Pennylane

Service ID: pennylane

French all-in-one accounting platform for SMEs and accounting firms

At a Glance

Difficulty
MODERATEPartner-Issued Credentials Required — OAuth apps are provisioned manually by Pennylane's Partnerships team (no self-service portal); otherwise a standard OAuth authorization-code connect.
Authentication
OAuth 2.0OAuth 2.0 (Authorization Code).
Webhooks
Virtual webhooks (polling-based change detection) for customer, supplier, invoice, invoice-item, and bill events — created and updated, 10 events across 5 resources. Pennylane's native webhooks are not used.
Partnership Required
Yes(OAuth Client ID and Secret are issued by Pennylane's Partnerships team after manual validation (no fee). The Client Secret is shown only once and cannot be retrieved again — store it immediately, or create a new OAuth app if it is lost. There is no self-service developer portal (developer.pennylane.com does not exist); request credentials via the partnership form.)
Partnership Application
Developer Portal
Apideck Credentials
Not available(Not available — consumers supply their own partnership-issued OAuth credentials in every environment.)
Costs
No partnership or API fees; consumers need an active Pennylane subscription.
Sandbox Availability
Available(Provisioned by the Pennylane Partnerships team on request as part of the partnership process — there is no self-service sandbox. Same rate limits as production.)
Account Type Required
Active Pennylane account (app.pennylane.com) with at least one company set up.
Consumer Access Level
A user with permission to authorize third-party (OAuth) apps for the company.
Rate Limits
25 requests per 5 seconds per token (production and sandbox).

Responsibility matrix

TaskYou (Customer)Your ConsumerApideck
Apply for Partnership / OAuth CredentialsDocs provided
Request Sandbox
Add Credentials to Apideck
Authorize Connection (OAuth)Handles OAuth flow
Build via Unified APIMaintains connector
Token Refresh✓ Automatic
Monitor Connections✓ Via Dashboard✓ Can revoke anytimeLogs & alerts

Environments

Sandbox
Development and testing. OAuth credentials are issued by the Pennylane Partnerships team and requested during the partnership process. Same rate limits as production (25 requests per 5 seconds per token).
Production
Live consumer data. Production OAuth credentials are issued by the Partnerships team after approval.
Both
Sandbox and production are separate Pennylane accounts with different credentials. Test against the sandbox account before pointing your OAuth app at production data — development credentials cannot be used with production accounts.

🚨Important to Know About Pennylane

  • There is no stated turnaround for OAuth credential issuance, so provisioning can gate your go-live — budget an unpredictable lead time rather than assuming instant self-service access.
  • Pennylane is available in France and Germany only — consumers based in other countries will not have a Pennylane account to connect, so confirm geographic fit before committing.
  • Access tokens last 24 hours and refresh tokens are valid for 90 days, rotating on every refresh; both are refreshed automatically by Apideck, but a connection left dormant beyond 90 days must be re-authorized by the consumer.
  • The partner onboarding journey is French-first — the partnership request form and parts of Pennylane's documentation are in French.
⚠️

16 gotchas across 15 resources

Connector-specific behaviors and limitations to be aware of

📦

15 supported resources

View field mappings, supported operations, and schema details