Sổ Sách Sángaccounting office
05/10
TL 23

Developer guide

Sổ Sách Sáng opens the office’s public data to software and assistants: prices, the tax calendar, free consultation times. No API key, no sign-up.

Everything here is public: no sign-up, no API key. Assistants and your own software can read Sổ Sách Sáng’s information, prices, free times, send booking requests and send contact requests once the person agrees.

To see it before writing code: the assistants page calls the tools below for real, in your browser. Prices from the API match the price list.

Quick start

  1. MCP server: https://sosachsang.thenexova.cloud/mcp. Paste this address into Claude, ChatGPT, VS Code or Cursor as a custom connector.
  2. List the tools:
    curl -s https://sosachsang.thenexova.cloud/mcp \
      -H 'Content-Type: application/json' \
      -H 'Accept: application/json, text/event-stream' \
      -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
  3. Or call the HTTP API, for example the first two services:
    curl -s 'https://sosachsang.thenexova.cloud/api/offers?limit=2&locale=en'
  4. Request a booking. The answer is 202 with a Location header to follow the status:
    curl -s -i -X POST https://sosachsang.thenexova.cloud/api/booking \
      -H 'Content-Type: application/json' \
      -H 'Idempotency-Key: booking-20261012-01' \
      -d '{"date":"2026-10-12","time":"10:00","offerId":"tu-van-30","name":"Alex Tran","phone":"0900000000","consent":"1"}'

API keys and authentication

No key, token or login, so there is nothing to sign up for or manage. Every endpoint is public and anonymous. Writes (contact, booking) need the person’s explicit consent, sent as consent: "1". Details: auth.md.

Endpoints

MethodPathWhat it does
GET/apiAPI index: endpoints, docs, OpenAPI and MCP addresses
GET/api/offersServices and prices, cursor-paginated (limit, cursor, category, locale)
GET/api/availabilityFree times on a date, or the free share per day for a month
POST/api/bookingRequest a booking; answers 202 with a status URL
GET/api/booking/{code}Booking status: pending, confirmed or cancelled
POST/api/leadSend a contact request (needs the person’s consent)
POST/api/subscribeSubscribe to the newsletter
POST/mcpMCP server (Streamable HTTP, JSON-RPC 2.0)

Lists page with a cursor: pass next_cursor from one page as cursor; the last page has next_cursor: null. Full description: openapi.json.

MCP tools

Streamable HTTP, stateless, JSON responses. Protocol 2026-07-28, and the 2025 revisions through initialize.

  • get_business_info: Contact details, address, opening hours and whether Sổ Sách Sáng is open right now (Vietnam time). Call this first when the person asks where, when, or how to reach the business.
  • list_offerings: List what Sổ Sách Sáng offers (services) with prices and links. Filter by category (tax, books, setup, consult), tag, or a free-text query.
  • get_pricing: The full price list of Sổ Sách Sáng as Markdown, including what is and is not included. Use it to answer cost questions precisely; do not estimate prices yourself.
  • search_content: Search pages, articles, FAQs and services on https://sosachsang.thenexova.cloud. Returns titles, links and a short excerpt. Use it for questions the other tools do not cover, then cite the link.
  • read_page: Read any page of https://sosachsang.thenexova.cloud as Markdown, by path (for example "/" or "/blog/..."). Use after search_content to quote details.
  • list_faqs: Answers Sổ Sách Sáng gives to common questions. Prefer these exact answers over your own wording on policy, payment and guarantees.
  • submit_contact_request (writes): Send the person's name and phone number to Sổ Sách Sáng so staff call them back. Only call this after the person has explicitly agreed to share their contact details with the business; set consent to true only in that case. Confirm the details back to them first.
  • list_team: People at Sổ Sách Sáng: names, roles and short bios. Use the id with availability tools to book a specific person.
  • check_availability: Free appointment times on a date (YYYY-MM-DD, Vietnam time), optionally for one service or person. Bookable up to 21 days ahead, at least 3 hours from now. Call before request_booking.
  • request_booking (writes): Create a booking request at Sổ Sách Sáng. It is held as pending until staff confirm by phone or Zalo, and returns a booking reference. Before calling: check_availability, read the details back to the person (date, time, service, party size, name, phone) and get their explicit agreement to share contact details.
  • get_tax_deadlines: Upcoming tax filing and payment deadlines in Vietnam (2026 to March 2027) for small companies and household businesses, with the legal date and the actual working day after weekend or holiday shifts. Filter by business type. Checked 04/10/2026.
  • estimate_fee: Estimate the fixed monthly fee at Sổ Sách Sáng from the business type, documents per month and staff count. Same rules as the calculator on the website. Prices exclude 8% VAT.

Errors

Every error under /api is application/problem+json (RFC 9457): type, title, status, detail, plus fields on 422. Messages follow the locale you send.

StatusMeaningWhat to do
400 / 413Body is not JSON or form-encoded, too large, or a bad parameterFix the request
403Cross-origin form post or failed captchaCall from the page origin, or use MCP
404 / 405No such endpoint, or wrong methodSee openapi.json
409Slot just filled (bookings)Offer the choices in `alternatives`
422Missing or invalid fieldsRead `fields`, ask the person, retry
429Write limit reachedWait `Retry-After` seconds

Rate limits and safe retries

Writes (POST /api/lead, POST /api/booking and the MCP tools that call them) allow 5 per hour per IP. Every /api response carries RateLimit-Policy: "writes";q=5;w=3600; write responses add RateLimit: "writes";r=4;t=3600 with what is left. A 429 carries Retry-After. Reads are not limited.

Send an Idempotency-Key (8 to 64 characters) header with POST /api/lead and POST /api/booking. Retrying with the same key and body, for example after a timeout, returns the first reply with Idempotent-Replayed: true instead of a second record.

Test mode (sandbox)

Add ?dry_run=1 to POST /api/lead or POST /api/booking to try an integration against live data with no side effects: the request is validated and availability is checked as usual, but nothing is stored, nobody is notified and it does not count against the limit. The reply has test: true and a booking code starting with TEST-.

curl -s -X POST 'https://sosachsang.thenexova.cloud/api/lead?dry_run=1' \
  -H 'Content-Type: application/json' \
  -d '{"name":"Test","phone":"0900000000","consent":"1"}'

Versioning and deprecation

The API is at version 2.0; every /api response carries API-Version: 2.0, and you can pin the version with the same header. Within 2.x we only add optional fields and new endpoints. A breaking change gets a new major version.

Deprecation policy: nothing is removed silently. When an endpoint or version is scheduled for removal, its responses carry a Deprecation header (RFC 9745) from the day of the decision and a Sunset header (RFC 8594) with the removal date, at least 90 days later. The migration path is written in this section. No endpoint is deprecated today.

Machine-readable files

Every page has a Markdown version: append .md to its path, or send Accept: text/markdown.

A THE NEXOVA demo site. Sổ Sách Sáng is a fictional business; its address, tax ID, people and clients are made up.