Skip to main content
SDKs & CLI 0.1.0 (beta) published
  • npm install @horizonpay/invoice-ai and pip install horizonpay-invoice-ai: typed clients with retries, idempotency keys, pagination and webhook verification. See Node.js and Python.
  • npm install -g @horizonpay/invoice-ai-cli: the invoice-ai command with browser login. See CLI.
  • npm releases are built and published by GitHub Actions with provenance, so you can verify where each version came from.
  • Every API reference page now shows cURL, Node.js and Python examples, and the whole API is one click away with Run in Postman.
  • 0.x is a beta, so minor releases may break. Pin the minor version.
Sending and webhook hardening
  • POST /invoices/{id}/send requires a verified account email. Otherwise it returns 409 invalid_state.
  • Invoice emails are capped at 50 per hour per account, across all keys and the dashboard, on top of 10 per hour per key. See Rate limits.
  • Webhook URLs can’t contain a username or password. IPv6 forms that embed an IPv4 address (NAT64, 6to4, Teredo) are refused, and every delivery re-checks the address.
  • invoice.viewed and invoice.downloaded fire at most once per invoice every 10 minutes.
  • Unexpected database errors return 502 upstream_failed with a generic detail.
v1
The first public version of the API, at https://invoice.horizonpay.co/api/v1.Resources
  • Business: read your business profile. Read-only.
  • Customers: create, list, read, update and archive (cus_…).
  • Products and prices: a catalog (prod_…, price_…) with one-time or recurring prices. Recurring prices don’t bill automatically.
  • Invoices: create, update, delete, finalize, send, pay and void (in_…), plus PDFs and event history.
  • Invoice items: add, list, read and remove lines on a draft (ii_…).
  • Webhook endpoints: register, list and delete HTTPS endpoints.
Platform
  • Bearer API keys (inv_live_…) with 11 scopes, managed in Settings.
  • RFC 9457 application/problem+json errors with stable code values.
  • Idempotency-Key, required on invoice creation and every lifecycle action.
  • Cursor pagination with limit up to 100.
  • Per-key rate limits: 120 requests per minute and 10 sends per hour.
  • Nine webhook event types, signed with Standard Webhooks and retried with backoff.
  • A public OpenAPI 3.1 document at /api/v1/openapi.json, and a Postman collection.
Changes before the SDKs
  • PATCH /invoices/{id} is a partial update. Lines are kept unless you send items.
  • Money uses each currency’s own minor unit (¥5,000 is 5000) everywhere, including webhooks.
  • Webhook payloads carry the REST Invoice under data.object. New signing secrets are standard base64.
  • GET /webhook-endpoints and GET /invoices/{id}/events are paginated.
  • POST /invoices/{id}/send returns { data: Invoice, emailed_to }.
  • A malformed id returns 404, an invalid cursor returns 422, and a reused Idempotency-Key returns idempotency_mismatch.
Known limitations
  • Webhooks are delivered once a day. See Verify signatures.
  • No business profile writes, credit notes, OAuth apps or key management through the API.