YoBridge

API & integrations

Connect your software to NSSA, ZIMRA and company records

YoBridge is API-first. Everything the web and mobile apps do — filing returns, registering employees, ordering FDMS devices, reading registers — is available to your ERP, payroll, accounting or POS system through one secure REST API.

  • ERP & payroll vendors
  • Accounting software
  • POS & fiscalisation partners
  • Banks & fintechs
  • In-house IT teams

Why integrate with YoBridge

NSSA and ZIMRA TaRMS have no public filing API for third-party software. Building and maintaining your own filing integration — for every client you serve — is slow, fragile and expensive.

YoBridge gives you one API instead. Your system sends a request; YoBridge files it as a durable, tracked transaction and tells you the result.

How other systems connect

Create an API key in the YoBridge Developer area, optionally restricted to specific companies, capabilities and IP addresses. Call the REST API with the key as a bearer token and an Idempotency-Key header, and YoBridge accepts the work immediately with a 202 response and a transaction you can poll.

Subscribe a webhook endpoint to receive signed events — completed, failed, awaiting OTP, low wallet balance, connections needing attention, compliance issues and FDMS order updates — so your system reacts without polling. YoERP already uses this API for NSSA P4, PAYE, VAT reconciliation and FDMS orders.

Built for production integrations

How it works

  1. 01

    Create an API key

    In the Developer area, create a test or live key with the scopes you need.

  2. 02

    Call a capability

    POST to a company capability with an Idempotency-Key.

  3. 03

    Track the transaction

    Poll the transaction or wait for a webhook event.

  4. 04

    Use the result

    Read structured results and download receipts and documents.

A request and a webhook

Start a capability run for a company with your API key, then receive the outcome by webhook. Every capability — from nssa.p4.upload to zimra.tarms.vat.submit — follows the same pattern.

Create a transaction
curl -X POST \
  https://api.yobridge.co.zw/api/v1/companies/{company_id}/capabilities/nssa.employee.list/transactions \
  -H "Authorization: Bearer yb_live_<prefix>_<secret>" \
  -H "Idempotency-Key: 2026-10-employee-sync" \
  -H "Content-Type: application/json" \
  -d '{ "payload": {} }'

# 202 Accepted
{
  "data": { "id": "0192…", "status": "queued", … },
  "meta": { "request_id": "…", "correlation_id": "…" }
}
Receive a signed webhook
POST https://your-system.example/webhooks/yobridge
X-YoBridge-Signature: <HMAC-SHA256 of timestamp + body>
X-YoBridge-Timestamp: 1791100800

{
  "event_id": "0192…",
  "delivery_id": "0192…",
  "event_type": "transaction.completed",
  "schema_version": 1,
  "occurred_at": "2026-10-05T09:00:00Z",
  "data": { "transaction_id": "0192…", "to_status": "completed" }
}

Pricing

API access is included in every plan, with request limits from 60 requests per minute on Starter to 2,000 on Enterprise. Capability runs are billed the same way as in the app — from your plan or pay-as-you-go wallet.

See plans and pay-as-you-go

Frequently asked questions

How do I get API access?

Sign up, open the Developer area in the YoBridge web app and create an API key. Test keys (yb_test_) let you build safely; live keys (yb_live_) run real portal work.

Is there an OpenAPI specification?

Yes. The YoBridge API is fully described in OpenAPI. Contact us or open the Developer area to get the latest specification.

How do I avoid duplicate submissions when my system retries?

Send an Idempotency-Key with every transaction request. Repeating the same key with the same request returns the original transaction; reusing a key with a different request returns HTTP 409.

How are webhooks secured?

Each delivery is signed with HMAC-SHA256 using your endpoint’s secret and includes a timestamp, event ID and delivery ID so you can verify authenticity and reject replays. Failed deliveries are retried with backoff and can be replayed manually.

Can I integrate on behalf of many client companies?

Yes. Software vendors and practices can manage many companies under one client account, and keys can be restricted to specific companies.

Is the API rate limited?

Yes. Limits depend on your plan, from 60 requests per minute on Starter up to 2,000 on Enterprise. Contact us if you need more.

Related solutions

Build on YoBridge

Sign up on the web or download the app. Choose a fixed monthly plan, top up your wallet and pay as you go only for the portal filings you run — or talk to us about a demo for your practice.

Get the YoBridge app