Authorization header on every request:
INVOICE_AI_API_KEY environment variable. Only GET /openapi.json works without a key.
Create a key
Create keys in Settings → API keys. Give the key a name, choose its scopes and, optionally, an expiry in days (0 never expires).
Keys look like inv_live_ab12cd34_7Kf9QmXz2pR4vNt6LwYb8HsJ3dGc5eAu. The full key is shown once. If you lose it, revoke it and create a new one.
There’s no test mode. Every key works on your real account. To try things out, create a customer with an email address you control.
Scopes
A request without the endpoint’s scope fails with403 forbidden, and detail names the missing scope.
Presets in Settings:
- Read only:
business:read,clients:read,invoices:read. - Raise and send invoices: Read only, plus
clients:write,invoices:write,invoices:finalize,invoices:sendandpayments:write.
Errors
A missing, malformed, unknown, revoked or expired key returns401 unauthorized. The detail says which, for example This API key has been revoked. See Errors.
Rotate a key
- Create a new key with the same scopes.
- Deploy it everywhere the old key is used.
- Check the old key’s last used time in Settings, then revoke it. Revocation takes effect on the next request.