "checkout".
  - name: Subscriptions
    description: >-
      Merchant-side read and management surface for recurring plans. Created
      automatically when a buyer pays a `type: subscription` payment link.
  - name: Customers
    description: 'Read-only surface: everyone who has paid you or been sent an invoice.'
  - name: Invoices
    description: >-
      Every checkout issues an invoice. List, retrieve, void, export, and
      download PDFs/receipts.
  - name: Transactions
    description: >-
      The unified activity feed: every inbound payment and outbound send, across
      every rail, in one list.
  - name: Businesses
    description: >-
      For platforms: the businesses you manage, a client's business or another
      app of your own company. To act as one of them on any other endpoint, send
      its id in the `AgentaOS-Account` header. Every field on this resource is
      camelCase on the wire.
paths:
  /gateway/businesses:
    get:
      tags:
        - Businesses
      summary: List businesses
      description: >-
        Every business you manage, with its status and your share. Not
        paginated: returns a plain array. The platform is always the caller's
        own account; an owner or admin of it.
      operationId: listBusinesses
      responses:
        '200':
          description: Every business you manage.
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/Business'
              examples:
                default:
                  $ref: '#/components/examples/BusinessListExample'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/BusinessForbidden'
components:
  schemas:
    Business:
      type: object
      description: >-
        A business you manage: a client's business, or another app of your own
        company. Every field is camelCase on the wire.
      properties:
        id:
          type: string
          format: uuid
          description: Business UUID. Send it in `AgentaOS-Account` to act as the business.
        name:
          type: string
          description: The name buyers see.
        country:
          type:
            - string
            - 'null'
          description: ISO 3166-1 alpha-2.
        status:
          type: string
          enum:
            - test_only
            - in_review
            - changes_needed
            - on_hold
            - rejected
            - live
          description: >-
            Where the business stands. `live` = verified and with a payout
            account. `changes_needed` = we asked the business for a change.
        platformOrgId:
          type: string
          format: uuid
          description: 'Your own id: the platform that manages it.'
        createdAt:
          type: string
          format: date-time
        platformFee:
          type: object
          description: >-
            Your share of its new sales, set in the dashboard: basis points of
            the price before VAT (`1000` = 10%) plus a fixed amount in minor
            units.
          properties:
            bps:
              type: integer
            fixedMinor:
              type: integer
          required:
            - bps
            - fixedMinor
        sameLegalEntity:
          type: boolean
          description: >-
            `true` for another app of your own company: verified and priced with
            you, no share, no identity check of its own.
        feesThisMonth:
          type: array
          description: >-
            Your share of its live sales this month, per currency. `feesDisplay`
            is ready to show.
          items:
            type: object
            properties:
              currency:
                type: string
              feesMinor:
                type: integer
              feesDisplay:
                type: string
            required:
              - currency
              - feesMinor
              - feesDisplay
        invitedEmail:
          type:
            - string
            - 'null'
          description: Who an open invitation is waiting on, or null.
        identityVerified:
          type: boolean
          description: >-
            The identity check is done: its own, or your company's for another
            app of your own company.
      required:
        - id
        - name
        - country
        - status
        - platformOrgId
        - createdAt
        - platformFee
        - sameLegalEntity
        - feesThisMonth
        - invitedEmail
        - identityVerified
    Error:
      type: object
      description: >-
        Every non-2xx response is JSON in this shape. Every response (success or
        error) also carries an `x-request-id` response header; send that header
        on your request to have your own id echoed back, otherwise the server
        mints one. On errors the same id is repeated in the `requestId` body
        field.
      properties:
        statusCode:
          type: integer
          description: Same as the HTTP status code.
        code:
          type: string
          description: >-
            Present on some refusals: a stable machine-readable reason, e.g.
            `live_key_required`.
        message:
          description: >-
            Human-readable. A validation failure (400) returns an array of
            per-field messages instead of one string.
          anyOf:
            - type: string
            - type: array
              items:
                type: string
        errors:
          type: array
          description: >-
            Present on 400 validation failures: one entry per invalid field. The
            flat human-readable strings stay in `message` for back-compat; this
            is the machine-readable, per-field view.
          items:
            type: object
            properties:
              field:
                type: string
                description: >-
                  Name of the invalid field, dot-notated for nested properties
                  (e.g. `checkoutFields.0.type`).
              message:
                type: string
                description: Validation messages for that field, joined with `, `.
            required:
              - field
              - message
        requestId:
          type: string
          description: >-
            Correlation id, identical to the `x-request-id` response header.
            Include it when contacting support. On success it is available on
            the header only, not the body.
        timestamp:
          type: string
          format: date-time
      required:
        - statusCode
        - message
        - timestamp
  examples:
    BusinessListExample:
      value:
        - id: 5b1f0c2e-8a4d-4c7b-9e21-3f6a7d8c9b10
          name: ClientCo
          country: DE
          status: in_review
          platformOrgId: 0e6d2c1a-3b4f-4a5e-8c7d-9f1a2b3c4d5e
          createdAt: '2026-09-28T10:00:00.000Z'
          platformFee:
            bps: 1000
            fixedMinor: 50
          sameLegalEntity: false
          feesThisMonth:
            - currency: EUR
              feesMinor: 1250
              feesDisplay: €12.50
          invitedEmail: founder@example.com
          identityVerified: false
  responses:
    Unauthorized:
      description: Missing or invalid `x-api-key`.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            statusCode: 401
            message: Invalid API key
            timestamp: '2026-08-06T12:00:00.000Z'
    BusinessForbidden:
      description: >-
        A business you do not manage, or an id that does not exist: the same
        answer for both, so the response never confirms an id. Also returned
        when the caller is not an owner or admin of the platform.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            statusCode: 403
            message: You cannot act as this business.
            timestamp: '2026-09-28T12:00:00.000Z'
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Your secret key, from app.agentaos.ai -> Settings -> Developers -> API
        Keys. The key's prefix is both its identity and its environment:
        `sk_test_...` (sandbox, free, no verification) or `sk_live_...` (real
        money, requires business verification). A missing or invalid key returns
        401.

````