# Vayana (Vay Network Services Pvt. Ltd.) > India's trade credit infrastructure network and a GSTN-authorized GST Suvidha Provider (GSP, > code "vay"). Founded 2016, headquartered in Pune. Three distinct developer programs: Vayana > Atlas (an API marketplace for trade and compliance, with a published OpenAPI 3.1 contract), the > Enriched API Service (EAS, a higher-level wrapper over the GSTN/NIC/IRP government systems), and > the GSP Pass-Through API Service (PAS, a thin encrypted gateway to the same systems). Generated by API Evangelist on 2026-09-02. This file was written by API Evangelist from Vayana's published documentation and contract; Vayana does not serve an llms.txt of its own (probed 2026-09-02: 404 on every host). ## What you can actually do here - Register and cancel GST e-invoices with an Invoice Registration Portal, and get back the government-signed invoice and QR code. - Generate, update, extend, cancel and reject Indian E-Way Bills for goods movements. - Download GST returns (GSTR-1, 2A, 2B, 3B, 6, CMP) and act on Invoice Management System records. - Verify Indian businesses and individuals against government registries: PAN, GSTIN, PAN-to-GSTIN, MCA/CIN, Udyam, Udyog, EPF, passport, driving licence, voter ID, vehicle, challan, TAN, FSSAI, shop & establishment, and bank account. - Verify an e-invoice, a signed QR code, a scanned QR code, an e-invoice PDF, or an invoice against its E-Way Bill. ## Contract - [Vayana Atlas OpenAPI 3.1](openapi/vayana-network-atlas-openapi.json): the only machine-readable contract Vayana publishes. 64 paths, 65 operations, 63 with operationId, across four tags — Verification Suite (30), Compliance Suite (27), Authorization Suite (5), Support Suite (3). Served by Vayana at https://s.docs.atlas.vayana.com/assets/documentation/mergedOpenapi.json (it is loaded at runtime by the Swagger UI app; it is not linked from any documentation page). - [API Evangelist overlay](overlays/vayana-network-atlas-overlay.yaml): our enrichment of that contract, including the gaps it leaves. ## Hosts - Atlas sandbox: `https://s.api.one.vayana.com` — the only server in the contract's servers[] block. **No production Atlas host is published anywhere.** Do not infer one. - EAS production: `https://live.enriched-api.vayana.com` (calls are chargeable) - EAS sandbox: `https://solo.enriched-api.vayana.com` (not chargeable) - GSP PAS production: `https://api.gsp.vayana.com` - GSP PAS sandbox: `https://yoda.api.vayanagsp.in` - SSO production: `https://services.vayana.com/theodore/apis/v1` - SSO sandbox: `https://sandbox.services.vayananet.com/theodore/apis/v1` Note: every API host above returns `503` to any unauthenticated GET, including the host root. That is an edge policy, not an outage. ## Documentation - [Atlas API reference](https://s.docs.atlas.vayana.com/) — Swagger UI over the OpenAPI above - [Atlas marketplace](https://atlas.vayana.com/) - [Enriched API Service docs](https://docs.enriched-api.vayana.com/) — the deepest of the three - [Getting started](https://docs.enriched-api.vayana.com/1s0-getting-started/) - [Onboarding and auth token](https://docs.enriched-api.vayana.com/1s1-onboarding/) - [Integration, headers and encryption](https://docs.enriched-api.vayana.com/1s2-integrating/) - [Error payloads](https://docs.enriched-api.vayana.com/components/error-payloads/) - [Long-running tasks](https://docs.enriched-api.vayana.com/routes/enriched/long-running-tasks/) - [Downloads: public keys and certificates](https://docs.enriched-api.vayana.com/3-downloads/) - [GSP Pass-Through docs](https://docs.gsp.vayana.com/) - [GSP server instances](https://docs.gsp.vayana.com/server-instances/) ## Authentication Bearer JWT from Vayana's own SSO service (internally "theodore"): `POST /theodore/apis/v1/authtokens`. Default lifetime 20 minutes, maximum 360; refreshable until a hard expiry of 6x the token duration; at most 10 concurrent sessions per user. The EAS additionally requires `X-FLYNN-N-USER-TOKEN` and `X-FLYNN-N-ORG-ID` headers, the GSP code `vay`, and the taxpayer's own government-portal credentials passed through. Sensitive values may be AES-encrypted under a per-request RSA-wrapped key (`X-FLYNN-S-REK`). There is no OAuth 2.0, no OpenID Connect and no scope vocabulary. Details: [authentication](authentication/vayana-network-authentication.yml). ## What an agent needs to know before writing - **There is no idempotency key on any operation.** Write operations mint government records with legal weight (an IRN, an E-Way Bill number). A retried POST after a timeout has no documented safe outcome. Reconcile before retrying. - **Reversal operations exist but no windows are published.** Cancel e-invoice, cancel E-Way Bill, reject E-Way Bill, extend validity and reset IMS action are all documented; Vayana states no deadline for any of them, because the deadlines belong to the government portals. Do not assume one. - **Read `status` in the body, not just the HTTP status.** A `200` can carry `status: "0"` and an error object in the v3 envelope. - **Bulk work is asynchronous.** Submit, poll `data.task.status` until `completed`, then fetch result or download. Results expire after 7 days. - **Close E-Way Bill is sandbox-only.** A flow rehearsed in sandbox may not be buildable in production. ## Artifacts in this profile - [Authentication](authentication/vayana-network-authentication.yml) - [Conventions, including reversibility](conventions/vayana-network-conventions.yml) - [Error catalog — the envelope plus 287 published E-Way Bill codes](errors/vayana-network-problem-types.yml) - [Lifecycle, versioning and deprecation](lifecycle/vayana-network-lifecycle.yml) - [Conformance and domain standards](conformance/vayana-network-conformance.yml) - [Sandbox environments](sandbox/vayana-network-sandbox.yml) - [Data model](data-model/vayana-network-data-model.yml) - [Plans and pricing](plans/vayana-network-plans-pricing.yml) - [Rate limits and caps](rate-limits/vayana-network-rate-limits.yml) - [Packages](packages/vayana-network-packages.yml) - [Domain security](security/vayana-network-domain-security.yml) - [MCP candidate tool surface](mcp/vayana-network-mcp.yml) - [Agent skills](skills/_index.yml) ## Domain standards The Generate E-Invoice request body is the Indian GST e-invoice document (INV-01, Version 1.1) field for field — `TranDtls`, `DocDtls`, `SellerDtls`, `BuyerDtls`, `ItemList`, `ValDtls`, `EwbDtls`. An integrator already producing INV-01 needs no field mapping. The E-Way Bill surface speaks the NIC contract, and its 287-code error dictionary is retrievable as a live operation. ## Not published No MCP server. No A2A agent card. No SDK or client library in any registry. No public pricing. No rate limits or rate-limit headers. No 429. No status page or SLA. No webhooks or event stream (bulk e-invoice generation can trigger an email notification, which is not a webhook). No security.txt, vulnerability disclosure policy or trust center. No changelog. No CLI. No RFC 9457 problem+json. No Sunset or Deprecation headers, though deprecation is documented in prose. ## Company - [Website](https://www.vayana.com/) - [Blog](https://www.vayana.com/blogs/) - [Contact](https://www.vayana.com/contact-us/) - [Privacy policy](https://www.vayana.com/privacy-policy/) - [GitHub organization](https://github.com/Vayana) — 21 repositories, all forks of upstream open-source projects; no first-party client library - Certifications displayed on the GSP product page: ISO 27001, PCI Security, SAP Certified Integration (badges only, no certificate numbers or scope statements)