PayFit Create

PayFit Create

Certified

Initialize a PayFit contract

Calls POST /companies/{companyId}/collaborators/{collaboratorId}/contracts. Currently available for French companies only. PayFit returns 201 with an empty body, and the contract can take 2 to 5 minutes before it can be read. The contract is not finalized until an administrator completes it in PayFit. Requires the collaborators: contracts: write scope.

yaml
type: io.kestra.plugin.payfit.contracts.Create

Initialize a contract for a new collaborator

yaml
id: payfit_create_contract
namespace: company.team

tasks:
  - id: contract
    type: io.kestra.plugin.payfit.contracts.Create
    apiKey: "{{ secret('PAYFIT_API_KEY') }}"
    collaboratorId: "{{ outputs.create.id }}"
    jobTitle: "Software Engineer"
    startDate: "2026-01-06"
Properties

API key

PayFit API key or OAuth access token, sent as a bearer token. Create a customer key in the PayFit app under Integrations > API Access, or use the access token returned by auth.AccessToken. Store this value in a Kestra secret.

Collaborator id returned by collaborators.Create

Job title

Contract start date, as YYYY-MM-DD

Defaulthttps://partner-api.payfit.com

Partner API base URL

Base URL of the PayFit Partner API. Defaults to https://partner-api.payfit.com.

Company ID

PayFit company identifier used in /companies/{companyId} paths. When omitted, the task calls POST https://oauth.payfit.com/introspect and uses company_id from the token.

Defaulthttps://oauth.payfit.com

OAuth base URL

Base URL used for token introspection and authorization-code exchange. Defaults to https://oauth.payfit.com.

HTTP client options

Optional HTTP client configuration applied to PayFit requests.

Definitions
allowFailedbooleanstring
Defaultfalse

If true, allow a failed response code (response code >= 400)

allowedResponseCodesarray
SubTypeinteger

List of response code allowed for this request

auth

The authentication to use.

type*object
passwordstring

The password for HTTP basic authentication.

usernamestring

The username for HTTP basic authentication.

type*object
tokenstring

The token for bearer token authentication.

type*object
passwordstring

The password for HTTP Digest authentication.

usernamestring

The username for HTTP Digest authentication.

defaultCharsetstring
DefaultUTF-8

The default charset for the request.

enabledTcpExtendedKeepAlivebooleanstring
Defaulttrue

Whether to enable TCP Keep-Alive extended socket options (TCP_KEEPIDLE, TCP_KEEPINTERVAL, TCP_KEEPCOUNT).

Set to false when running on Windows workers, as these extended socket options are not supported by the Windows JDK and will cause connection failures.

followRedirectsbooleanstring
Defaulttrue

Whether redirects should be followed automatically.

logsarray
SubTypestring
Possible Values
REQUEST_HEADERSREQUEST_BODYRESPONSE_HEADERSRESPONSE_BODY

The enabled log.

proxy

The proxy configuration.

addressstring

The address of the proxy server.

passwordstring

The password for proxy authentication.

portintegerstring

The port of the proxy server.

typestring
DefaultDIRECT
Possible Values
DIRECTHTTPSOCKS

The type of proxy to use.

usernamestring

The username for proxy authentication.

ssl

The SSL request options

insecureTrustAllCertificatesbooleanstring

Whether to disable checking of the remote SSL certificate.

Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.

timeout

The timeout configuration.

connectTimeoutstring

The time allowed to establish a connection to the server before failing.

readIdleTimeoutstring
DefaultPT5M

The time allowed for a read connection to remain idle before closing it.

Raw PayFit response

Created contract id when PayFit returns one. The current API returns an empty 201 body