API changelog
Dated log of the additions, changes and deprecations of the NovaFisko API v1, from newest to oldest.
This log lists the changes to the v1 API, from the most recent to the oldest. The rules that govern these changes are described in the versioning policy.
Each entry is classified as follows:
| Label | Meaning |
|---|---|
| Added | New route, new field or new event. Compatible |
| Changed | Compatible evolution of an existing behaviour |
| Fixed | Alignment of a behaviour with the documentation |
| Deprecated | Item due to disappear, with its removal date |
No deprecation is in progress on v1.
5 October 2026
Opening of the API to third-party integrations.
Integration tokens
- Added:
GET /v1/auth/tokens,POST /v1/auth/tokensandDELETE /v1/auth/tokens/{token}to create, list and revoke integration tokens. - Added:
read,writeandsyncabilities, optional expiry from 1 to 730 days, last-used date. - Added:
403errorstoken_ability_missing(withrequired_ability) andsession_token_required,422errortoken_limit_reached.
See Authentication.
Webhooks
- Added: endpoints per firm with
GET,POST,PATCHandDELETE /v1/firms/{firm}/webhooks. - Added: test send
POST .../webhooks/{webhook}/testand logGET .../webhooks/{webhook}/deliveries. - Added: catalogue
GET /v1/webhooks/events. - Added: events
document.imported,document.booked,entry.posted,entry.reversed,bank.transaction_imported,vat.declaration_validated,fiscal_year.closed,peppol.status_changed,third_party.created,third_party.updatedandwebhook.test. - Added: HMAC-SHA256 signature in the
X-Novafisko-Signatureheader,X-Novafisko-EventandX-Novafisko-Deliveryheaders. - Added: 8 delivery attempts with an increasing delay from 1 to 64 minutes.
See Webhooks and Verify signatures.
Demo mode
- Added:
POST /v1/auth/demoopens a demo session without an account, valid for 24 hours, on a fictitious firm reset every night. - Added:
is_demofield in the response ofGET /v1/auth/me. - Added:
403errordemo_modeon external effects and503errordemo_unavailable.
See Overview.
Documentation
- Added: OpenAPI 3.1 specification in JSON and YAML, Postman collection and interactive reference.
- Added: integration guides and step-by-step use cases.
History and synchronisation
- Added: change history with
GET history, detail of a revision and history per record. - Added: revert of a revision or of a complete operation with
POST history/{revision}/revertandPOST history/operations/{operation}/revert. - Added: recycle bin with
GET trash, restore and permanent purge. Existing deletions now move the record to the recycle bin and respond with theX-Trashed: 1header. - Added: offline synchronisation with
sync/bootstrap,sync/pull,sync/push,sync/statusandsync/conflicts. - Added: idempotency of writes with
X-Client-Mutation-Idand theX-Idempotent-Replay: 1response. - Added: optimistic lock with
X-Base-Versionand the409conflictresponse. - Added:
versionfield on the resources tracked by the history. - Added: activity log
GET activityper company andGET /v1/firms/{firm}/activityper firm. - Added: probe
GET /v1/ping. Every503response now carries acode.
See Idempotency and Continuous sync.
Document importer
- Added:
document-importsto upload PDF, image, XML and ZIP files, analyse them, correct them and validate them. - Added: signed preview of the uploaded file.
Exports
- Added: PDF and XLSX formats for all exports, in addition to CSV, with the
formatparameter. - Added: detailed catalogue in
GET exports(catalogfield), PDF preview through a signed URL andX-Export-Fingerprintheader. - Changed: the full dossier (
exports/full-dossier/{fiscalYear}) now contains the PDFs, the CSVs, the CODA files, the documents and amanifest.jsonin version 2.
Licence, company detection, Peppol and integrations
- Added: firm licence, activation and release of a key, public price list and simulator.
- Added: company detection
lookup/*, company sheets and reference lists of legal forms and NACE codes. - Added: Peppol registration of a company, transport settings, directory and Peppol status of third parties.
- Added: integration catalogue per company, activation, test, synchronisation and run log.
- Added: journal rules, bank rules, analytic codes, budgets and third-party reminders.
4 October 2026
First version of the v1 API, used by the NovaFisko applications.
- Added: token authentication with
auth/login,auth/meandauth/logout. - Added: firms, team and assignment of companies.
- Added: companies with initialisation of the chart of accounts, the journals, the VAT codes and the fiscal year according to the country pack (Belgium, France, Luxembourg).
- Added: reference data (accounts, journals, third parties, VAT codes, fiscal years and periods).
- Added: free-form entries, purchase and sales invoices, reversal.
- Added: documents and bank transactions imported from Novadesko, bank reconciliation and CODA files.
- Added: fixed assets and depreciation schedules.
- Added: VAT returns, Intervat XML file, customer listing and intra-Community listing.
- Added: statements (trial balance, general ledger, balance by period, balance sheet and income statement, third-party balances, aged balance) and year-end operations.
- Added: recurring entries and quality checks.
- Added: CSV exports and full dossier as ZIP.
Staying informed
The log is updated with every deployment that affects the API. Deprecations are also signalled by the Deprecation and Sunset headers described in the versioning policy.