Skip to main content
Send your API key in the Authorization header on every request:
The SDKs and the CLI read the key from the INVOICE_AI_API_KEY environment variable. Only GET /openapi.json works without a key.

Create a key

Create keys in Settings → API keys. Give the key a name, choose its scopes and, optionally, an expiry in days (0 never expires). Keys look like inv_live_ab12cd34_7Kf9QmXz2pR4vNt6LwYb8HsJ3dGc5eAu. The full key is shown once. If you lose it, revoke it and create a new one.
There’s no test mode. Every key works on your real account. To try things out, create a customer with an email address you control.
You can’t create, list or revoke keys through the API.

Scopes

A request without the endpoint’s scope fails with 403 forbidden, and detail names the missing scope. Presets in Settings:
  • Read only: business:read, clients:read, invoices:read.
  • Raise and send invoices: Read only, plus clients:write, invoices:write, invoices:finalize, invoices:send and payments:write.
Give each integration only the scopes it needs.

Errors

A missing, malformed, unknown, revoked or expired key returns 401 unauthorized. The detail says which, for example This API key has been revoked. See Errors.

Rotate a key

  1. Create a new key with the same scopes.
  2. Deploy it everywhere the old key is used.
  3. Check the old key’s last used time in Settings, then revoke it. Revocation takes effect on the next request.
Keep keys on your server. Never put one in browser code, a mobile app, a public repository or a URL. If a key leaks, revoke it in Settings right away.