SDKs & CLI 0.1.0 (beta) published
npm install @horizonpay/invoice-aiandpip install horizonpay-invoice-ai: typed clients with retries, idempotency keys, pagination and webhook verification. See Node.js and Python.npm install -g @horizonpay/invoice-ai-cli: theinvoice-aicommand with browser login. See CLI.- npm releases are built and published by GitHub Actions with provenance, so you can verify where each version came from.
- Every API reference page now shows cURL, Node.js and Python examples, and the whole API is one click away with Run in Postman.
0.xis a beta, so minor releases may break. Pin the minor version.
Sending and webhook hardening
POST /invoices/{id}/sendrequires a verified account email. Otherwise it returns409 invalid_state.- Invoice emails are capped at 50 per hour per account, across all keys and the dashboard, on top of 10 per hour per key. See Rate limits.
- Webhook URLs can’t contain a username or password. IPv6 forms that embed an IPv4 address (NAT64, 6to4, Teredo) are refused, and every delivery re-checks the address.
invoice.viewedandinvoice.downloadedfire at most once per invoice every 10 minutes.- Unexpected database errors return
502 upstream_failedwith a genericdetail.
v1
The first public version of the API, at
https://invoice.horizonpay.co/api/v1.Resources- Business: read your business profile. Read-only.
- Customers: create, list, read, update and archive (
cus_…). - Products and prices: a catalog (
prod_…,price_…) with one-time or recurring prices. Recurring prices don’t bill automatically. - Invoices: create, update, delete, finalize, send, pay and void (
in_…), plus PDFs and event history. - Invoice items: add, list, read and remove lines on a draft (
ii_…). - Webhook endpoints: register, list and delete HTTPS endpoints.
- Bearer API keys (
inv_live_…) with 11 scopes, managed in Settings. - RFC 9457
application/problem+jsonerrors with stablecodevalues. Idempotency-Key, required on invoice creation and every lifecycle action.- Cursor pagination with
limitup to 100. - Per-key rate limits: 120 requests per minute and 10 sends per hour.
- Nine webhook event types, signed with Standard Webhooks and retried with backoff.
- A public OpenAPI 3.1 document at
/api/v1/openapi.json, and a Postman collection.
PATCH /invoices/{id}is a partial update. Lines are kept unless you senditems.- Money uses each currency’s own minor unit (¥5,000 is
5000) everywhere, including webhooks. - Webhook payloads carry the REST
Invoiceunderdata.object. New signing secrets are standard base64. GET /webhook-endpointsandGET /invoices/{id}/eventsare paginated.POST /invoices/{id}/sendreturns{ data: Invoice, emailed_to }.- A malformed id returns
404, an invalidcursorreturns422, and a reusedIdempotency-Keyreturnsidempotency_mismatch.
- Webhooks are delivered once a day. See Verify signatures.
- No business profile writes, credit notes, OAuth apps or key management through the API.