Architecture
The full sequence
Method map
Every real call this Business Case uses, and which Ishtaran module owns it:
| Step | SDK call | Module | Chapter |
|---|---|---|---|
| Sign up | auth.signUp(...) | OrganizationTenancy | Setup |
| Invite + claim | accounts.createAccountHolderInvitation, accountHolders.signUpAndClaimInvitation | Accounts | Seller onboarding |
| Authorize | accounts.authorizeApplication | Accounts | Seller onboarding |
| Workflow | workflows.create/createVersion/createRule/publishVersion, eventTypes.create | WorkflowRules | Creating an order |
| Order | transactions.create | Transactions | Creating an order |
| Payment | deposits.createPaymentIntent/getPaymentIntent | Deposits | Accepting payment |
| Simulated funding | sandbox.simulateDeposit/simulateConfirmation | Sandbox | Holding funds |
| Delivery event | events.ingest | WorkflowRules | Confirming delivery |
| Settlement | settlements.executeSettlement, signingRequests.get/submitSignedTransaction, sandbox.simulateBroadcastConfirmation | Settlement → ExecutionCustody → Ledger | Settlement and Split |
| Balance | ledger.getBalance | Ledger | Seller balance |
| Withdrawal | withdrawals.createDestination/quote/request | Withdrawals | Withdrawal |
Two real authorization rules worth knowing up front
- Some calls need Mercatto's Member session, not its API Key.
accounts.authorizeApplication, everyworkflows.*mutation, andevents.ingestall reject an Application API Key today (confirmed live). Mercatto's examples keep two clients around —owner(Member) andmercatto(API Key) — for exactly this reason. See Known Limitations §F.9. - Bob and Alice's own logins are for identity only. Once they've claimed their invitation, their own session can't call Ledger, Settlement, or Withdrawals — those all require Mercatto's own credentials. Mercatto reads Bob's balance and requests his withdrawal on his behalf, the same way a real marketplace backend would. See Known Limitations §F.10.