Skip to main content
POST
cURL

Authorizations

Authorization
string
header
required

An Invoice-AI API key sent as Authorization: Bearer inv_live_….

Create keys in Settings → API keys; the secret is shown once. Each key carries scopes, and every operation lists the scope it needs (x-required-scope):

  • business:read — Read your business profile, tax ID and bank details
  • clients:read — List and read your clients
  • clients:write — Create, update and archive clients
  • products:read — List and read products and prices
  • products:write — Create, update and archive products and prices
  • invoices:read — List and read invoices, including PDFs
  • invoices:write — Create, edit and delete drafts
  • invoices:finalize — Finalize invoices and void them
  • invoices:send — Email invoices to your clients
  • payments:write — Mark invoices as paid
  • webhooks:manage — Manage webhook endpoints

Keys cannot be created or revoked through the API, so a leaked key cannot mint more keys.

Headers

Idempotency-Key
string

A unique key per distinct operation (a UUID works), reused only when retrying that same request. Up to 255 characters; stored for 24 hours.

Maximum string length: 255
Example:

"6f1c2d9e-8a4b-4c3f-9e7d-2b5a1c8f4e30"

Body

application/json
url
string
required

An https:// URL of up to 2048 characters, without a username or password, that resolves only to public addresses. Redirects are not followed.

Example:

"https://example.com/webhooks/invoice-ai"

events
enum<string>[]

Event types to receive. Omit or send [] to receive every type, including ones added later.

Available options:
invoice.created,
invoice.updated,
invoice.finalized,
invoice.emailed,
invoice.email_failed,
invoice.viewed,
invoice.downloaded,
invoice.paid,
invoice.voided
Example:

Response

The endpoint, with its signing secret.

data
object
required

The created endpoint, including its secret.