Vendor integration & provisioning

Connect your own product once and every partner can provision customers into it. A partner grants credits, units, a plan, a feature, or something custom; your product receives a signed, typed, idempotent request and reports usage and subscription state back. Configure it all from one manifest — or let your coding agent do it over the integration MCP server.

partnerswatch.com/admin/integrations/provisions
Integrations /Provisioning
N
DeliveriesConnectionsPolicyManifest
Delivered · 24h
1,28499.6%
Retrying
3
Blocked by policy
1
EnvEventAccountStatus
liveaccount.createdKeystone · plan pro200
livecredits.grantedVertex Labs · 5,000200
testplan.changedSandbox Co · growth200
livefeature.changedMeridian · sso onretrying
liveunits.grantedAcme · 40 seats409 policy
testaccount.suspendedSandbox Co200
signature: t=1727712000,v1=9f2c…e41a · HMAC-SHA256(timestamp.body)
The problem

Reselling stops at the edge of your product

A partner closes a customer, then emails your team to set the account up. Credits are granted by hand, plan changes live in a spreadsheet, and nobody hears what renewed or churned afterwards. Every integration is a one-off script nobody wants to own — and testing it means risking real partners and real money.

How it works

The flow, end to end

01

Connect

Submit a manifest — or add the product in the console — with a delivery endpoint per environment.

02

Rehearse

Run the self-test through your test connection and clear every readiness blocker.

03

Provision

A partner provisions a customer; your endpoint gets a signed request and answers 2xx.

04

Report back

Your product pushes usage and subscription state, so partners see what renewed — and what didn't.

Capabilities

What's in the box

✓

Five provision kinds

Credits, units, plan, feature, or custom — one rail for anything a partner can hand a customer.

✓

Signed & typed

Every request is HMAC-signed with a rotatable secret and carries a stable event name and payload version.

✓

Provision policy

Cap what partners can hand out per product: allowed kinds, a max quantity, catalogue plans only.

✓

Return rails

Your product reports usage and subscription state back — renewals, churn, plan changes — idempotently.

✓

Integration manifest

Endpoints per environment, auth, plan-code mapping, and webhooks from one document. Each resubmission can be diffed against the last, so upgrades are reviewable.

✓

Integration MCP server

Your coding agent wires the integration itself: scoped tools, readiness reports, a self-test, and guided plays.

✓

Live & test environments

Credentials are born live or test. Test traffic reaches your staging endpoint and never touches commissions or payouts.

✓

Partner sync

A reselling partner is set up on your product — brand, admin, domain — before their first customer exists.

A contract you can build against

Signed, idempotent, versioned — retries are always safe

Each delivery carries a timestamp and an HMAC signature over the raw body, with both signatures sent during a secret rotation so nothing breaks mid-swap. A stable event name says what happened, a kind says what's handed over, and a reference makes every retry a no-op. Policy refusals happen before any wallet debit or delivery attempt.

  • ✓account.created, plan.changed, credits.granted, feature.changed, and more
  • ✓The vendor's response is kept on every delivery for debugging
  • ✓Payload versions only change on purpose — connections keep the one they declared
partnerswatch.com/admin/integrations/provisions
Integrations /Provisioning
N
DeliveriesConnectionsPolicyManifest
Delivered · 24h
1,28499.6%
Retrying
3
Blocked by policy
1
EnvEventAccountStatus
liveaccount.createdKeystone · plan pro200
livecredits.grantedVertex Labs · 5,000200
testplan.changedSandbox Co · growth200
livefeature.changedMeridian · sso onretrying
liveunits.grantedAcme · 40 seats409 policy
testaccount.suspendedSandbox Co200
signature: t=1727712000,v1=9f2c…e41a · HMAC-SHA256(timestamp.body)
Built for coding agents

Hand the integration to an agent, and watch the readiness report go green

The integration MCP server gives a vendor's coding agent everything it needs: the integration guide, connections, webhooks, plan mapping, provision policy, and readiness reports that list every blocker with the one action that clears it. Guided plays walk the agent from integrate to verify, launch, and troubleshoot. What a key can do is decided by its scopes and its environment.

  • ✓Dozens of scoped tools and four guided plays
  • ✓A rehearsal that runs as a test actor — never live, never debits credits
  • ✓Test keys change only test configuration; live keys can do both
partnerswatch.com/admin/integrations/provisions
Integrations /Provisioning
N
DeliveriesConnectionsPolicyManifest
Delivered · 24h
1,28499.6%
Retrying
3
Blocked by policy
1
EnvEventAccountStatus
liveaccount.createdKeystone · plan pro200
livecredits.grantedVertex Labs · 5,000200
testplan.changedSandbox Co · growth200
livefeature.changedMeridian · sso onretrying
liveunits.grantedAcme · 40 seats409 policy
testaccount.suspendedSandbox Co200
signature: t=1727712000,v1=9f2c…e41a · HMAC-SHA256(timestamp.body)
5
provision kinds on one rail
2
environments per product: live and test
4
guided plays for coding agents
0
test rows that reach a payout

Ready to run your partner program in one place?

Book a walkthrough and see recruitment, PRM, automation, payouts, CX, and dashboards working together — on one platform.