.png)
Mollie Integration Guide
Integrate Mollie with enterprise systems through its REST API, payment webhooks, bearer authentication, and scheduled reconciliation workflows.
Mollie integration options at a glance
Mollie’s primary integration model is a versioned REST API over HTTPS for Payments, Customers, Mandates, Subscriptions, Orders, Refunds, Profiles, Settlements, Balances, and related resources. Mollie also supports webhook-style callbacks, particularly for Payment status changes. Martini can consume these APIs, receive callbacks through a Martini API or workflow trigger, and map Mollie JSON into commerce, ERP, CRM, billing, or internal database schemas. API keys support account-level integrations, while OAuth 2.0 supports delegated access to Mollie organizations. Scheduled workflows can paginate through resources and reconcile missed notifications; a general Mollie bulk API, file exchange interface, GraphQL API, or SOAP API was not confirmed.
Common Mollie integration patterns
Common Mollie data objects used in integrations
Authentication and security considerations
Bearer authentication
Mollie supports bearer authentication with test and live API keys. Martini should store these credentials in secrets and keep test and live configuration isolated.
OAuth 2.0
OAuth 2.0 is available when an application accesses Mollie organizations on behalf of users or merchants. Martini should protect client credentials, access tokens, and refresh tokens and request only the scopes required by the integration.
Webhook protection
A Mollie callback indicates that a resource may have changed; it does not by itself prove payment success. The receiving workflow should retrieve the current Mollie resource and evaluate its status before making business decisions.
Sensitive data
Payment identifiers, customer information, metadata, credentials, and webhook payloads should be protected and excluded from unnecessary workflow logs or error messages.
Operational considerations for Mollie integrations
Pagination and checkpoints
Collection workflows should follow Mollie pagination links and persist progress so an interruption does not require a full restart.
Rate limits and retries
Throttle requests according to Mollie responses and documented limits. Use timeouts, bounded retries, and backoff for transient failures and rate-limit responses.
Idempotency
Webhook processing and payment, order, or refund writes should use Mollie identifiers and internal business keys to prevent duplicate business actions.
Payment states
Model payment states explicitly rather than reducing them to a simple success or failure flag. Apply the status rules required by the downstream order, fulfillment, or accounting process.
Financial values
Preserve amount and currency as structured values and use decimal-safe processing when mapping to financial systems.
Testing and change management
Keep test and live credentials, webhook URLs, downstream endpoints, and monitoring configuration separate. Mappings should tolerate additive fields, validate required fields, and be reviewed when Mollie resource representations evolve.
Why use Martini instead of scripts or point-to-point integrations?
Orchestrated workflows
Martini coordinates Mollie API calls, webhook receipt, downstream writes, scheduled reconciliation, validation, and exception paths in a maintainable workflow rather than scattering logic across scripts.
Reusable APIs
Martini can expose controlled APIs for payment creation, refund requests, or other Mollie operations so multiple applications use consistent authentication, validation, and business rules.
Consistent transformation
Mappings and transformations convert Mollie JSON, payment statuses, and monetary values into stable canonical and target-system contracts.
Operational resilience
Retries, checkpoints, idempotency, monitoring, and reconciliation help address duplicate callbacks, asynchronous payment completion, rate limits, and missed notifications.
Environment control
Secrets and environment configuration keep Mollie test and live credentials, webhook endpoints, and downstream connections isolated without embedding sensitive values in application code.