The rows worth reading twice
Creating a sub-client works on both, and belongs on the API. The dashboard creates one from Customers, which is what you want for a handful onboarded by hand. Onboarding a customer is normally part of your product’s own flow, though, and that is the API. Webhook endpoints are the dashboard alone. Registering a URL, filtering its events, pausing it, rotating its secret and replaying a delivery all happen in the Developers section of the dashboard, and there is no/v1 endpoint for any of them.
Roles are a dashboard matter. Who on your team may do what is set in the dashboard, by an administrator on your own team, and there is no /v1 endpoint for it either. Roles and permissions covers what each role grants.
A dashboard payout takes a one-time code, sent to the person making it, and an API payout does not. Same operation, same result, different check.
Choosing between them
The question is not what is possible, it is who is doing it and how often:- Every time, automatically, inside your product → the API.
- Occasionally, by a person, with judgement involved → the dashboard.
Whichever surface an operation happens on, the same webhooks fire. Your integration learns about a dashboard action without doing anything special, so you never have to reconcile the two.