Skip to content
Documentation
English
Open the app

API reference

Complete reference of the NovaFisko API v1, generated from the OpenAPI specification, with parameters, schemas and examples for every route.

This reference is generated from NovaFisko's OpenAPI 3.1 specification. It describes every route with its parameters, the expected body, the possible responses and an example call in curl, PHP, JavaScript and Python.

All routes are relative to https://api.novafisko.com/v1 and require, unless stated otherwise, the Authorization: Bearer <token> header. Routes are grouped by area. Schemas expand with one click and each example can be copied with the Copy button.

Tip

Do you prefer to work in your own tool? Download the specification in JSON or in YAML, or import the Postman collection.

If you are new to the API, start with the overview, authentication and the conventions. The use cases show how to chain the calls.

Complete reference of the NovaFisko API v1.0.0: 240 endpoints grouped by domain, generated from the OpenAPI 3.1 specification. Expand an endpoint to see its parameters, body, responses and a request sample.

Endpoint summaries and descriptions are in English: they come straight from the specification.

Base URLhttps://api.novafisko.com
240 endpoints
Common headers and parameters Idempotence, optimistic lock, device, language and signed URLs: described once here.
NameTypeDescription
Accept-Language
header
stringLanguage of the translated messages and labels (fr, nl, en, de). The language of the authenticated user wins when it is set; several endpoints also accept ?lang=.
fr nl en de
X-Client-Mutation-Id
header
stringIdempotence key chosen by the client (64 characters max, a UUID is recommended). A request replayed with the same key returns the memorised result with status 200 and X-Idempotent-Replay: 1; nothing is executed twice.
e.g. b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11
X-Base-Version
header
integerOptimistic lock (opt-in): the version of the record the client last read. When the record moved on the server the answer is 409 conflict with server_version and server_data, and nothing is changed.
e.g. 3
X-Operation-Id
header
string <uuid>UUID grouping every change of the request in the history (generated when absent). Returned in the response when something was recorded: it is the handle of « undo ».
X-Device-Id
header
stringStable id of the app install or of the integration (64 characters max). Shown in the history and in the synchronisation status.
e.g. erp-connector-01
X-Device-Name
header
stringReadable device name, percent-encoded (120 characters max).
e.g. ERP%20connector
X-Occurred-At
header
string <date-time>ISO 8601 date of the action on the client. Bounded to ±24 h around the server time; used to rank conflicts.
X-Origin
header
stringoffline_sync when the request replays an action made offline.
offline_sync
signature
query
stringSignature of the URL (issued by the API).
expires
query
integerUnix timestamp after which the signed URL is refused.

Response headers

Response headerDescription
X-Operation-IdOperation id under which the changes of the request were recorded in the history. Present only when something was recorded.
X-Trashed1 when the DELETE moved the record to the recycle bin (restorable) instead of destroying it.
X-Idempotent-Replay1 when the answer is the memorised result of a previous request carrying the same X-Client-Mutation-Id.
X-Export-FingerprintSHA-256 of the exported data set: two exports of the same data carry the same fingerprint.
Content-DispositionFile name of the download (attachment; filename="…") or inline for previews.
X-RateLimit-LimitMaximum number of requests in the current window.
X-RateLimit-RemainingRequests left in the current window.
Retry-AfterSeconds to wait before the next attempt.

Meta

Service status, connectivity probe and country packs.

GET/API root Public

Name and version of the API.

Public endpoint: no bearer token.

Operation id root

Responses

200OK

application/json

Schema object
  • namestring
    e.g. NovaFisko API
  • versionstring
    e.g. v1
  • statusstring
    e.g. ok
Example
{
    "name": "NovaFisko API",
    "version": "v1",
    "status": "ok"
}

Request sample

curl -X GET "https://api.novafisko.com/" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/', [
    'headers' => [
        'Accept' => 'application/json',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/",
    headers={
        "Accept": "application/json",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/statusService status Public

Public endpoint: no bearer token.

Operation id status

Responses

200OK

application/json

Schema object
  • okboolean
  • timestring <date-time>
Example
{
    "ok": true,
    "time": "2026-03-15T09:41:00+00:00"
}

Request sample

curl -X GET "https://api.novafisko.com/v1/status" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/status', [
    'headers' => [
        'Accept' => 'application/json',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/status", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/status",
    headers={
        "Accept": "application/json",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/pingConnectivity probe Public

Cheap probe without database access. The apps call it to leave offline mode; integrations can use it as a health check and to read the server clock.

Public endpoint: no bearer token.

Operation id ping

Responses

200OK

application/json

Schema object
  • okboolean
  • server_timestring <date-time>
Example
{
    "ok": true,
    "server_time": "2026-03-15T09:41:00+00:00"
}

Request sample

curl -X GET "https://api.novafisko.com/v1/ping" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/ping', [
    'headers' => [
        'Accept' => 'application/json',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/ping", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/ping",
    headers={
        "Accept": "application/json",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/country-packsAvailable country packs read

Country packs (chart of accounts, VAT codes, journals) a company file can be created with.

Integration tokens need the read ability.

Operation id country-packs

Common headers: Accept-Language

Responses

200OK

application/json

Schema object[]

Array of

  • codestring
    BE FR LU
  • currencystring
    e.g. EUR
  • vat_regimesstring[]
    monthly quarterly franchise exempt unit
Example
[
    {
        "code": "BE",
        "currency": "EUR",
        "vat_regimes": [
            "monthly"
        ]
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/country-packs" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/country-packs', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/country-packs", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/country-packs",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Auth

Sign-in, account of the user, demo session.

POST/v1/auth/loginSign in Public 20 / 1 min

Exchanges an e-mail and a password for a session token (all abilities). Novadesko fiduciary users sign in with their Novadesko credentials: firm, team and company files are mirrored at each sign-in. Ten failed attempts per IP lock the sign-in for five minutes.

Public endpoint: no bearer token.

Rate limit: 20 requests per minute (429 beyond, see Retry-After).

Operation id auth.login

Request body

application/json

Schema object
  • emailstring <email>required
  • passwordstringrequired
    e.g. ••••••••
  • device_namestring
    Label of the token (100 characters max).
    e.g. MacBook de Claire
Example
{
    "email": "claire.dumont@fiduciaire-dumont.be",
    "password": "correct horse battery staple",
    "device_name": "ERP connector"
}

Responses

201Signed in

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • tokenstring
    Bearer token, shown once.
  • userUser
Example
{
    "token": "57|Qm9x2kL8vT4nR7sW1pZ5cY3hJ6dF0gA9bE2uI4oK",
    "user": {
        "id": 12,
        "name": "Claire Dumont",
        "email": "claire.dumont@fiduciaire-dumont.be",
        "locale": "fr",
        "email_verified": true,
        "pending_email": null,
        "is_platform_admin": false,
        "is_demo": false,
        "firms": [
            {
                "public_token": "NDTQVQU4AUAV",
                "name": "Fiduciaire Dumont & Associés",
                "role": "admin"
            }
        ],
        "managed_firms": [
            {
                "public_token": "NDTQVQU4AUAV",
                "name": "Fiduciaire Dumont & Associés"
            }
        ]
    }
}
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/auth/login" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "claire.dumont@fiduciaire-dumont.be",
    "password": "correct horse battery staple",
    "device_name": "ERP connector"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/auth/login', [
    'headers' => [
        'Accept' => 'application/json',
    ],
    'json' => [
        'email' => 'claire.dumont@fiduciaire-dumont.be',
        'password' => 'correct horse battery staple',
        'device_name' => 'ERP connector',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/login", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "email": "claire.dumont@fiduciaire-dumont.be",
      "password": "correct horse battery staple",
      "device_name": "ERP connector"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/auth/login",
    headers={
        "Accept": "application/json",
    },
    json={
        "email": "claire.dumont@fiduciaire-dumont.be",
        "password": "correct horse battery staple",
        "device_name": "ERP connector"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/auth/demoSign in to the demo Public 10 / 1 min

Creates an ephemeral user attached to the demo firm (« Fiduciaire Démo », four realistic Belgian company files) and returns its token. Local bookkeeping is allowed (entries, lettering, VAT declarations, exports, history, recycle bin, synchronisation); every external effect answers 403 demo_mode: Peppol, Novadesko, e-mails and reminders, integrations, licence keys, team and firm management, company creation and deletion, webhooks and integration tokens, company lookups and VIES, uploads and analysis of the document importer, SEPA files (operations flagged x-demo-blocked). A demo user never reaches anything outside the demo firm (404). The demo data is reset every night and demo users are purged after 24 hours.

Public endpoint: no bearer token.

Rate limit: 10 requests per minute (429 beyond, see Retry-After).

Error codes (code):

  • demo_unavailable: the demo data set is not available right now

Operation id auth.demo

Request body optional

application/json

Schema object
  • localestring
    fr nl en de
  • device_namestring
    100 characters max.
Example
{
    "locale": "fr"
}

Responses

201Demo session opened

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • tokenstring
  • userUser
  • demoobject
    Properties
    • firmobject
      Properties
      • public_tokenstring
      • namestring
        e.g. Fiduciaire Démo
    • companiesobject[]
      Properties
      • public_tokenstring
      • codestring
        e.g. COMPTOIR
      • namestring
        e.g. Le Comptoir Montois SRL
    • expires_atstring <date-time>
      End of life of the demo user.
    • resets_atstring <date-time>
      Next nightly reset of the demo data.
Example
{
    "token": "XBVD5O1L29HC",
    "user": {
        "id": 12,
        "name": "Claire Dumont",
        "email": "claire.dumont@fiduciaire-dumont.be",
        "locale": "fr",
        "email_verified": true,
        "pending_email": "claire.dumont@fiduciaire-dumont.be",
        "is_platform_admin": false,
        "is_demo": false,
        "firms": [
            {
                "public_token": "NDTQVQU4AUAV",
                "name": "Fiduciaire Dumont & Associés",
                "role": "admin"
            }
        ],
        "managed_firms": [
            {
                "public_token": "NDTQVQU4AUAV",
                "name": "Fiduciaire Dumont & Associés"
            }
        ]
    },
    "demo": {
        "firm": {
            "public_token": "XBVD5O1L29HC",
            "name": "Fiduciaire Démo"
        },
        "companies": [
            {
                "public_token": "XBVD5O1L29HC",
                "code": "COMPTOIR",
                "name": "Le Comptoir Montois SRL"
            }
        ],
        "expires_at": "2026-03-15T09:41:00+00:00",
        "resets_at": "2026-03-15T09:41:00+00:00"
    }
}
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error
503The demo firm is not seeded (demo_unavailable).

application/json

Schema Error

Example
{
    "message": "La démonstration est momentanément indisponible.",
    "code": "demo_unavailable"
}

Request sample

curl -X POST "https://api.novafisko.com/v1/auth/demo" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "locale": "fr"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/auth/demo', [
    'headers' => [
        'Accept' => 'application/json',
    ],
    'json' => [
        'locale' => 'fr',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/demo", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "locale": "fr"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/auth/demo",
    headers={
        "Accept": "application/json",
    },
    json={
        "locale": "fr"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/auth/meCurrent user read

User behind the token, with the firms it belongs to and is_demo.

Integration tokens need the read ability.

Operation id auth.me

Common headers: Accept-Language

Responses

200OK

application/json

Schema User

Example
{
    "id": 12,
    "name": "Claire Dumont",
    "email": "claire.dumont@fiduciaire-dumont.be",
    "locale": "fr",
    "email_verified": true,
    "pending_email": null,
    "is_platform_admin": false,
    "is_demo": false,
    "firms": [
        {
            "public_token": "NDTQVQU4AUAV",
            "name": "Fiduciaire Dumont & Associés",
            "role": "admin"
        }
    ],
    "managed_firms": [
        {
            "public_token": "NDTQVQU4AUAV",
            "name": "Fiduciaire Dumont & Associés"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/auth/me" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/auth/me', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/me", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/auth/me",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/auth/logoutSign out write

Revokes the token used for the request.

Integration tokens need the write ability.

Operation id auth.logout

Common headers: Accept-Language

Responses

204Token revoked.

No body.

401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/auth/logout" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/auth/logout', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/logout", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/auth/logout",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/auth/forgot-passwordAsk for a password reset Public 5 / 1 min

Always answers the same generic message, whether the account exists or not.

Public endpoint: no bearer token.

Rate limit: 5 requests per minute (429 beyond, see Retry-After).

Operation id auth.forgot-password

Request body

application/json

Schema object
  • emailstring <email>required
  • localestring
    fr nl en de
Example
{
    "email": "claire.dumont@fiduciaire-dumont.be",
    "locale": "fr"
}

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema Message

Example
{
    "message": "Mot de passe modifié."
}
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/auth/forgot-password" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "claire.dumont@fiduciaire-dumont.be",
    "locale": "fr"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/auth/forgot-password', [
    'headers' => [
        'Accept' => 'application/json',
    ],
    'json' => [
        'email' => 'claire.dumont@fiduciaire-dumont.be',
        'locale' => 'fr',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/forgot-password", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "email": "claire.dumont@fiduciaire-dumont.be",
      "locale": "fr"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/auth/forgot-password",
    headers={
        "Accept": "application/json",
    },
    json={
        "email": "claire.dumont@fiduciaire-dumont.be",
        "locale": "fr"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/auth/reset-passwordReset the password Public 10 / 1 min

With the token of the reset mail. Every device is signed out.

Public endpoint: no bearer token.

Rate limit: 10 requests per minute (429 beyond, see Retry-After).

Operation id auth.reset-password

Request body

application/json

Schema object
  • tokenstringrequired
  • emailstring <email>required
  • passwordstringrequired
    8 characters at least.
  • password_confirmationstringrequired
Example
{
    "token": "XBVD5O1L29HC",
    "email": "claire.dumont@fiduciaire-dumont.be",
    "password": "string",
    "password_confirmation": "string"
}

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema Message

Example
{
    "message": "Mot de passe modifié."
}
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/auth/reset-password" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "token": "XBVD5O1L29HC",
    "email": "claire.dumont@fiduciaire-dumont.be",
    "password": "string",
    "password_confirmation": "string"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/auth/reset-password', [
    'headers' => [
        'Accept' => 'application/json',
    ],
    'json' => [
        'token' => 'XBVD5O1L29HC',
        'email' => 'claire.dumont@fiduciaire-dumont.be',
        'password' => 'string',
        'password_confirmation' => 'string',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/reset-password", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "token": "XBVD5O1L29HC",
      "email": "claire.dumont@fiduciaire-dumont.be",
      "password": "string",
      "password_confirmation": "string"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/auth/reset-password",
    headers={
        "Accept": "application/json",
    },
    json={
        "token": "XBVD5O1L29HC",
        "email": "claire.dumont@fiduciaire-dumont.be",
        "password": "string",
        "password_confirmation": "string"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/auth/email/verify/{id}/{hash}Confirm an e-mail address Signed URL 30 / 1 min

Signed link of the verification mail. Opened in a browser it redirects to the app; with format=json it answers JSON.

Authorised by the signature of the URL (query parameters signature and expires), not by a bearer token. The URL is issued by another endpoint and expires.

Rate limit: 30 requests per minute (429 beyond, see Retry-After).

Operation id auth.email.verify

Path parameters

NameTypeDescription
id requiredintegerId of the record.
e.g. 42
hash requiredstringSHA-1 of the e-mail address being confirmed.
e.g. 5f2b8c…

Query parameters

NameTypeDescription
formatstringAnswer JSON instead of redirecting.
json

Common headers: signature expires

Responses

200Confirmed (format=json).

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • verifiedboolean
Example
{
    "verified": true
}
302Redirection to app.novafisko.com/email-verified.
Response headerDescription
LocationTarget of the redirection.
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Invalid or outdated link (format=json).

application/json

Schema object
  • verifiedboolean
    e.g. false
Example
{
    "verified": false
}
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/auth/email/verify/42/5f2b8c%E2%80%A6" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/auth/email/verify/42/5f2b8c%E2%80%A6', [
    'headers' => [
        'Accept' => 'application/json',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/email/verify/42/5f2b8c%E2%80%A6", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/auth/email/verify/42/5f2b8c%E2%80%A6",
    headers={
        "Accept": "application/json",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/auth/change-passwordChange the password Session token Not in demo 10 / 1 min

Refused for accounts whose password is managed by Novadesko.

Session token only: integration tokens are refused with 403 session_token_required.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 10 requests per minute (429 beyond, see Retry-After).

Operation id auth.change-password

Common headers: Accept-Language

Request body

application/json

Schema object
  • current_passwordstringrequired
  • passwordstringrequired
    8 characters at least, different from the current one.
  • password_confirmationstringrequired
Example
{
    "current_password": "string",
    "password": "string",
    "password_confirmation": "string"
}

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema Message

Example
{
    "message": "Mot de passe modifié."
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/auth/change-password" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "current_password": "string",
    "password": "string",
    "password_confirmation": "string"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/auth/change-password', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'current_password' => 'string',
        'password' => 'string',
        'password_confirmation' => 'string',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/change-password", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "current_password": "string",
      "password": "string",
      "password_confirmation": "string"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/auth/change-password",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "current_password": "string",
        "password": "string",
        "password_confirmation": "string"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/auth/change-emailChange the e-mail address Session token Not in demo 6 / 1 min

The current password is asked again; the new address replaces the old one once confirmed.

Session token only: integration tokens are refused with 403 session_token_required.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 6 requests per minute (429 beyond, see Retry-After).

Operation id auth.change-email

Common headers: Accept-Language

Request body

application/json

Schema object
  • emailstring <email>required
  • passwordstringrequired
Example
{
    "email": "claire.dumont@fiduciaire-dumont.be",
    "password": "string"
}

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • messagestring
  • pending_emailstring <email>
Example
{
    "message": "OK",
    "pending_email": "claire.dumont@fiduciaire-dumont.be"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/auth/change-email" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "claire.dumont@fiduciaire-dumont.be",
    "password": "string"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/auth/change-email', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'email' => 'claire.dumont@fiduciaire-dumont.be',
        'password' => 'string',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/change-email", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "email": "claire.dumont@fiduciaire-dumont.be",
      "password": "string"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/auth/change-email",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "email": "claire.dumont@fiduciaire-dumont.be",
        "password": "string"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/auth/email/resendSend the confirmation mail again Session token Not in demo 6 / 1 min

Session token only: integration tokens are refused with 403 session_token_required.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 6 requests per minute (429 beyond, see Retry-After).

Operation id auth.email.resend

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • sentboolean
  • messagestring
Example
{
    "sent": true,
    "message": "OK"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/auth/email/resend" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/auth/email/resend', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/email/resend", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/auth/email/resend",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/auth/notification-preferencesMail notification preferences read

Integration tokens need the read ability.

Operation id auth.notification-preferences

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • categoriesobject[]
    Properties
    • keystring
      account firm billing documents integrations platform
    • labelstring
      e.g. Documents
    • descriptionstring
    • lockedboolean
      Locked categories (account security) cannot be switched off.
    • enabledboolean
Example
{
    "categories": [
        {
            "key": "account",
            "label": "Documents",
            "description": "Description",
            "locked": true,
            "enabled": true
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/auth/notification-preferences" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/auth/notification-preferences', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/notification-preferences", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/auth/notification-preferences",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/auth/notification-preferencesUpdate the notification preferences Session token

Locked categories and unknown keys are ignored.

Session token only: integration tokens are refused with 403 session_token_required.

Operation id auth.notification-preferences.update

Common headers: Accept-Language

Request body

application/json

Schema object
  • prefsobjectrequired
    Category => enabled.
Example
{
    "prefs": {
        "documents": true,
        "billing": false
    }
}

Responses

200OK

application/json

Schema object
  • categoriesobject[]
    Properties
    • keystring
      account firm billing documents integrations platform
    • labelstring
      e.g. Documents
    • descriptionstring
    • lockedboolean
      Locked categories (account security) cannot be switched off.
    • enabledboolean
Example
{
    "categories": [
        {
            "key": "account",
            "label": "Documents",
            "description": "Description",
            "locked": true,
            "enabled": true
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/auth/notification-preferences" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "prefs": {
        "documents": true,
        "billing": false
    }
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/auth/notification-preferences', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'prefs' => [
            'documents' => true,
            'billing' => false,
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/notification-preferences", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "prefs": {
          "documents": true,
          "billing": false
      }
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/auth/notification-preferences",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "prefs": {
            "documents": True,
            "billing": False
        }
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Integration tokens

Long-lived tokens for server-to-server integrations, limited to the abilities read, write and sync.

GET/v1/auth/tokensList the integration tokens Session token

Integration tokens of the current user. The secret is never returned again.

Session token only: integration tokens are refused with 403 session_token_required.

Operation id auth.tokens.index

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
Example
{
    "data": [
        {
            "id": 57,
            "name": "ERP connector",
            "abilities": [
                "read"
            ],
            "created_at": "2026-03-15T09:41:00+00:00",
            "expires_at": "2026-03-15T09:41:00+00:00",
            "last_used_at": "2026-03-15T09:41:00+00:00"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/auth/tokens" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/auth/tokens', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/tokens", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/auth/tokens",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/auth/tokensCreate an integration token Session token Not in demo 20 / 1 min

Long-lived token for a server-to-server integration, limited to the chosen abilities:

  • read: every GET;
  • write: POST, PUT, PATCH and DELETE;
  • sync: the offline synchronisation endpoints (sync/bootstrap, sync/pull, sync/push, sync/status, sync/conflicts).

The token acts with the rights of the user who created it (same firms, same company files). The plain token is shown once: store it in a secret manager.

Session token only: integration tokens are refused with 403 session_token_required.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 20 requests per minute (429 beyond, see Retry-After).

Error codes (code):

  • token_limit_reached: 50 integration tokens per user at most

Operation id auth.tokens.store

Common headers: Accept-Language

Request body

application/json

Schema object
  • namestringrequired
    Label (100 characters max).
  • abilitiesstring[]required
    read write sync
  • expires_in_daysinteger | null
    1 to 730; null or absent = no expiry.
  • expires_atstring <date-time> | null
    Alternative to expires_in_days: a future date, 730 days ahead at most.
Example
{
    "name": "ERP connector",
    "abilities": [
        "read",
        "sync"
    ],
    "expires_in_days": 365
}

Responses

201Token created (data and integration_token are the same object)

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
Example
{
    "token": "57|Qm9x2kL8vT4nR7sW1pZ5cY3hJ6dF0gA9bE2uI4oK",
    "data": {
        "id": 57,
        "name": "ERP connector",
        "abilities": [
            "read",
            "sync"
        ],
        "created_at": "2026-10-05T09:12:44+00:00",
        "expires_at": "2027-10-05T09:12:44+00:00",
        "last_used_at": null
    },
    "integration_token": {
        "id": 57,
        "name": "ERP connector",
        "abilities": [
            "read",
            "sync"
        ],
        "created_at": "2026-10-05T09:12:44+00:00",
        "expires_at": "2027-10-05T09:12:44+00:00",
        "last_used_at": null
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/auth/tokens" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "ERP connector",
    "abilities": [
        "read",
        "sync"
    ],
    "expires_in_days": 365
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/auth/tokens', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'name' => 'ERP connector',
        'abilities' => [
            'read',
            'sync',
        ],
        'expires_in_days' => 365,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/tokens", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "name": "ERP connector",
      "abilities": [
          "read",
          "sync"
      ],
      "expires_in_days": 365
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/auth/tokens",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "name": "ERP connector",
        "abilities": [
            "read",
            "sync"
        ],
        "expires_in_days": 365
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/auth/tokens/{token}Revoke an integration token Session token Not in demo

Only the integration tokens of the current user; anything else answers 404.

Session token only: integration tokens are refused with 403 session_token_required.

Not available in demo mode: answers 403 demo_mode.

Operation id auth.tokens.destroy

Path parameters

NameTypeDescription
token requiredintegerId of the integration token.
e.g. 57

Common headers: Accept-Language

Responses

204Token revoked.

No body.

401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X DELETE "https://api.novafisko.com/v1/auth/tokens/57" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/auth/tokens/57', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/auth/tokens/57", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/auth/tokens/57",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Firms

Accounting firm: identity, team, assignment of the company files, activity.

GET/v1/firms/{firm}Firm, team and company files read

Any active member of the firm can read it.

Integration tokens need the read ability.

Operation id firms.show

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV

Common headers: Accept-Language

Responses

200OK

application/json

Schema Firm

Example
{
    "public_token": "NDTQVQU4AUAV",
    "name": "Fiduciaire Dumont & Associés",
    "enterprise_number": "0458662817",
    "vat_number": "BE0458662817",
    "itaa_number": "50.123.456",
    "itaa_status": "string",
    "itaa_quality": "string",
    "address": "Rue de Nimy 52",
    "postal_code": "7000",
    "city": "Mons",
    "website": "https://www.comptoir-montois.be",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "is_partner": true,
    "country_code": "BE",
    "locale": "fr",
    "email": "claire.dumont@fiduciaire-dumont.be",
    "phone": "+32 65 31 42 18",
    "source": "local",
    "synced_at": "2026-03-15T09:41:00+00:00",
    "can_manage": true,
    "members": [
        {
            "id": 12,
            "name": "Thomas Peeters",
            "email": "thomas.peeters@fiduciaire-dumont.be",
            "auth_source": "local",
            "locale": "fr",
            "role": "admin",
            "is_active": true,
            "all_companies": true,
            "companies": [
                {
                    "public_token": "XBVD5O1L29HC",
                    "name": "Le Comptoir Montois SRL",
                    "code": "COMPTOIR",
                    "role": "manager",
                    "is_active": true
                }
            ]
        }
    ],
    "companies": [
        {
            "public_token": "XBVD5O1L29HC",
            "name": "Le Comptoir Montois SRL",
            "code": "COMPTOIR",
            "icon_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "members": [
                {
                    "id": 42,
                    "name": "Thomas Peeters",
                    "email": "claire.dumont@fiduciaire-dumont.be",
                    "role": "manager",
                    "is_active": true
                }
            ]
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/firms/{firm}Update the identity of the firm write Not in demo

Admins and managers of the firm.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Operation id firms.update

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV

Common headers: Accept-Language

Request body

application/json

Schema object
  • namestring
    200 characters max.
  • enterprise_numberstring | null
  • vat_numberstring | null
  • itaa_numberstring | null
  • emailstring <email> | null
  • phonestring | null
  • websitestring | null
  • addressstring | null
  • postal_codestring | null
  • citystring | null
  • country_codestring
    ISO 3166-1 alpha-2.
  • localestring
    fr nl en de
Example
{
    "phone": "+32 65 31 42 18",
    "website": "https://www.fiduciaire-dumont.be"
}

Responses

200OK

application/json

Schema Firm

Example
{
    "public_token": "NDTQVQU4AUAV",
    "name": "Fiduciaire Dumont & Associés",
    "enterprise_number": "0458662817",
    "vat_number": "BE0458662817",
    "itaa_number": "50.123.456",
    "itaa_status": "string",
    "itaa_quality": "string",
    "address": "Rue de Nimy 52",
    "postal_code": "7000",
    "city": "Mons",
    "website": "https://www.comptoir-montois.be",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "is_partner": true,
    "country_code": "BE",
    "locale": "fr",
    "email": "claire.dumont@fiduciaire-dumont.be",
    "phone": "+32 65 31 42 18",
    "source": "local",
    "synced_at": "2026-03-15T09:41:00+00:00",
    "can_manage": true,
    "members": [
        {
            "id": 12,
            "name": "Thomas Peeters",
            "email": "thomas.peeters@fiduciaire-dumont.be",
            "auth_source": "local",
            "locale": "fr",
            "role": "admin",
            "is_active": true,
            "all_companies": true,
            "companies": [
                {
                    "public_token": "XBVD5O1L29HC",
                    "name": "Le Comptoir Montois SRL",
                    "code": "COMPTOIR",
                    "role": "manager",
                    "is_active": true
                }
            ]
        }
    ],
    "companies": [
        {
            "public_token": "XBVD5O1L29HC",
            "name": "Le Comptoir Montois SRL",
            "code": "COMPTOIR",
            "icon_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "members": [
                {
                    "id": 42,
                    "name": "Thomas Peeters",
                    "email": "claire.dumont@fiduciaire-dumont.be",
                    "role": "manager",
                    "is_active": true
                }
            ]
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "phone": "+32 65 31 42 18",
    "website": "https://www.fiduciaire-dumont.be"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'phone' => '+32 65 31 42 18',
        'website' => 'https://www.fiduciaire-dumont.be',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "phone": "+32 65 31 42 18",
      "website": "https://www.fiduciaire-dumont.be"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "phone": "+32 65 31 42 18",
        "website": "https://www.fiduciaire-dumont.be"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/firms/{firm}/syncResynchronise the firm from Novadesko write Not in demo 6 / 1 min

Identity, members and company files of a firm linked to Novadesko. 422 when the firm is not linked, 503 when Novadesko does not answer.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 6 requests per minute (429 beyond, see Retry-After).

Operation id firms.sync

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema Firm

Example
{
    "public_token": "NDTQVQU4AUAV",
    "name": "Fiduciaire Dumont & Associés",
    "enterprise_number": "0458662817",
    "vat_number": "BE0458662817",
    "itaa_number": "50.123.456",
    "itaa_status": "string",
    "itaa_quality": "string",
    "address": "Rue de Nimy 52",
    "postal_code": "7000",
    "city": "Mons",
    "website": "https://www.comptoir-montois.be",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "is_partner": true,
    "country_code": "BE",
    "locale": "fr",
    "email": "claire.dumont@fiduciaire-dumont.be",
    "phone": "+32 65 31 42 18",
    "source": "local",
    "synced_at": "2026-03-15T09:41:00+00:00",
    "can_manage": true,
    "members": [
        {
            "id": 12,
            "name": "Thomas Peeters",
            "email": "thomas.peeters@fiduciaire-dumont.be",
            "auth_source": "local",
            "locale": "fr",
            "role": "admin",
            "is_active": true,
            "all_companies": true,
            "companies": [
                {
                    "public_token": "XBVD5O1L29HC",
                    "name": "Le Comptoir Montois SRL",
                    "code": "COMPTOIR",
                    "role": "manager",
                    "is_active": true
                }
            ]
        }
    ],
    "companies": [
        {
            "public_token": "XBVD5O1L29HC",
            "name": "Le Comptoir Montois SRL",
            "code": "COMPTOIR",
            "icon_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "members": [
                {
                    "id": 42,
                    "name": "Thomas Peeters",
                    "email": "claire.dumont@fiduciaire-dumont.be",
                    "role": "manager",
                    "is_active": true
                }
            ]
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error
503Temporarily unavailable (maintenance, external provider down). A 503 always carries a code. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/sync" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/sync', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/sync", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/sync",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/firms/{firm}/membersAdd a member write Not in demo

Attaches an existing user (by e-mail) or creates the account (password required then). 201 when the account was created, 200 when an existing user was attached.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Error codes (code):

  • user_limit_reached: the licence does not allow one more user

Operation id firms.members.store

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV

Common headers: Accept-Language

Request body

application/json

Schema object
  • emailstring <email>required
  • namestring
    Required for a new account.
  • passwordstring | null
    8 characters at least; required for a new account.
  • rolestringrequired
    admin manager encoder reviewer
  • localestring
    fr nl en de
  • company_tokensstring[]
Example
{
    "email": "thomas.peeters@fiduciaire-dumont.be",
    "name": "Thomas Peeters",
    "password": "S3cure-Pass!",
    "role": "encoder",
    "company_tokens": [
        "XBVD5O1L29HC"
    ]
}

Responses

200Existing user attached

application/json

Schema FirmMember

Example
{
    "id": 12,
    "name": "Thomas Peeters",
    "email": "thomas.peeters@fiduciaire-dumont.be",
    "auth_source": "local",
    "locale": "fr",
    "role": "admin",
    "is_active": true,
    "all_companies": true,
    "companies": [
        {
            "public_token": "XBVD5O1L29HC",
            "name": "Le Comptoir Montois SRL",
            "code": "COMPTOIR",
            "role": "manager",
            "is_active": true
        }
    ]
}
201Account created and attached

application/json

Schema FirmMember

Example
{
    "id": 12,
    "name": "Thomas Peeters",
    "email": "thomas.peeters@fiduciaire-dumont.be",
    "auth_source": "local",
    "locale": "fr",
    "role": "admin",
    "is_active": true,
    "all_companies": true,
    "companies": [
        {
            "public_token": "XBVD5O1L29HC",
            "name": "Le Comptoir Montois SRL",
            "code": "COMPTOIR",
            "role": "manager",
            "is_active": true
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "thomas.peeters@fiduciaire-dumont.be",
    "name": "Thomas Peeters",
    "password": "S3cure-Pass!",
    "role": "encoder",
    "company_tokens": [
        "XBVD5O1L29HC"
    ]
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'email' => 'thomas.peeters@fiduciaire-dumont.be',
        'name' => 'Thomas Peeters',
        'password' => 'S3cure-Pass!',
        'role' => 'encoder',
        'company_tokens' => [
            'XBVD5O1L29HC',
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "email": "thomas.peeters@fiduciaire-dumont.be",
      "name": "Thomas Peeters",
      "password": "S3cure-Pass!",
      "role": "encoder",
      "company_tokens": [
          "XBVD5O1L29HC"
      ]
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "email": "thomas.peeters@fiduciaire-dumont.be",
        "name": "Thomas Peeters",
        "password": "S3cure-Pass!",
        "role": "encoder",
        "company_tokens": [
            "XBVD5O1L29HC"
        ]
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/firms/{firm}/members/{user}Update a member write Not in demo

Role, activation, name, password. The last active admin cannot lose its role.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Operation id firms.members.update

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV
user requiredintegerId of the user (member of the firm).
e.g. 12

Common headers: Accept-Language

Request body

application/json

Schema object
  • rolestring
    admin manager encoder reviewer
  • is_activeboolean
  • namestring
  • passwordstring | null
Example
{
    "role": "manager"
}

Responses

200OK

application/json

Schema FirmMember

Example
{
    "id": 12,
    "name": "Thomas Peeters",
    "email": "thomas.peeters@fiduciaire-dumont.be",
    "auth_source": "local",
    "locale": "fr",
    "role": "admin",
    "is_active": true,
    "all_companies": true,
    "companies": [
        {
            "public_token": "XBVD5O1L29HC",
            "name": "Le Comptoir Montois SRL",
            "code": "COMPTOIR",
            "role": "manager",
            "is_active": true
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members/12" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "role": "manager"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members/12', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'role' => 'manager',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members/12", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "role": "manager"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members/12",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "role": "manager"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/firms/{firm}/members/{user}Remove a member write Not in demo

Detaches the user from the firm and from its company files. The user account itself is kept.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Operation id firms.members.destroy

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV
user requiredintegerId of the user (member of the firm).
e.g. 12

Common headers: Accept-Language

Responses

204Done, no body.

No body.

401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X DELETE "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members/12" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members/12', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members/12", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members/12",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PUT/v1/firms/{firm}/members/{user}/companiesReplace the company files of a member write Not in demo

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Operation id firms.members.companies

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV
user requiredintegerId of the user (member of the firm).
e.g. 12

Common headers: Accept-Language

Request body

application/json

Schema object
  • company_tokensstring[]required
  • rolestring
    manager encoder reviewer
Example
{
    "company_tokens": [
        "XBVD5O1L29HC",
        "K7MPL2QX9ZTA"
    ],
    "role": "encoder"
}

Responses

200OK

application/json

Schema FirmMember

Example
{
    "id": 12,
    "name": "Thomas Peeters",
    "email": "thomas.peeters@fiduciaire-dumont.be",
    "auth_source": "local",
    "locale": "fr",
    "role": "admin",
    "is_active": true,
    "all_companies": true,
    "companies": [
        {
            "public_token": "XBVD5O1L29HC",
            "name": "Le Comptoir Montois SRL",
            "code": "COMPTOIR",
            "role": "manager",
            "is_active": true
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PUT "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members/12/companies" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "company_tokens": [
        "XBVD5O1L29HC",
        "K7MPL2QX9ZTA"
    ],
    "role": "encoder"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PUT', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members/12/companies', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'company_tokens' => [
            'XBVD5O1L29HC',
            'K7MPL2QX9ZTA',
        ],
        'role' => 'encoder',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members/12/companies", {
  method: "PUT",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "company_tokens": [
          "XBVD5O1L29HC",
          "K7MPL2QX9ZTA"
      ],
      "role": "encoder"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.put(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/members/12/companies",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "company_tokens": [
            "XBVD5O1L29HC",
            "K7MPL2QX9ZTA"
        ],
        "role": "encoder"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PUT/v1/firms/{firm}/companies/{company}/membersReplace the members of a company file write Not in demo

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Operation id firms.companies.members

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Request body

application/json

Schema object
  • membersobject[]required
    Properties
    • user_idintegerrequired
    • rolestring
      manager encoder reviewer
Example
{
    "members": [
        {
            "user_id": 12,
            "role": "manager"
        },
        {
            "user_id": 15,
            "role": "encoder"
        }
    ]
}

Responses

200OK

application/json

Schema Firm

Example
{
    "public_token": "NDTQVQU4AUAV",
    "name": "Fiduciaire Dumont & Associés",
    "enterprise_number": "0458662817",
    "vat_number": "BE0458662817",
    "itaa_number": "50.123.456",
    "itaa_status": "string",
    "itaa_quality": "string",
    "address": "Rue de Nimy 52",
    "postal_code": "7000",
    "city": "Mons",
    "website": "https://www.comptoir-montois.be",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "is_partner": true,
    "country_code": "BE",
    "locale": "fr",
    "email": "claire.dumont@fiduciaire-dumont.be",
    "phone": "+32 65 31 42 18",
    "source": "local",
    "synced_at": "2026-03-15T09:41:00+00:00",
    "can_manage": true,
    "members": [
        {
            "id": 12,
            "name": "Thomas Peeters",
            "email": "thomas.peeters@fiduciaire-dumont.be",
            "auth_source": "local",
            "locale": "fr",
            "role": "admin",
            "is_active": true,
            "all_companies": true,
            "companies": [
                {
                    "public_token": "XBVD5O1L29HC",
                    "name": "Le Comptoir Montois SRL",
                    "code": "COMPTOIR",
                    "role": "manager",
                    "is_active": true
                }
            ]
        }
    ],
    "companies": [
        {
            "public_token": "XBVD5O1L29HC",
            "name": "Le Comptoir Montois SRL",
            "code": "COMPTOIR",
            "icon_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "members": [
                {
                    "id": 42,
                    "name": "Thomas Peeters",
                    "email": "claire.dumont@fiduciaire-dumont.be",
                    "role": "manager",
                    "is_active": true
                }
            ]
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PUT "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/companies/XBVD5O1L29HC/members" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "members": [
        {
            "user_id": 12,
            "role": "manager"
        },
        {
            "user_id": 15,
            "role": "encoder"
        }
    ]
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PUT', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/companies/XBVD5O1L29HC/members', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'members' => [
            [
                'user_id' => 12,
                'role' => 'manager',
            ],
            [
                'user_id' => 15,
                'role' => 'encoder',
            ],
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/companies/XBVD5O1L29HC/members", {
  method: "PUT",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "members": [
          {
              "user_id": 12,
              "role": "manager"
          },
          {
              "user_id": 15,
              "role": "encoder"
          }
      ]
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.put(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/companies/XBVD5O1L29HC/members",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "members": [
            {
                "user_id": 12,
                "role": "manager"
            },
            {
                "user_id": 15,
                "role": "encoder"
            }
        ]
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/firms/{firm}/activityActivity of the firm read

Audit trail and history merged, newest first, for every company file of the firm. Admins and managers only (404 otherwise).

Integration tokens need the read ability.

Operation id firms.activity

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV

Query parameters

NameTypeDescription
companystringRestrict to one company file.
user_idinteger
fromstring <date>
tostring <date>
typestringAction or subject type.
sourcestring
audit revision
qstring
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200OK

application/json

Schema ActivityFeed

Example
{
    "data": [
        {
            "source": "audit",
            "at": "2026-03-15T09:41:00+00:00",
            "recorded_at": "2026-03-15T09:41:00+00:00",
            "user": null,
            "action": "entry.posted",
            "action_label": "Écriture validée",
            "subject_type": "string",
            "subject_id": 42,
            "subject_label": "string",
            "origin": "string",
            "device_name": "MacBook de Claire",
            "revision_id": 42,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "company_id": 7,
            "changed_fields": [
                "string"
            ],
            "company": {
                "token": "XBVD5O1L29HC",
                "name": "Le Comptoir Montois SRL"
            }
        }
    ],
    "current_page": 1,
    "per_page": 50,
    "has_more": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/activity" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/activity', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/activity", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/activity",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/firms/{firm}/files/viewSigned relay of a firm file Signed URL 120 / 1 min

Serves the logo of a firm stored on Novadesko with CORS headers. The signed URL is found in logo_url of the firm payload.

Authorised by the signature of the URL (query parameters signature and expires), not by a bearer token. The URL is issued by another endpoint and expires.

Rate limit: 120 requests per minute (429 beyond, see Retry-After).

Operation id firms.files.view

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV

Query parameters

NameTypeDescription
url requiredstring <uri>Relayed file.

Common headers: signature expires

Responses

200The file, inline.

Response headers Content-Disposition X-RateLimit-Limit X-RateLimit-Remaining

image/png

image/jpeg

image/webp

application/pdf

403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/files/view?url=https%3A%2F%2Fapi.novafisko.com%2Fv1%2Fcompanies%2FXBVD5O1L29HC" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/files/view', [
    'headers' => [
        'Accept' => 'application/json',
    ],
    'query' => [
        'url' => 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/files/view?url=https%3A%2F%2Fapi.novafisko.com%2Fv1%2Fcompanies%2FXBVD5O1L29HC", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/files/view",
    headers={
        "Accept": "application/json",
    },
    params={
        "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Licence & pricing

Licence of a firm, activation keys, public price list and simulator.

GET/v1/firms/{firm}/licenceLicence of the firm read

Plan, status, usage of the month, estimate of the next invoice, entitlements and limits.

Integration tokens need the read ability.

Operation id firms.licence

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV

Query parameters

NameTypeDescription
langstring
fr nl en de

Common headers: Accept-Language

Responses

200OK

application/json

Schema Licence

Example
{
    "status": "none",
    "subscription": {},
    "plan": {},
    "usage": {
        "month": "2026-10",
        "companies": 25,
        "users": 4,
        "bank_accounts": 31,
        "rows": [
            {
                "company_id": 7,
                "token": "XBVD5O1L29HC",
                "name": "Le Comptoir Montois SRL",
                "code": "COMPTOIR",
                "bank_accounts": 1,
                "status": "active",
                "activated_at": "2026-03-15T09:41:00+00:00",
                "deactivated_at": "2026-03-15T09:41:00+00:00"
            }
        ],
        "max_companies": 1,
        "over_limit": false,
        "suggestion": "string"
    },
    "estimate": {},
    "companies_detail": [
        {
            "company_id": 7,
            "name": "Le Comptoir Montois SRL",
            "public_token": "XBVD5O1L29HC",
            "status": "active",
            "activated_at": "2026-03-15T09:41:00+00:00",
            "deactivated_at": "2026-03-15T09:41:00+00:00",
            "billable": true
        }
    ],
    "next_month_preview": {
        "companies": 25,
        "total": 121.5
    },
    "over_limit": false,
    "over_limit_firm_total": 12.5,
    "entitlements": {
        "accounting": true,
        "peppol": true,
        "coda": true,
        "client_portal": true,
        "client_invoicing": true,
        "document_import": true
    },
    "limits": {
        "max_users": 1,
        "max_companies": 1,
        "users_count": 4,
        "companies_count": 25
    },
    "expires_at": "2026-03-15T09:41:00+00:00",
    "warning": "string",
    "activation": {},
    "statements": [
        {}
    ],
    "options_available": [
        {
            "code": "client_portal",
            "name": "Portail client",
            "price_monthly": 6.9,
            "unit": "client"
        }
    ],
    "can_manage": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/licence" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/licence', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/licence", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/licence",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/firms/{firm}/licence/activateActivate a licence key Session token Not in demo 10 / 1 min

Creates or replaces the subscription of the firm.

Session token only: integration tokens are refused with 403 session_token_required.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 10 requests per minute (429 beyond, see Retry-After).

Error codes (code):

  • invalid_key: unknown key
  • expired_key: key past its validity
  • exhausted_key: every activation of the key is used
  • key_reserved: key reserved for another firm
  • already_active: the key is already active on this firm

Operation id firms.licence.activate

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV

Common headers: Accept-Language

Request body

application/json

Schema object
  • keystringrequired
    Licence key.
    e.g. NVFK-7Q2M-X4TA-9LDP
Example
{
    "key": "NVFK-7Q2M-X4TA-9LDP"
}

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema Licence

Example
{
    "status": "none",
    "subscription": {},
    "plan": {},
    "usage": {
        "month": "2026-10",
        "companies": 25,
        "users": 4,
        "bank_accounts": 31,
        "rows": [
            {
                "company_id": 7,
                "token": "XBVD5O1L29HC",
                "name": "Le Comptoir Montois SRL",
                "code": "COMPTOIR",
                "bank_accounts": 1,
                "status": "active",
                "activated_at": "2026-03-15T09:41:00+00:00",
                "deactivated_at": "2026-03-15T09:41:00+00:00"
            }
        ],
        "max_companies": 1,
        "over_limit": false,
        "suggestion": "string"
    },
    "estimate": {},
    "companies_detail": [
        {
            "company_id": 7,
            "name": "Le Comptoir Montois SRL",
            "public_token": "XBVD5O1L29HC",
            "status": "active",
            "activated_at": "2026-03-15T09:41:00+00:00",
            "deactivated_at": "2026-03-15T09:41:00+00:00",
            "billable": true
        }
    ],
    "next_month_preview": {
        "companies": 25,
        "total": 121.5
    },
    "over_limit": false,
    "over_limit_firm_total": 12.5,
    "entitlements": {
        "accounting": true,
        "peppol": true,
        "coda": true,
        "client_portal": true,
        "client_invoicing": true,
        "document_import": true
    },
    "limits": {
        "max_users": 1,
        "max_companies": 1,
        "users_count": 4,
        "companies_count": 25
    },
    "expires_at": "2026-03-15T09:41:00+00:00",
    "warning": "string",
    "activation": {},
    "statements": [
        {}
    ],
    "options_available": [
        {
            "code": "client_portal",
            "name": "Portail client",
            "price_monthly": 6.9,
            "unit": "client"
        }
    ],
    "can_manage": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/licence/activate" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "key": "NVFK-7Q2M-X4TA-9LDP"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/licence/activate', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'key' => 'NVFK-7Q2M-X4TA-9LDP',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/licence/activate", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "key": "NVFK-7Q2M-X4TA-9LDP"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/licence/activate",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "key": "NVFK-7Q2M-X4TA-9LDP"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/firms/{firm}/licence/activationRelease the licence key Session token Not in demo

The subscription that depends on the key is cancelled.

Session token only: integration tokens are refused with 403 session_token_required.

Not available in demo mode: answers 403 demo_mode.

Operation id firms.licence.release

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV

Common headers: Accept-Language

Responses

200OK

application/json

Schema Licence

Example
{
    "status": "none",
    "subscription": {},
    "plan": {},
    "usage": {
        "month": "2026-10",
        "companies": 25,
        "users": 4,
        "bank_accounts": 31,
        "rows": [
            {
                "company_id": 7,
                "token": "XBVD5O1L29HC",
                "name": "Le Comptoir Montois SRL",
                "code": "COMPTOIR",
                "bank_accounts": 1,
                "status": "active",
                "activated_at": "2026-03-15T09:41:00+00:00",
                "deactivated_at": "2026-03-15T09:41:00+00:00"
            }
        ],
        "max_companies": 1,
        "over_limit": false,
        "suggestion": "string"
    },
    "estimate": {},
    "companies_detail": [
        {
            "company_id": 7,
            "name": "Le Comptoir Montois SRL",
            "public_token": "XBVD5O1L29HC",
            "status": "active",
            "activated_at": "2026-03-15T09:41:00+00:00",
            "deactivated_at": "2026-03-15T09:41:00+00:00",
            "billable": true
        }
    ],
    "next_month_preview": {
        "companies": 25,
        "total": 121.5
    },
    "over_limit": false,
    "over_limit_firm_total": 12.5,
    "entitlements": {
        "accounting": true,
        "peppol": true,
        "coda": true,
        "client_portal": true,
        "client_invoicing": true,
        "document_import": true
    },
    "limits": {
        "max_users": 1,
        "max_companies": 1,
        "users_count": 4,
        "companies_count": 25
    },
    "expires_at": "2026-03-15T09:41:00+00:00",
    "warning": "string",
    "activation": {},
    "statements": [
        {}
    ],
    "options_available": [
        {
            "code": "client_portal",
            "name": "Portail client",
            "price_monthly": 6.9,
            "unit": "client"
        }
    ],
    "can_manage": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X DELETE "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/licence/activation" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/licence/activation', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/licence/activation", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/licence/activation",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/pricingPublic price list Public 120 / 1 min

Plans, tiers and options, excl. VAT, per month. Cached five minutes.

Public endpoint: no bearer token.

Rate limit: 120 requests per minute (429 beyond, see Retry-After).

Operation id pricing

Query parameters

NameTypeDescription
localestring
fr nl en de

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema PricingGrid

Example
{
    "currency": "EUR",
    "vat_included": false,
    "plans": [
        {
            "code": "starter",
            "name": "Firm",
            "kind": "starter",
            "base_price_monthly": 49,
            "per_company": 2.9,
            "tiers": [
                {
                    "up_to": 100,
                    "price": 2.9
                }
            ],
            "max_companies": 1,
            "peppol_fair_use_per_company": 100,
            "annual_discount_pct": 10,
            "included": [
                "Unlimited users"
            ]
        }
    ],
    "options": [
        {
            "code": "client_portal",
            "name": "Client portal",
            "price_monthly": 6.9,
            "unit": "client"
        }
    ],
    "annual_discount_pct": 10,
    "winauditor": {},
    "pilot": {
        "free_months": 3,
        "max_firms": 20
    }
}
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/pricing" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/pricing', [
    'headers' => [
        'Accept' => 'application/json',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/pricing", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/pricing",
    headers={
        "Accept": "application/json",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/pricing/simulatePrice simulator Public 120 / 1 min

Public endpoint: no bearer token.

Rate limit: 120 requests per minute (429 beyond, see Retry-After).

Operation id pricing.simulate

Query parameters

NameTypeDescription
companies requiredintegerNumber of company files.
e.g. 25
client_portalintegerClients with the portal option.
client_invoicingintegerClients with the invoicing option.
yearlystringYearly billing.
0 1 true false
localestring
fr nl en de

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema PricingSimulation

Example
{
    "companies": 25,
    "yearly": false,
    "starter": {},
    "firm": {
        "plan": "firm",
        "billing_interval": "monthly",
        "companies": 25,
        "base": 49,
        "companies_breakdown": [
            {
                "from": 1,
                "to": 100,
                "quantity": 25,
                "unit_price": 2.9,
                "total": 72.5
            }
        ],
        "companies_total": 72.5,
        "options": [
            {}
        ],
        "options_total": 0,
        "pilot_discount": 0,
        "annual_discount_pct": 0,
        "annual_discount": 0,
        "discount": 0,
        "total": 121.5,
        "yearly_total": 1458,
        "name": "Firm",
        "saving_vs_winauditor": 36,
        "saving_pct": 22.9
    },
    "winauditor": 157.5,
    "cheapest": "starter"
}
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/pricing/simulate?companies=25" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/pricing/simulate', [
    'headers' => [
        'Accept' => 'application/json',
    ],
    'query' => [
        'companies' => '25',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/pricing/simulate?companies=25", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/pricing/simulate",
    headers={
        "Accept": "application/json",
    },
    params={
        "companies": "25"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Companies

Company files (dossiers): creation with accounting set-up, identity, settings, integrity.

GET/v1/companiesList the company files read

Every company file the user can open: all files of the firms it administers or manages, plus the files it is assigned to.

Integration tokens need the read ability.

Operation id companies.index

Common headers: Accept-Language

Responses

200OK

application/json

Schema Company[]

Array of Company

Example
[
    {
        "id": 7,
        "public_token": "XBVD5O1L29HC",
        "firm_id": 3,
        "code": "COMPTOIR",
        "name": "Le Comptoir Montois SRL",
        "legal_form": "SRL",
        "legal_form_code": "610",
        "enterprise_number": "0477472701",
        "vat_number": "BE0477472701",
        "country_pack": "BE",
        "vat_regime": "monthly",
        "currency": "EUR",
        "locale": "fr",
        "address": "Grand-Place 14, 7000 Mons",
        "street": "Grand-Place",
        "house_number": "14",
        "box": "string",
        "postal_code": "7000",
        "city": "Mons",
        "country": "BE",
        "latitude": "50.4541000",
        "longitude": "3.9523000",
        "nace_codes": [
            {
                "code": "56111",
                "classification": "MAIN"
            }
        ],
        "main_nace_code": "56111",
        "company_sheet_at": "2026-03-15T09:41:00+00:00",
        "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "icon_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "fiscal_year_start": "2026-03-15",
        "fiscal_year_end": "2026-03-15",
        "settings": {
            "vat": {
                "administration_cell": "string",
                "structured_communication": "000000000101",
                "directorate_number": "string",
                "office_number": "string",
                "declarant": {
                    "applicable": false,
                    "company_name": "string",
                    "signatory_1": "string",
                    "signatory_1_title": "string",
                    "signatory_2": "string",
                    "signatory_2_title": "string",
                    "phone": "+32 65 31 42 18",
                    "fax": "string",
                    "email": "claire.dumont@fiduciaire-dumont.be",
                    "language": "fr"
                },
                "sender_281_50": {
                    "name": "Le Comptoir Montois SRL",
                    "enterprise_number": "0477472701",
                    "address": "Grand-Place 14",
                    "phone": "+32 65 31 42 18",
                    "email": "claire.dumont@fiduciaire-dumont.be"
                },
                "filer": {
                    "quality": "company",
                    "name": "Le Comptoir Montois SRL",
                    "enterprise_number": "0477472701",
                    "phone": "+32 65 31 42 18",
                    "email": "claire.dumont@fiduciaire-dumont.be"
                }
            },
            "legal": {
                "rpm_district": "Hainaut, division Mons"
            },
            "annual_accounts": {
                "scheme": "abbreviated",
                "general_meeting_date": "2026-03-15",
                "directors": "string",
                "valuation_rules": "string"
            },
            "auto_entries": {
                "vat": {
                    "payable_account": "451000",
                    "receivable_account": "411000",
                    "correction_payable_account": "string",
                    "correction_receivable_account": "string",
                    "journal_id": 3
                },
                "invoices_to_receive": {
                    "supplier_account": "444000",
                    "customer_account": "404000",
                    "journal_id": 3
                },
                "reconciliation_difference": {
                    "expense_account": "657000",
                    "income_account": "757000",
                    "max_amount": 1
                },
                "transfers": {
                    "transit_account": "580000",
                    "journal_id": 3
                }
            },
            "history": {
                "trash_retention_days": 90
            }
        },
        "is_active": true,
        "is_demo": false,
        "source": "manual",
        "external_id": "string",
        "synced_at": "2026-03-15T09:41:00+00:00",
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal_entries_count": 1284,
        "firm": {
            "id": 3,
            "public_token": "NDTQVQU4AUAV",
            "name": "Fiduciaire Dumont & Associés"
        },
        "fiscal_years": [
            {
                "id": 2,
                "company_id": 7,
                "code": "2026",
                "starts_on": "2026-01-01T00:00:00.000000Z",
                "ends_on": "2026-12-31T00:00:00.000000Z",
                "is_closed": false,
                "closed_at": "2026-03-15T09:41:00+00:00",
                "closed_by": 1,
                "created_at": "2026-03-15T09:41:00+00:00",
                "updated_at": "2026-03-15T09:41:00+00:00",
                "lock_version": 3,
                "version": 3,
                "periods": [
                    {}
                ]
            }
        ],
        "journals": [
            {
                "id": 3,
                "company_id": 7,
                "code": "VEN",
                "label": "Ventes",
                "type": "purchase",
                "control_account_id": 42,
                "iban": "BE68539007547034",
                "bic": "GEBABEBB",
                "last_number": 412,
                "is_active": true,
                "is_default": true,
                "description": "Description",
                "created_at": "2026-03-15T09:41:00+00:00",
                "updated_at": "2026-03-15T09:41:00+00:00",
                "lock_version": 3,
                "version": 3,
                "deleted_at": "2026-03-15T09:41:00+00:00",
                "deleted_by": 1,
                "entries_count": 412,
                "control_account": null,
                "rules": [
                    {}
                ]
            }
        ]
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companiesCreate a company file write Not in demo

Creates the file and initialises its accounting: chart of accounts of the country pack (PCMN for BE), VAT codes, journals (ACH, NCA, VEN, NCV, OD, CAI and one financial journal per bank) and the first fiscal year with its periods. firm is optional when the user manages exactly one firm; without a firm the file is standalone.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Error codes (code):

  • company_limit_reached: the licence or the plan does not allow one more company file

Operation id companies.store

Common headers: Accept-Language

Request body

application/json

Schema object
  • firmstring | null
    Firm that manages the file.
  • country_packstring
    BE FR LU
  • codestring | null
    Short code, letters, digits, dash, underscore (20 max).
  • namestringrequired
    200 characters max.
  • enterprise_numberstring | null
    Checked against the country rules (BE: modulo 97).
  • vat_numberstring | null
    Format and check digits validated per country.
  • legal_formstring | null
  • legal_form_codestring | null
    Code of GET /v1/reference/legal-forms.
  • addressstring | null
  • logo_urlstring <uri> | null
  • vat_regimestring
    monthly quarterly franchise exempt unit
  • localestring
    fr nl en de
  • streetstring | null
  • house_numberstring | null
  • boxstring | null
  • postal_codestring | null
  • citystring | null
  • countrystring | null
    ISO 3166-1 alpha-2.
  • latitudenumber | null
  • longitudenumber | null
  • nace_codesobject[]
    Properties
    • codestringrequired
    • classificationstring
      MAIN SECO ANCI
  • main_nace_codestring | null
  • fiscal_yearobject
    Properties
    • codestring
      10 characters max.
    • starts_onstring <date>required
    • ends_onstring <date>required
  • banksobject[]
    Properties
    • codestringrequired
      Journal code, 6 characters max.
    • labelstringrequired
    • ibanstring | null
Example
{
    "firm": "NDTQVQU4AUAV",
    "country_pack": "BE",
    "code": "COMPTOIR",
    "name": "Le Comptoir Montois SRL",
    "enterprise_number": "0477.472.701",
    "legal_form_code": "610",
    "vat_regime": "quarterly",
    "street": "Grand-Place",
    "house_number": "14",
    "postal_code": "7000",
    "city": "Mons",
    "fiscal_year": {
        "code": "2026",
        "starts_on": "2026-01-01",
        "ends_on": "2026-12-31"
    },
    "banks": [
        {
            "code": "BNP",
            "label": "BNP Paribas Fortis",
            "iban": "BE68 5390 0754 7034"
        }
    ]
}

Responses

201Created

application/json

Schema Company

Example
{
    "id": 7,
    "public_token": "XBVD5O1L29HC",
    "firm_id": 3,
    "code": "COMPTOIR",
    "name": "Le Comptoir Montois SRL",
    "legal_form": "SRL",
    "legal_form_code": "610",
    "enterprise_number": "0477472701",
    "vat_number": "BE0477472701",
    "country_pack": "BE",
    "vat_regime": "monthly",
    "currency": "EUR",
    "locale": "fr",
    "address": "Grand-Place 14, 7000 Mons",
    "street": "Grand-Place",
    "house_number": "14",
    "box": "string",
    "postal_code": "7000",
    "city": "Mons",
    "country": "BE",
    "latitude": "50.4541000",
    "longitude": "3.9523000",
    "nace_codes": [
        {
            "code": "56111",
            "classification": "MAIN"
        }
    ],
    "main_nace_code": "56111",
    "company_sheet_at": "2026-03-15T09:41:00+00:00",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "icon_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "fiscal_year_start": "2026-03-15",
    "fiscal_year_end": "2026-03-15",
    "settings": {
        "vat": {
            "administration_cell": "string",
            "structured_communication": "000000000101",
            "directorate_number": "string",
            "office_number": "string",
            "declarant": {
                "applicable": false,
                "company_name": "string",
                "signatory_1": "string",
                "signatory_1_title": "string",
                "signatory_2": "string",
                "signatory_2_title": "string",
                "phone": "+32 65 31 42 18",
                "fax": "string",
                "email": "claire.dumont@fiduciaire-dumont.be",
                "language": "fr"
            },
            "sender_281_50": {
                "name": "Le Comptoir Montois SRL",
                "enterprise_number": "0477472701",
                "address": "Grand-Place 14",
                "phone": "+32 65 31 42 18",
                "email": "claire.dumont@fiduciaire-dumont.be"
            },
            "filer": {
                "quality": "company",
                "name": "Le Comptoir Montois SRL",
                "enterprise_number": "0477472701",
                "phone": "+32 65 31 42 18",
                "email": "claire.dumont@fiduciaire-dumont.be"
            }
        },
        "legal": {
            "rpm_district": "Hainaut, division Mons"
        },
        "annual_accounts": {
            "scheme": "abbreviated",
            "general_meeting_date": "2026-03-15",
            "directors": "string",
            "valuation_rules": "string"
        },
        "auto_entries": {
            "vat": {
                "payable_account": "451000",
                "receivable_account": "411000",
                "correction_payable_account": "string",
                "correction_receivable_account": "string",
                "journal_id": 3
            },
            "invoices_to_receive": {
                "supplier_account": "444000",
                "customer_account": "404000",
                "journal_id": 3
            },
            "reconciliation_difference": {
                "expense_account": "657000",
                "income_account": "757000",
                "max_amount": 1
            },
            "transfers": {
                "transit_account": "580000",
                "journal_id": 3
            }
        },
        "history": {
            "trash_retention_days": 90
        }
    },
    "is_active": true,
    "is_demo": false,
    "source": "manual",
    "external_id": "string",
    "synced_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal_entries_count": 1284,
    "firm": {
        "id": 3,
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "fiscal_years": [
        {
            "id": 2,
            "company_id": 7,
            "code": "2026",
            "starts_on": "2026-01-01T00:00:00.000000Z",
            "ends_on": "2026-12-31T00:00:00.000000Z",
            "is_closed": false,
            "closed_at": "2026-03-15T09:41:00+00:00",
            "closed_by": 1,
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "periods": [
                {}
            ]
        }
    ],
    "journals": [
        {
            "id": 3,
            "company_id": 7,
            "code": "VEN",
            "label": "Ventes",
            "type": "purchase",
            "control_account_id": 42,
            "iban": "BE68539007547034",
            "bic": "GEBABEBB",
            "last_number": 412,
            "is_active": true,
            "is_default": true,
            "description": "Description",
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "deleted_at": "2026-03-15T09:41:00+00:00",
            "deleted_by": 1,
            "entries_count": 412,
            "control_account": null,
            "rules": [
                {}
            ]
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "firm": "NDTQVQU4AUAV",
    "country_pack": "BE",
    "code": "COMPTOIR",
    "name": "Le Comptoir Montois SRL",
    "enterprise_number": "0477.472.701",
    "legal_form_code": "610",
    "vat_regime": "quarterly",
    "street": "Grand-Place",
    "house_number": "14",
    "postal_code": "7000",
    "city": "Mons",
    "fiscal_year": {
        "code": "2026",
        "starts_on": "2026-01-01",
        "ends_on": "2026-12-31"
    },
    "banks": [
        {
            "code": "BNP",
            "label": "BNP Paribas Fortis",
            "iban": "BE68 5390 0754 7034"
        }
    ]
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'firm' => 'NDTQVQU4AUAV',
        'country_pack' => 'BE',
        'code' => 'COMPTOIR',
        'name' => 'Le Comptoir Montois SRL',
        'enterprise_number' => '0477.472.701',
        'legal_form_code' => '610',
        'vat_regime' => 'quarterly',
        'street' => 'Grand-Place',
        'house_number' => '14',
        'postal_code' => '7000',
        'city' => 'Mons',
        'fiscal_year' => [
            'code' => '2026',
            'starts_on' => '2026-01-01',
            'ends_on' => '2026-12-31',
        ],
        'banks' => [
            [
                'code' => 'BNP',
                'label' => 'BNP Paribas Fortis',
                'iban' => 'BE68 5390 0754 7034',
            ],
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "firm": "NDTQVQU4AUAV",
      "country_pack": "BE",
      "code": "COMPTOIR",
      "name": "Le Comptoir Montois SRL",
      "enterprise_number": "0477.472.701",
      "legal_form_code": "610",
      "vat_regime": "quarterly",
      "street": "Grand-Place",
      "house_number": "14",
      "postal_code": "7000",
      "city": "Mons",
      "fiscal_year": {
          "code": "2026",
          "starts_on": "2026-01-01",
          "ends_on": "2026-12-31"
      },
      "banks": [
          {
              "code": "BNP",
              "label": "BNP Paribas Fortis",
              "iban": "BE68 5390 0754 7034"
          }
      ]
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "firm": "NDTQVQU4AUAV",
        "country_pack": "BE",
        "code": "COMPTOIR",
        "name": "Le Comptoir Montois SRL",
        "enterprise_number": "0477.472.701",
        "legal_form_code": "610",
        "vat_regime": "quarterly",
        "street": "Grand-Place",
        "house_number": "14",
        "postal_code": "7000",
        "city": "Mons",
        "fiscal_year": {
            "code": "2026",
            "starts_on": "2026-01-01",
            "ends_on": "2026-12-31"
        },
        "banks": [
            {
                "code": "BNP",
                "label": "BNP Paribas Fortis",
                "iban": "BE68 5390 0754 7034"
            }
        ]
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}Company file read

With its fiscal years, periods and journals.

Integration tokens need the read ability.

Operation id companies.show

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema Company

Example
{
    "id": 7,
    "public_token": "XBVD5O1L29HC",
    "firm_id": 3,
    "code": "COMPTOIR",
    "name": "Le Comptoir Montois SRL",
    "legal_form": "SRL",
    "legal_form_code": "610",
    "enterprise_number": "0477472701",
    "vat_number": "BE0477472701",
    "country_pack": "BE",
    "vat_regime": "monthly",
    "currency": "EUR",
    "locale": "fr",
    "address": "Grand-Place 14, 7000 Mons",
    "street": "Grand-Place",
    "house_number": "14",
    "box": "string",
    "postal_code": "7000",
    "city": "Mons",
    "country": "BE",
    "latitude": "50.4541000",
    "longitude": "3.9523000",
    "nace_codes": [
        {
            "code": "56111",
            "classification": "MAIN"
        }
    ],
    "main_nace_code": "56111",
    "company_sheet_at": "2026-03-15T09:41:00+00:00",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "icon_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "fiscal_year_start": "2026-03-15",
    "fiscal_year_end": "2026-03-15",
    "settings": {
        "vat": {
            "administration_cell": "string",
            "structured_communication": "000000000101",
            "directorate_number": "string",
            "office_number": "string",
            "declarant": {
                "applicable": false,
                "company_name": "string",
                "signatory_1": "string",
                "signatory_1_title": "string",
                "signatory_2": "string",
                "signatory_2_title": "string",
                "phone": "+32 65 31 42 18",
                "fax": "string",
                "email": "claire.dumont@fiduciaire-dumont.be",
                "language": "fr"
            },
            "sender_281_50": {
                "name": "Le Comptoir Montois SRL",
                "enterprise_number": "0477472701",
                "address": "Grand-Place 14",
                "phone": "+32 65 31 42 18",
                "email": "claire.dumont@fiduciaire-dumont.be"
            },
            "filer": {
                "quality": "company",
                "name": "Le Comptoir Montois SRL",
                "enterprise_number": "0477472701",
                "phone": "+32 65 31 42 18",
                "email": "claire.dumont@fiduciaire-dumont.be"
            }
        },
        "legal": {
            "rpm_district": "Hainaut, division Mons"
        },
        "annual_accounts": {
            "scheme": "abbreviated",
            "general_meeting_date": "2026-03-15",
            "directors": "string",
            "valuation_rules": "string"
        },
        "auto_entries": {
            "vat": {
                "payable_account": "451000",
                "receivable_account": "411000",
                "correction_payable_account": "string",
                "correction_receivable_account": "string",
                "journal_id": 3
            },
            "invoices_to_receive": {
                "supplier_account": "444000",
                "customer_account": "404000",
                "journal_id": 3
            },
            "reconciliation_difference": {
                "expense_account": "657000",
                "income_account": "757000",
                "max_amount": 1
            },
            "transfers": {
                "transit_account": "580000",
                "journal_id": 3
            }
        },
        "history": {
            "trash_retention_days": 90
        }
    },
    "is_active": true,
    "is_demo": false,
    "source": "manual",
    "external_id": "string",
    "synced_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal_entries_count": 1284,
    "firm": {
        "id": 3,
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "fiscal_years": [
        {
            "id": 2,
            "company_id": 7,
            "code": "2026",
            "starts_on": "2026-01-01T00:00:00.000000Z",
            "ends_on": "2026-12-31T00:00:00.000000Z",
            "is_closed": false,
            "closed_at": "2026-03-15T09:41:00+00:00",
            "closed_by": 1,
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "periods": [
                {}
            ]
        }
    ],
    "journals": [
        {
            "id": 3,
            "company_id": 7,
            "code": "VEN",
            "label": "Ventes",
            "type": "purchase",
            "control_account_id": 42,
            "iban": "BE68539007547034",
            "bic": "GEBABEBB",
            "last_number": 412,
            "is_active": true,
            "is_default": true,
            "description": "Description",
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "deleted_at": "2026-03-15T09:41:00+00:00",
            "deleted_by": 1,
            "entries_count": 412,
            "control_account": null,
            "rules": [
                {}
            ]
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}Update a company file write

Identity and / or settings. Settings are merged key by key: send only the keys to change; only known keys are accepted.

Integration tokens need the write ability.

Operation id companies.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • codestring | null
    Short code, letters, digits, dash, underscore (20 max).
  • namestring
    200 characters max.
  • enterprise_numberstring | null
    Checked against the country rules (BE: modulo 97).
  • vat_numberstring | null
    Format and check digits validated per country.
  • legal_formstring | null
  • legal_form_codestring | null
    Code of GET /v1/reference/legal-forms.
  • addressstring | null
  • logo_urlstring <uri> | null
  • vat_regimestring
    monthly quarterly franchise exempt unit
  • localestring
    fr nl en de
  • streetstring | null
  • house_numberstring | null
  • boxstring | null
  • postal_codestring | null
  • citystring | null
  • countrystring | null
    ISO 3166-1 alpha-2.
  • latitudenumber | null
  • longitudenumber | null
  • nace_codesobject[]
    Properties
    • codestringrequired
    • classificationstring
      MAIN SECO ANCI
  • main_nace_codestring | null
Example
{
    "vat_regime": "monthly",
    "settings": {
        "vat": {
            "office_number": "0420"
        },
        "auto_entries": {
            "reconciliation_difference": {
                "max_amount": 2.5
            }
        }
    }
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema Company

Example
{
    "id": 7,
    "public_token": "XBVD5O1L29HC",
    "firm_id": 3,
    "code": "COMPTOIR",
    "name": "Le Comptoir Montois SRL",
    "legal_form": "SRL",
    "legal_form_code": "610",
    "enterprise_number": "0477472701",
    "vat_number": "BE0477472701",
    "country_pack": "BE",
    "vat_regime": "monthly",
    "currency": "EUR",
    "locale": "fr",
    "address": "Grand-Place 14, 7000 Mons",
    "street": "Grand-Place",
    "house_number": "14",
    "box": "string",
    "postal_code": "7000",
    "city": "Mons",
    "country": "BE",
    "latitude": "50.4541000",
    "longitude": "3.9523000",
    "nace_codes": [
        {
            "code": "56111",
            "classification": "MAIN"
        }
    ],
    "main_nace_code": "56111",
    "company_sheet_at": "2026-03-15T09:41:00+00:00",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "icon_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "fiscal_year_start": "2026-03-15",
    "fiscal_year_end": "2026-03-15",
    "settings": {
        "vat": {
            "administration_cell": "string",
            "structured_communication": "000000000101",
            "directorate_number": "string",
            "office_number": "string",
            "declarant": {
                "applicable": false,
                "company_name": "string",
                "signatory_1": "string",
                "signatory_1_title": "string",
                "signatory_2": "string",
                "signatory_2_title": "string",
                "phone": "+32 65 31 42 18",
                "fax": "string",
                "email": "claire.dumont@fiduciaire-dumont.be",
                "language": "fr"
            },
            "sender_281_50": {
                "name": "Le Comptoir Montois SRL",
                "enterprise_number": "0477472701",
                "address": "Grand-Place 14",
                "phone": "+32 65 31 42 18",
                "email": "claire.dumont@fiduciaire-dumont.be"
            },
            "filer": {
                "quality": "company",
                "name": "Le Comptoir Montois SRL",
                "enterprise_number": "0477472701",
                "phone": "+32 65 31 42 18",
                "email": "claire.dumont@fiduciaire-dumont.be"
            }
        },
        "legal": {
            "rpm_district": "Hainaut, division Mons"
        },
        "annual_accounts": {
            "scheme": "abbreviated",
            "general_meeting_date": "2026-03-15",
            "directors": "string",
            "valuation_rules": "string"
        },
        "auto_entries": {
            "vat": {
                "payable_account": "451000",
                "receivable_account": "411000",
                "correction_payable_account": "string",
                "correction_receivable_account": "string",
                "journal_id": 3
            },
            "invoices_to_receive": {
                "supplier_account": "444000",
                "customer_account": "404000",
                "journal_id": 3
            },
            "reconciliation_difference": {
                "expense_account": "657000",
                "income_account": "757000",
                "max_amount": 1
            },
            "transfers": {
                "transit_account": "580000",
                "journal_id": 3
            }
        },
        "history": {
            "trash_retention_days": 90
        }
    },
    "is_active": true,
    "is_demo": false,
    "source": "manual",
    "external_id": "string",
    "synced_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal_entries_count": 1284,
    "firm": {
        "id": 3,
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "fiscal_years": [
        {
            "id": 2,
            "company_id": 7,
            "code": "2026",
            "starts_on": "2026-01-01T00:00:00.000000Z",
            "ends_on": "2026-12-31T00:00:00.000000Z",
            "is_closed": false,
            "closed_at": "2026-03-15T09:41:00+00:00",
            "closed_by": 1,
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "periods": [
                {}
            ]
        }
    ],
    "journals": [
        {
            "id": 3,
            "company_id": 7,
            "code": "VEN",
            "label": "Ventes",
            "type": "purchase",
            "control_account_id": 42,
            "iban": "BE68539007547034",
            "bic": "GEBABEBB",
            "last_number": 412,
            "is_active": true,
            "is_default": true,
            "description": "Description",
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "deleted_at": "2026-03-15T09:41:00+00:00",
            "deleted_by": 1,
            "entries_count": 412,
            "control_account": null,
            "rules": [
                {}
            ]
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "vat_regime": "monthly",
    "settings": {
        "vat": {
            "office_number": "0420"
        },
        "auto_entries": {
            "reconciliation_difference": {
                "max_amount": 2.5
            }
        }
    }
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'vat_regime' => 'monthly',
        'settings' => [
            'vat' => [
                'office_number' => '0420',
            ],
            'auto_entries' => [
                'reconciliation_difference' => [
                    'max_amount' => 2.5,
                ],
            ],
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "vat_regime": "monthly",
      "settings": {
          "vat": {
              "office_number": "0420"
          },
          "auto_entries": {
              "reconciliation_difference": {
                  "max_amount": 2.5
              }
          }
      }
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "vat_regime": "monthly",
        "settings": {
            "vat": {
                "office_number": "0420"
            },
            "auto_entries": {
                "reconciliation_difference": {
                    "max_amount": 2.5
                }
            }
        }
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}Delete a company file write Not in demo

Soft delete: the file disappears from every list.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Operation id companies.destroy

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

204Done, no body.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/integrityIntegrity check read

Sum of debits and credits over every entry of the file.

Integration tokens need the read ability.

Operation id companies.integrity

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • debitnumber
    e.g. 184320.55
  • creditnumber
    e.g. 184320.55
  • entriesinteger
    e.g. 1284
  • is_balancedboolean
Example
{
    "debit": 184320.55,
    "credit": 184320.55,
    "entries": 1284,
    "is_balanced": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrity" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrity', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrity", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrity",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/settingsResolved settings read

Settings of the file with the journals available for the selectors.

Integration tokens need the read ability.

Operation id companies.settings

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • journalsobject[]
    Properties
    • idinteger
    • codestring
      e.g. OD
    • labelstring
      e.g. Opérations diverses
    • typestring
      e.g. miscellaneous
Example
{
    "settings": {
        "vat": {
            "administration_cell": "string",
            "structured_communication": "000000000101",
            "directorate_number": "string",
            "office_number": "string",
            "declarant": {
                "applicable": false,
                "company_name": "string",
                "signatory_1": "string",
                "signatory_1_title": "string",
                "signatory_2": "string",
                "signatory_2_title": "string",
                "phone": "+32 65 31 42 18",
                "fax": "string",
                "email": "claire.dumont@fiduciaire-dumont.be",
                "language": "fr"
            },
            "sender_281_50": {
                "name": "Le Comptoir Montois SRL",
                "enterprise_number": "0477472701",
                "address": "Grand-Place 14",
                "phone": "+32 65 31 42 18",
                "email": "claire.dumont@fiduciaire-dumont.be"
            },
            "filer": {
                "quality": "company",
                "name": "Le Comptoir Montois SRL",
                "enterprise_number": "0477472701",
                "phone": "+32 65 31 42 18",
                "email": "claire.dumont@fiduciaire-dumont.be"
            }
        },
        "legal": {
            "rpm_district": "Hainaut, division Mons"
        },
        "annual_accounts": {
            "scheme": "abbreviated",
            "general_meeting_date": "2026-03-15",
            "directors": "string",
            "valuation_rules": "string"
        },
        "auto_entries": {
            "vat": {
                "payable_account": "451000",
                "receivable_account": "411000",
                "correction_payable_account": "string",
                "correction_receivable_account": "string",
                "journal_id": 3
            },
            "invoices_to_receive": {
                "supplier_account": "444000",
                "customer_account": "404000",
                "journal_id": 3
            },
            "reconciliation_difference": {
                "expense_account": "657000",
                "income_account": "757000",
                "max_amount": 1
            },
            "transfers": {
                "transit_account": "580000",
                "journal_id": 3
            }
        },
        "history": {
            "trash_retention_days": 90
        }
    },
    "journals": [
        {
            "id": 42,
            "code": "OD",
            "label": "Opérations diverses",
            "type": "miscellaneous"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/settings" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/settings', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/settings", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/settings",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Lookup

Company detection (CompanySearch for BE and FR, VIES elsewhere), legal forms, NACE codes, address autocompletion.

GET/v1/companies/{company}/sheetCompany sheet of the file read

Sheet stored on the file (last detection), structured address, legal form, NACE codes and map links.

Integration tokens need the read ability.

Operation id companies.sheet

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema SheetView

Example
{
    "sheet": {
        "identifier": "0477472701",
        "enterprise_number": "0477472701",
        "vat_number": "BE0477472701",
        "name": "Le Comptoir Montois",
        "legal_form": "SRL",
        "legal_form_code": "610",
        "status": "active",
        "start_date": "2026-03-15",
        "address": {
            "street": "Grand-Place",
            "house_number": "14",
            "box": "string",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE"
        },
        "address_line": "string",
        "latitude": 12.5,
        "longitude": 12.5,
        "nace_codes": [
            {
                "code": "56111",
                "classification": "MAIN",
                "label": "Facture Brasserie Dubuisson"
            }
        ],
        "main_nace_code": "string",
        "email": "claire.dumont@fiduciaire-dumont.be",
        "phone": "+32 65 31 42 18",
        "website": "https://www.comptoir-montois.be",
        "source": "companysearch",
        "fetched_at": "2026-03-15T09:41:00+00:00",
        "map": {
            "query": "Grand-Place 14, 7000 Mons, Belgique",
            "apple_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "google_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "static_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "latitude": 12.5,
            "longitude": 12.5
        }
    },
    "sheet_at": "2026-03-15T09:41:00+00:00",
    "address": {
        "street": "Grand-Place",
        "house_number": "14",
        "box": "string",
        "postal_code": "7000",
        "city": "Mons",
        "country": "BE"
    },
    "address_line": "string",
    "legal_form": {},
    "nace_codes": [
        {
            "code": "COMPTOIR",
            "classification": "string",
            "label": "Facture Brasserie Dubuisson",
            "is_main": true
        }
    ],
    "main_nace_code": "string",
    "vat_number_formatted": "BE 0477.472.701",
    "map": {
        "query": "Grand-Place 14, 7000 Mons, Belgique",
        "apple_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "google_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "static_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "latitude": 12.5,
        "longitude": 12.5
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sheet" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sheet', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sheet", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sheet",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/apply-sheetFill the file from a company sheet write Not in demo 30 / 1 min

Looks the company up and copies name, legal form, address, NACE codes and VAT number to the file (empty fields only unless overwrite).

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 30 requests per minute (429 beyond, see Retry-After).

Operation id companies.apply-sheet

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • identifierstringrequired
    Enterprise or VAT number.
    e.g. 0477472701
  • refreshboolean | null
    Ignore the 24 h cache.
  • overwriteboolean | null
    Replace the fields already filled in.
Example
{
    "identifier": "0477472701",
    "refresh": true,
    "overwrite": true
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
Example
{
    "company": {
        "id": 7,
        "public_token": "XBVD5O1L29HC",
        "firm_id": 3,
        "code": "COMPTOIR",
        "name": "Le Comptoir Montois SRL",
        "legal_form": "SRL",
        "legal_form_code": "610",
        "enterprise_number": "0477472701",
        "vat_number": "BE0477472701",
        "country_pack": "BE",
        "vat_regime": "monthly",
        "currency": "EUR",
        "locale": "fr",
        "address": "Grand-Place 14, 7000 Mons",
        "street": "Grand-Place",
        "house_number": "14",
        "box": "string",
        "postal_code": "7000",
        "city": "Mons",
        "country": "BE",
        "latitude": "50.4541000",
        "longitude": "3.9523000",
        "nace_codes": [
            {
                "code": "56111",
                "classification": "MAIN"
            }
        ],
        "main_nace_code": "56111",
        "company_sheet_at": "2026-03-15T09:41:00+00:00",
        "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "icon_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "fiscal_year_start": "2026-03-15",
        "fiscal_year_end": "2026-03-15",
        "settings": {
            "vat": {
                "administration_cell": "string",
                "structured_communication": "000000000101",
                "directorate_number": "string",
                "office_number": "string",
                "declarant": {
                    "applicable": false,
                    "company_name": "string",
                    "signatory_1": "string",
                    "signatory_1_title": "string",
                    "signatory_2": "string",
                    "signatory_2_title": "string",
                    "phone": "+32 65 31 42 18",
                    "fax": "string",
                    "email": "claire.dumont@fiduciaire-dumont.be",
                    "language": "fr"
                },
                "sender_281_50": {
                    "name": "Le Comptoir Montois SRL",
                    "enterprise_number": "0477472701",
                    "address": "Grand-Place 14",
                    "phone": "+32 65 31 42 18",
                    "email": "claire.dumont@fiduciaire-dumont.be"
                },
                "filer": {
                    "quality": "company",
                    "name": "Le Comptoir Montois SRL",
                    "enterprise_number": "0477472701",
                    "phone": "+32 65 31 42 18",
                    "email": "claire.dumont@fiduciaire-dumont.be"
                }
            },
            "legal": {
                "rpm_district": "Hainaut, division Mons"
            },
            "annual_accounts": {
                "scheme": "abbreviated",
                "general_meeting_date": "2026-03-15",
                "directors": "string",
                "valuation_rules": "string"
            },
            "auto_entries": {
                "vat": {
                    "payable_account": "451000",
                    "receivable_account": "411000",
                    "correction_payable_account": "string",
                    "correction_receivable_account": "string",
                    "journal_id": 3
                },
                "invoices_to_receive": {
                    "supplier_account": "444000",
                    "customer_account": "404000",
                    "journal_id": 3
                },
                "reconciliation_difference": {
                    "expense_account": "657000",
                    "income_account": "757000",
                    "max_amount": 1
                },
                "transfers": {
                    "transit_account": "580000",
                    "journal_id": 3
                }
            },
            "history": {
                "trash_retention_days": 90
            }
        },
        "is_active": true,
        "is_demo": false,
        "source": "manual",
        "external_id": "string",
        "synced_at": "2026-03-15T09:41:00+00:00",
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal_entries_count": 1284,
        "firm": {
            "id": 3,
            "public_token": "NDTQVQU4AUAV",
            "name": "Fiduciaire Dumont & Associés"
        },
        "fiscal_years": [
            {
                "id": 2,
                "company_id": 7,
                "code": "2026",
                "starts_on": "2026-01-01T00:00:00.000000Z",
                "ends_on": "2026-12-31T00:00:00.000000Z",
                "is_closed": false,
                "closed_at": "2026-03-15T09:41:00+00:00",
                "closed_by": 1,
                "created_at": "2026-03-15T09:41:00+00:00",
                "updated_at": "2026-03-15T09:41:00+00:00",
                "lock_version": 3,
                "version": 3,
                "periods": [
                    {}
                ]
            }
        ],
        "journals": [
            {
                "id": 3,
                "company_id": 7,
                "code": "VEN",
                "label": "Ventes",
                "type": "purchase",
                "control_account_id": 42,
                "iban": "BE68539007547034",
                "bic": "GEBABEBB",
                "last_number": 412,
                "is_active": true,
                "is_default": true,
                "description": "Description",
                "created_at": "2026-03-15T09:41:00+00:00",
                "updated_at": "2026-03-15T09:41:00+00:00",
                "lock_version": 3,
                "version": 3,
                "deleted_at": "2026-03-15T09:41:00+00:00",
                "deleted_by": 1,
                "entries_count": 412,
                "control_account": null,
                "rules": [
                    {}
                ]
            }
        ]
    },
    "sheet": {
        "identifier": "0477472701",
        "enterprise_number": "0477472701",
        "vat_number": "BE0477472701",
        "name": "Le Comptoir Montois",
        "legal_form": "SRL",
        "legal_form_code": "610",
        "status": "active",
        "start_date": "2026-03-15",
        "address": {
            "street": "Grand-Place",
            "house_number": "14",
            "box": "string",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE"
        },
        "address_line": "string",
        "latitude": 12.5,
        "longitude": 12.5,
        "nace_codes": [
            {
                "code": "56111",
                "classification": "MAIN",
                "label": "Facture Brasserie Dubuisson"
            }
        ],
        "main_nace_code": "string",
        "email": "claire.dumont@fiduciaire-dumont.be",
        "phone": "+32 65 31 42 18",
        "website": "https://www.comptoir-montois.be",
        "source": "companysearch",
        "fetched_at": "2026-03-15T09:41:00+00:00",
        "map": {
            "query": "Grand-Place 14, 7000 Mons, Belgique",
            "apple_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "google_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "static_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "latitude": 12.5,
            "longitude": 12.5
        }
    },
    "map": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error
503Temporarily unavailable (maintenance, external provider down). A 503 always carries a code. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/apply-sheet" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "identifier": "0477472701",
    "refresh": true,
    "overwrite": true
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/apply-sheet', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'identifier' => '0477472701',
        'refresh' => true,
        'overwrite' => true,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/apply-sheet", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "identifier": "0477472701",
      "refresh": true,
      "overwrite": true
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/apply-sheet",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "identifier": "0477472701",
        "refresh": True,
        "overwrite": True
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/third-parties/{thirdParty}/sheetCompany sheet of a third party read

Integration tokens need the read ability.

Operation id companies.third-parties.sheet

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Common headers: Accept-Language

Responses

200OK

application/json

Schema SheetView

Example
{
    "sheet": {
        "identifier": "0477472701",
        "enterprise_number": "0477472701",
        "vat_number": "BE0477472701",
        "name": "Le Comptoir Montois",
        "legal_form": "SRL",
        "legal_form_code": "610",
        "status": "active",
        "start_date": "2026-03-15",
        "address": {
            "street": "Grand-Place",
            "house_number": "14",
            "box": "string",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE"
        },
        "address_line": "string",
        "latitude": 12.5,
        "longitude": 12.5,
        "nace_codes": [
            {
                "code": "56111",
                "classification": "MAIN",
                "label": "Facture Brasserie Dubuisson"
            }
        ],
        "main_nace_code": "string",
        "email": "claire.dumont@fiduciaire-dumont.be",
        "phone": "+32 65 31 42 18",
        "website": "https://www.comptoir-montois.be",
        "source": "companysearch",
        "fetched_at": "2026-03-15T09:41:00+00:00",
        "map": {
            "query": "Grand-Place 14, 7000 Mons, Belgique",
            "apple_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "google_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "static_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "latitude": 12.5,
            "longitude": 12.5
        }
    },
    "sheet_at": "2026-03-15T09:41:00+00:00",
    "address": {
        "street": "Grand-Place",
        "house_number": "14",
        "box": "string",
        "postal_code": "7000",
        "city": "Mons",
        "country": "BE"
    },
    "address_line": "string",
    "legal_form": {},
    "nace_codes": [
        {
            "code": "COMPTOIR",
            "classification": "string",
            "label": "Facture Brasserie Dubuisson",
            "is_main": true
        }
    ],
    "main_nace_code": "string",
    "vat_number_formatted": "BE 0477.472.701",
    "map": {
        "query": "Grand-Place 14, 7000 Mons, Belgique",
        "apple_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "google_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "static_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "latitude": 12.5,
        "longitude": 12.5
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/sheet" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/sheet', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/sheet", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/sheet",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/third-parties/{thirdParty}/apply-sheetFill a third party from a company sheet write Not in demo 30 / 1 min

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 30 requests per minute (429 beyond, see Retry-After).

Operation id companies.third-parties.apply-sheet

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • identifierstringrequired
    Enterprise or VAT number.
    e.g. 0477472701
  • refreshboolean | null
    Ignore the 24 h cache.
  • overwriteboolean | null
    Replace the fields already filled in.
Example
{
    "identifier": "0477472701",
    "refresh": true,
    "overwrite": true
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
Example
{
    "third_party": {
        "id": 18,
        "company_id": 7,
        "type": "customer",
        "code": "DUBUISSON",
        "name": "Brasserie Dubuisson SA",
        "contact_name": "string",
        "vat_number": "BE0402531376",
        "enterprise_number": "0402531376",
        "legal_form_code": "string",
        "vat_status": "subject",
        "country": "BE",
        "language": "fr",
        "category": "string",
        "currency": "EUR",
        "address": "Chaussée de Mons 28",
        "house_number": "14",
        "box": "string",
        "address_line_2": "string",
        "postal_code": "7904",
        "city": "Pipaix",
        "nace_code": "string",
        "iban": "BE71096123456769",
        "bic": "GKCCBEBB",
        "bank_account": "string",
        "email": "compta@dubuisson.example",
        "phone": "+32 65 31 42 18",
        "fax": "string",
        "website": "https://www.comptoir-montois.be",
        "payment_terms_days": 30,
        "form_281_50_type": "string",
        "profession_281_50": "string",
        "is_natural_person": false,
        "notes": "string",
        "default_vat_code_id": 42,
        "default_account_id": 42,
        "vies_valid": true,
        "vies_checked_at": "2026-03-15T09:41:00+00:00",
        "vies_name": "string",
        "peppol_identifier": "0208:0402531376",
        "peppol_registered": true,
        "peppol_access_point": {},
        "peppol_document_types": [
            {
                "id": "bis_billing_invoice",
                "name": "Invoice BIS Billing 3.0",
                "family": "billing",
                "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
                "document_id": "string"
            }
        ],
        "peppol_checked_at": "2026-03-15T09:41:00+00:00",
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1,
        "default_account": {},
        "default_vat_code": {}
    },
    "sheet": {
        "identifier": "0477472701",
        "enterprise_number": "0477472701",
        "vat_number": "BE0477472701",
        "name": "Le Comptoir Montois",
        "legal_form": "SRL",
        "legal_form_code": "610",
        "status": "active",
        "start_date": "2026-03-15",
        "address": {
            "street": "Grand-Place",
            "house_number": "14",
            "box": "string",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE"
        },
        "address_line": "string",
        "latitude": 12.5,
        "longitude": 12.5,
        "nace_codes": [
            {
                "code": "56111",
                "classification": "MAIN",
                "label": "Facture Brasserie Dubuisson"
            }
        ],
        "main_nace_code": "string",
        "email": "claire.dumont@fiduciaire-dumont.be",
        "phone": "+32 65 31 42 18",
        "website": "https://www.comptoir-montois.be",
        "source": "companysearch",
        "fetched_at": "2026-03-15T09:41:00+00:00",
        "map": {
            "query": "Grand-Place 14, 7000 Mons, Belgique",
            "apple_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "google_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "static_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "latitude": 12.5,
            "longitude": 12.5
        }
    },
    "map": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error
503Temporarily unavailable (maintenance, external provider down). A 503 always carries a code. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/apply-sheet" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "identifier": "0477472701",
    "refresh": true,
    "overwrite": true
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/apply-sheet', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'identifier' => '0477472701',
        'refresh' => true,
        'overwrite' => true,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/apply-sheet", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "identifier": "0477472701",
      "refresh": true,
      "overwrite": true
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/apply-sheet",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "identifier": "0477472701",
        "refresh": True,
        "overwrite": True
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/reference/naceNACE codes read

Search in the NACE-BEL nomenclature by code or words.

Integration tokens need the read ability.

Operation id reference.nace

Query parameters

NameTypeDescription
countrystring
e.g. BE
qstring
e.g. restauration
limitinteger1 to 200, 30 by default.
levelinteger1 to 7.
editionstring
e.g. 2025
langstring
fr nl en de

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • dataobject[]
    Properties
    • codestring
      e.g. 56111
    • labelstring
      e.g. Restauration à service complet
    • label_frstring
    • label_nlstring
    • label_destring
    • label_enstring
    • levelinteger
      e.g. 5
    • editionstring
      e.g. 2025
  • countrystring
  • nomenclature_countrystring
  • localestring
Example
{
    "data": [
        {
            "code": "56111",
            "label": "Restauration à service complet",
            "label_fr": "string",
            "label_nl": "string",
            "label_de": "string",
            "label_en": "string",
            "level": 5,
            "edition": "2025"
        }
    ],
    "country": "BE",
    "nomenclature_country": "string",
    "locale": "fr"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/reference/nace" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/reference/nace', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/reference/nace", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/reference/nace",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/lookup/capabilitiesLookup capabilities of a country read

What the detection can do for a country: BE and FR through CompanySearch (search, sheet, cities, streets), other EU countries through VIES (VAT check only).

Integration tokens need the read ability.

Operation id lookup.capabilities

Query parameters

NameTypeDescription
countrystring
e.g. BE

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • countrystring
    e.g. BE
  • searchboolean
  • sheetboolean
  • vatboolean
  • citiesboolean
  • streetsboolean
  • sourcestring
    e.g. companysearch
  • provider_configuredboolean
Example
{
    "country": "BE",
    "search": true,
    "sheet": true,
    "vat": true,
    "cities": true,
    "streets": true,
    "source": "companysearch",
    "provider_configured": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/lookup/capabilities" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/lookup/capabilities', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/lookup/capabilities", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/lookup/capabilities",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/lookup/companies/{identifier}Company sheet read Not in demo 60 / 1 min

Normalised sheet of a company, cached 24 hours.

Integration tokens need the read ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 60 requests per minute (429 beyond, see Retry-After).

Operation id lookup.companies.show

Path parameters

NameTypeDescription
identifier requiredstringEnterprise number or VAT number of the company to look up.
e.g. 0477472701

Query parameters

NameTypeDescription
countrystring
refreshbooleanIgnore the cache.
langstring
fr nl en de

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema CompanySheet

Example
{
    "identifier": "0477472701",
    "enterprise_number": "0477472701",
    "vat_number": "BE0477472701",
    "name": "Le Comptoir Montois",
    "legal_form": "SRL",
    "legal_form_code": "610",
    "status": "active",
    "start_date": "2026-03-15",
    "address": {
        "street": "Grand-Place",
        "house_number": "14",
        "box": "string",
        "postal_code": "7000",
        "city": "Mons",
        "country": "BE"
    },
    "address_line": "string",
    "latitude": 12.5,
    "longitude": 12.5,
    "nace_codes": [
        {
            "code": "56111",
            "classification": "MAIN",
            "label": "Facture Brasserie Dubuisson"
        }
    ],
    "main_nace_code": "string",
    "email": "claire.dumont@fiduciaire-dumont.be",
    "phone": "+32 65 31 42 18",
    "website": "https://www.comptoir-montois.be",
    "source": "companysearch",
    "fetched_at": "2026-03-15T09:41:00+00:00",
    "map": {
        "query": "Grand-Place 14, 7000 Mons, Belgique",
        "apple_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "google_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "static_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "latitude": 12.5,
        "longitude": 12.5
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error
503Temporarily unavailable (maintenance, external provider down). A 503 always carries a code. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/lookup/companies/0477472701" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/lookup/companies/0477472701', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/lookup/companies/0477472701", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/lookup/companies/0477472701",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/lookup/vatCheck a VAT number read Not in demo 60 / 1 min

Format, check digits and existence, with the Peppol status when known.

Integration tokens need the read ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 60 requests per minute (429 beyond, see Retry-After).

Operation id lookup.vat

Query parameters

NameTypeDescription
vat requiredstring
e.g. BE0477472701
countrystring

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • validboolean | null
  • valid_formatboolean
  • vat_numberstring
  • enterprise_numberstring | null
  • namestring | null
  • address_linestring | null
  • statusstring | null
  • peppolobject | null
  • reasonstring | null
  • sourcestring
Example
{
    "valid": true,
    "valid_format": true,
    "vat_number": "BE0477472701",
    "enterprise_number": "0477472701",
    "name": "Le Comptoir Montois SRL",
    "address_line": "string",
    "status": "active",
    "peppol": {},
    "reason": "string",
    "source": "string"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
429Rate limit reached. Error
503Temporarily unavailable (maintenance, external provider down). A 503 always carries a code. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/lookup/vat?vat=BE0477472701" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/lookup/vat', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'query' => [
        'vat' => 'BE0477472701',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/lookup/vat?vat=BE0477472701", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/lookup/vat",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    params={
        "vat": "BE0477472701"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/lookup/citiesCity autocompletion read Not in demo 120 / 1 min

Integration tokens need the read ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 120 requests per minute (429 beyond, see Retry-After).

Operation id lookup.cities

Query parameters

NameTypeDescription
q requiredstring
e.g. Mons
countrystring
e.g. BE

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • dataobject[]
    Properties
    • postal_codestring
      e.g. 7000
    • citystring
      e.g. Mons
    • city_frstring | null
    • city_nlstring | null
      e.g. Bergen
    • countrystring
      e.g. BE
Example
{
    "data": [
        {
            "postal_code": "7000",
            "city": "Mons",
            "city_fr": "string",
            "city_nl": "Bergen",
            "country": "BE"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
429Rate limit reached. Error
503Temporarily unavailable (maintenance, external provider down). A 503 always carries a code. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/lookup/cities?q=Mons" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/lookup/cities', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'query' => [
        'q' => 'Mons',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/lookup/cities?q=Mons", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/lookup/cities",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    params={
        "q": "Mons"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/lookup/streetsStreet autocompletion read Not in demo 120 / 1 min

Integration tokens need the read ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 120 requests per minute (429 beyond, see Retry-After).

Operation id lookup.streets

Query parameters

NameTypeDescription
zipcode requiredstringFour digits.
e.g. 7000
qstring
e.g. Grand
countrystring
e.g. BE

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • dataobject[]
    Properties
    • streetstring
      e.g. Grand-Place
    • street_frstring | null
    • street_nlstring | null
    • postal_codestring
    • citystring
    • countrystring
Example
{
    "data": [
        {
            "street": "Grand-Place",
            "street_fr": "string",
            "street_nl": "string",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
429Rate limit reached. Error
503Temporarily unavailable (maintenance, external provider down). A 503 always carries a code. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/lookup/streets?zipcode=7000" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/lookup/streets', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'query' => [
        'zipcode' => '7000',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/lookup/streets?zipcode=7000", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/lookup/streets",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    params={
        "zipcode": "7000"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/lookup/capabilitiesLookup capabilities of a country read

What the detection can do for a country: BE and FR through CompanySearch (search, sheet, cities, streets), other EU countries through VIES (VAT check only). The call is attributed to the company file.

Integration tokens need the read ability.

Operation id companies.lookup.capabilities

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
countrystring
e.g. BE

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • countrystring
    e.g. BE
  • searchboolean
  • sheetboolean
  • vatboolean
  • citiesboolean
  • streetsboolean
  • sourcestring
    e.g. companysearch
  • provider_configuredboolean
Example
{
    "country": "BE",
    "search": true,
    "sheet": true,
    "vat": true,
    "cities": true,
    "streets": true,
    "source": "companysearch",
    "provider_configured": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/capabilities" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/capabilities', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/capabilities", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/capabilities",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/lookup/companies/{identifier}Company sheet read Not in demo 60 / 1 min

Normalised sheet of a company, cached 24 hours. The call is attributed to the company file.

Integration tokens need the read ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 60 requests per minute (429 beyond, see Retry-After).

Operation id companies.lookup.companies.show

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
identifier requiredstringEnterprise number or VAT number of the company to look up.
e.g. 0477472701

Query parameters

NameTypeDescription
countrystring
refreshbooleanIgnore the cache.
langstring
fr nl en de

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema CompanySheet

Example
{
    "identifier": "0477472701",
    "enterprise_number": "0477472701",
    "vat_number": "BE0477472701",
    "name": "Le Comptoir Montois",
    "legal_form": "SRL",
    "legal_form_code": "610",
    "status": "active",
    "start_date": "2026-03-15",
    "address": {
        "street": "Grand-Place",
        "house_number": "14",
        "box": "string",
        "postal_code": "7000",
        "city": "Mons",
        "country": "BE"
    },
    "address_line": "string",
    "latitude": 12.5,
    "longitude": 12.5,
    "nace_codes": [
        {
            "code": "56111",
            "classification": "MAIN",
            "label": "Facture Brasserie Dubuisson"
        }
    ],
    "main_nace_code": "string",
    "email": "claire.dumont@fiduciaire-dumont.be",
    "phone": "+32 65 31 42 18",
    "website": "https://www.comptoir-montois.be",
    "source": "companysearch",
    "fetched_at": "2026-03-15T09:41:00+00:00",
    "map": {
        "query": "Grand-Place 14, 7000 Mons, Belgique",
        "apple_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "google_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "static_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "latitude": 12.5,
        "longitude": 12.5
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error
503Temporarily unavailable (maintenance, external provider down). A 503 always carries a code. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/companies/0477472701" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/companies/0477472701', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/companies/0477472701", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/companies/0477472701",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/lookup/vatCheck a VAT number read Not in demo 60 / 1 min

Format, check digits and existence, with the Peppol status when known. The call is attributed to the company file.

Integration tokens need the read ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 60 requests per minute (429 beyond, see Retry-After).

Operation id companies.lookup.vat

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
vat requiredstring
e.g. BE0477472701
countrystring

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • validboolean | null
  • valid_formatboolean
  • vat_numberstring
  • enterprise_numberstring | null
  • namestring | null
  • address_linestring | null
  • statusstring | null
  • peppolobject | null
  • reasonstring | null
  • sourcestring
Example
{
    "valid": true,
    "valid_format": true,
    "vat_number": "BE0477472701",
    "enterprise_number": "0477472701",
    "name": "Le Comptoir Montois SRL",
    "address_line": "string",
    "status": "active",
    "peppol": {},
    "reason": "string",
    "source": "string"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error
503Temporarily unavailable (maintenance, external provider down). A 503 always carries a code. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/vat?vat=BE0477472701" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/vat', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'query' => [
        'vat' => 'BE0477472701',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/vat?vat=BE0477472701", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/vat",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    params={
        "vat": "BE0477472701"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/lookup/citiesCity autocompletion read Not in demo 120 / 1 min

The call is attributed to the company file.

Integration tokens need the read ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 120 requests per minute (429 beyond, see Retry-After).

Operation id companies.lookup.cities

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
q requiredstring
e.g. Mons
countrystring
e.g. BE

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • dataobject[]
    Properties
    • postal_codestring
      e.g. 7000
    • citystring
      e.g. Mons
    • city_frstring | null
    • city_nlstring | null
      e.g. Bergen
    • countrystring
      e.g. BE
Example
{
    "data": [
        {
            "postal_code": "7000",
            "city": "Mons",
            "city_fr": "string",
            "city_nl": "Bergen",
            "country": "BE"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error
503Temporarily unavailable (maintenance, external provider down). A 503 always carries a code. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/cities?q=Mons" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/cities', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'query' => [
        'q' => 'Mons',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/cities?q=Mons", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/cities",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    params={
        "q": "Mons"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/lookup/streetsStreet autocompletion read Not in demo 120 / 1 min

The call is attributed to the company file.

Integration tokens need the read ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 120 requests per minute (429 beyond, see Retry-After).

Operation id companies.lookup.streets

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
zipcode requiredstringFour digits.
e.g. 7000
qstring
e.g. Grand
countrystring
e.g. BE

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • dataobject[]
    Properties
    • streetstring
      e.g. Grand-Place
    • street_frstring | null
    • street_nlstring | null
    • postal_codestring
    • citystring
    • countrystring
Example
{
    "data": [
        {
            "street": "Grand-Place",
            "street_fr": "string",
            "street_nl": "string",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error
503Temporarily unavailable (maintenance, external provider down). A 503 always carries a code. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/streets?zipcode=7000" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/streets', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'query' => [
        'zipcode' => '7000',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/streets?zipcode=7000", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/lookup/streets",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    params={
        "zipcode": "7000"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Chart of accounts

Accounts of a company file.

GET/v1/companies/{company}/accountsChart of accounts read

Integration tokens need the read ability.

Operation id companies.accounts.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
qstringNumber prefix or part of the label.
e.g. 6120
postablebooleanOnly the accounts entries can be posted to.

Common headers: Accept-Language

Responses

200OK

application/json

Schema Account[]

Array of Account

Example
[
    {
        "id": 580,
        "company_id": 7,
        "number": "702000",
        "label": "Prestations de services",
        "type": "asset",
        "is_postable": true,
        "is_reconcilable": true,
        "purchase_grid": 82,
        "default_vat_code_id": 42,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1,
        "default_vat_code": {}
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/accountsCreate an account write

Integration tokens need the write ability.

Operation id companies.accounts.store

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • numberstringrequired
    2 to 12 digits, unique in the file.
  • typestringrequired
    asset liability expense income off_balance
  • labelstringrequired
    200 characters max.
  • is_postableboolean
  • is_reconcilableboolean
  • purchase_gridinteger | null
    81, 82 or 83.
  • default_vat_code_idinteger | null
Example
{
    "number": "612100",
    "label": "Électricité",
    "type": "expense",
    "is_postable": true,
    "purchase_grid": 82
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema Account

Example
{
    "id": 580,
    "company_id": 7,
    "number": "702000",
    "label": "Prestations de services",
    "type": "asset",
    "is_postable": true,
    "is_reconcilable": true,
    "purchase_grid": 82,
    "default_vat_code_id": 42,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "default_vat_code": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "number": "612100",
    "label": "Électricité",
    "type": "expense",
    "is_postable": true,
    "purchase_grid": 82
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'number' => '612100',
        'label' => 'Électricité',
        'type' => 'expense',
        'is_postable' => true,
        'purchase_grid' => 82,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "number": "612100",
      "label": "Électricité",
      "type": "expense",
      "is_postable": true,
      "purchase_grid": 82
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "number": "612100",
        "label": "Électricité",
        "type": "expense",
        "is_postable": True,
        "purchase_grid": 82
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/accounts/{account}Update an account write

The number and the type of an account never change.

Integration tokens need the write ability.

Operation id companies.accounts.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
account requiredintegerId of the account (not its number).
e.g. 223

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • labelstring
    200 characters max.
  • is_postableboolean
  • is_reconcilableboolean
  • purchase_gridinteger | null
    81, 82 or 83.
  • default_vat_code_idinteger | null
Example
{
    "label": "Électricité et gaz"
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema Account

Example
{
    "id": 580,
    "company_id": 7,
    "number": "702000",
    "label": "Prestations de services",
    "type": "asset",
    "is_postable": true,
    "is_reconcilable": true,
    "purchase_grid": 82,
    "default_vat_code_id": 42,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "default_vat_code": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts/223" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "label": "Électricité et gaz"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts/223', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'label' => 'Électricité et gaz',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts/223", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "label": "Électricité et gaz"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts/223",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "label": "Électricité et gaz"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Journals

Journals, routing rules of the imported documents, numbering series.

GET/v1/companies/{company}/journalsJournals read

With their control account, routing rules and number of entries.

Integration tokens need the read ability.

Operation id companies.journals.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema Journal[]

Array of Journal

Example
[
    {
        "id": 3,
        "company_id": 7,
        "code": "VEN",
        "label": "Ventes",
        "type": "purchase",
        "control_account_id": 42,
        "iban": "BE68539007547034",
        "bic": "GEBABEBB",
        "last_number": 412,
        "is_active": true,
        "is_default": true,
        "description": "Description",
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1,
        "entries_count": 412,
        "control_account": {
            "id": 580,
            "number": "702000",
            "label": "Prestations de services"
        },
        "rules": [
            {
                "id": 4,
                "company_id": 7,
                "journal_id": 3,
                "direction": "sale",
                "match_field": "payment_provider",
                "match_value": "TK",
                "priority": 100,
                "is_active": true,
                "created_at": "2026-03-15T09:41:00+00:00",
                "updated_at": "2026-03-15T09:41:00+00:00",
                "lock_version": 3,
                "version": 3,
                "deleted_at": "2026-03-15T09:41:00+00:00",
                "deleted_by": 1,
                "journal": {
                    "id": 3,
                    "code": "VEN",
                    "label": "Ventes",
                    "type": "sale"
                }
            }
        ]
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/journalsCreate a journal write

Integration tokens need the write ability.

Operation id companies.journals.store

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • codestringrequired
    Letters and digits, 6 max, unique.
  • labelstringrequired
  • typestringrequired
    purchase sale purchase_credit_note sale_credit_note financial miscellaneous
  • control_account_idinteger | null
  • ibanstring | null
  • bicstring | null
Example
{
    "code": "ING",
    "label": "ING Business",
    "type": "financial",
    "iban": "BE12310123456789"
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema Journal

Example
{
    "id": 3,
    "company_id": 7,
    "code": "VEN",
    "label": "Ventes",
    "type": "purchase",
    "control_account_id": 42,
    "iban": "BE68539007547034",
    "bic": "GEBABEBB",
    "last_number": 412,
    "is_active": true,
    "is_default": true,
    "description": "Description",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "entries_count": 412,
    "control_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "rules": [
        {
            "id": 4,
            "company_id": 7,
            "journal_id": 3,
            "direction": "sale",
            "match_field": "payment_provider",
            "match_value": "TK",
            "priority": 100,
            "is_active": true,
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "deleted_at": "2026-03-15T09:41:00+00:00",
            "deleted_by": 1,
            "journal": {
                "id": 3,
                "code": "VEN",
                "label": "Ventes",
                "type": "sale"
            }
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "code": "ING",
    "label": "ING Business",
    "type": "financial",
    "iban": "BE12310123456789"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'code' => 'ING',
        'label' => 'ING Business',
        'type' => 'financial',
        'iban' => 'BE12310123456789',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "code": "ING",
      "label": "ING Business",
      "type": "financial",
      "iban": "BE12310123456789"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "code": "ING",
        "label": "ING Business",
        "type": "financial",
        "iban": "BE12310123456789"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/journals/{journal}Update a journal write

is_default makes it the default journal of its type.

Integration tokens need the write ability.

Operation id companies.journals.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
journal requiredintegerId of the journal.
e.g. 3

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • labelstring
  • descriptionstring | null
  • control_account_idinteger | null
  • ibanstring | null
  • is_activeboolean
  • is_defaultboolean
Example
{
    "is_default": true
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema Journal

Example
{
    "id": 3,
    "company_id": 7,
    "code": "VEN",
    "label": "Ventes",
    "type": "purchase",
    "control_account_id": 42,
    "iban": "BE68539007547034",
    "bic": "GEBABEBB",
    "last_number": 412,
    "is_active": true,
    "is_default": true,
    "description": "Description",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "entries_count": 412,
    "control_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "rules": [
        {
            "id": 4,
            "company_id": 7,
            "journal_id": 3,
            "direction": "sale",
            "match_field": "payment_provider",
            "match_value": "TK",
            "priority": 100,
            "is_active": true,
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "deleted_at": "2026-03-15T09:41:00+00:00",
            "deleted_by": 1,
            "journal": {
                "id": 3,
                "code": "VEN",
                "label": "Ventes",
                "type": "sale"
            }
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/3" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "is_default": true
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/3', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'is_default' => true,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/3", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "is_default": true
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/3",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "is_default": True
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/journals/{journal}Delete a journal write

Only a journal that never held an entry (continuous numbering); otherwise deactivate it. Goes to the recycle bin.

Integration tokens need the write ability.

Operation id companies.journals.destroy

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
journal requiredintegerId of the journal.
e.g. 3

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

204Done, no body.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/3" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/3', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/3", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/3",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/journal-rulesJournal routing rules read

Integration tokens need the read ability.

Operation id companies.journal-rules.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema JournalRule[]

Array of JournalRule

Example
[
    {
        "id": 4,
        "company_id": 7,
        "journal_id": 3,
        "direction": "sale",
        "match_field": "payment_provider",
        "match_value": "TK",
        "priority": 100,
        "is_active": true,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1,
        "journal": {
            "id": 3,
            "code": "VEN",
            "label": "Ventes",
            "type": "sale"
        }
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/journal-rulesCreate a journal rule write

Integration tokens need the write ability.

Operation id companies.journal-rules.store

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • journal_idintegerrequired
  • directionstringrequired
    sale purchase
  • match_fieldstringrequired
    payment_provider number_series number_prefix third_party
  • match_valuestringrequired
    100 characters max.
  • priorityinteger
    1 to 999, lowest first.
  • is_activeboolean
Example
{
    "journal_id": 3,
    "direction": "sale",
    "match_field": "number_prefix",
    "match_value": "TK"
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema JournalRule

Example
{
    "id": 4,
    "company_id": 7,
    "journal_id": 3,
    "direction": "sale",
    "match_field": "payment_provider",
    "match_value": "TK",
    "priority": 100,
    "is_active": true,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "journal": {
        "id": 3,
        "code": "VEN",
        "label": "Ventes",
        "type": "sale"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "journal_id": 3,
    "direction": "sale",
    "match_field": "number_prefix",
    "match_value": "TK"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'journal_id' => 3,
        'direction' => 'sale',
        'match_field' => 'number_prefix',
        'match_value' => 'TK',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "journal_id": 3,
      "direction": "sale",
      "match_field": "number_prefix",
      "match_value": "TK"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "journal_id": 3,
        "direction": "sale",
        "match_field": "number_prefix",
        "match_value": "TK"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/journal-rules/{journalRule}Update a journal rule write

Integration tokens need the write ability.

Operation id companies.journal-rules.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
journalRule requiredintegerId of the journal rule.
e.g. 4

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • journal_idinteger
  • directionstring
    sale purchase
  • match_fieldstring
    payment_provider number_series number_prefix third_party
  • match_valuestring
    100 characters max.
  • priorityinteger
    1 to 999, lowest first.
  • is_activeboolean
Example
{
    "priority": 10
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema JournalRule

Example
{
    "id": 4,
    "company_id": 7,
    "journal_id": 3,
    "direction": "sale",
    "match_field": "payment_provider",
    "match_value": "TK",
    "priority": 100,
    "is_active": true,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "journal": {
        "id": 3,
        "code": "VEN",
        "label": "Ventes",
        "type": "sale"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules/4" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "priority": 10
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules/4', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'priority' => 10,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules/4", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "priority": 10
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules/4",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "priority": 10
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/journal-rules/{journalRule}Delete a journal rule write

Integration tokens need the write ability.

Operation id companies.journal-rules.destroy

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
journalRule requiredintegerId of the journal rule.
e.g. 4

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

204Done, no body.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules/4" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules/4', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules/4", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journal-rules/4",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/documents/seriesNumbering series of the documents read

Series observed in the imported documents (prefix and payment provider) and the journal resolved for each.

Integration tokens need the read ability.

Operation id companies.documents.series

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema object[]

Array of

  • directionstring
    sale purchase
  • is_credit_noteboolean
  • number_seriesstring | null
    e.g. TK
  • payment_providerstring | null
  • documentsinteger
    e.g. 214
  • pendinginteger
    e.g. 6
  • sample_numberstring | null
    e.g. TK-2026-00214
  • journalobject | null
Example
[
    {
        "direction": "sale",
        "is_credit_note": true,
        "number_series": "TK",
        "payment_provider": "string",
        "documents": 214,
        "pending": 6,
        "sample_number": "TK-2026-00214",
        "journal": {}
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/series" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/series', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/series", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/series",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Fiscal years

Fiscal years, periods, locking, closing and year-end.

GET/v1/companies/{company}/fiscal-yearsFiscal years and periods read

Integration tokens need the read ability.

Operation id companies.fiscal-years.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema FiscalYear[]

Array of FiscalYear

Example
[
    {
        "id": 2,
        "company_id": 7,
        "code": "2026",
        "starts_on": "2026-01-01T00:00:00.000000Z",
        "ends_on": "2026-12-31T00:00:00.000000Z",
        "is_closed": false,
        "closed_at": "2026-03-15T09:41:00+00:00",
        "closed_by": 1,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "periods": [
            {
                "id": 16,
                "fiscal_year_id": 2,
                "number": 3,
                "label": "Mars 2026",
                "starts_on": "2026-03-15T09:41:00+00:00",
                "ends_on": "2026-03-15T09:41:00+00:00",
                "is_locked": false,
                "locked_at": "2026-03-15T09:41:00+00:00",
                "lock_version": 3,
                "version": 3
            }
        ]
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/fiscal-yearsOpen a fiscal year write

Creates the year and its periods (opening, one per month, closing).

Integration tokens need the write ability.

Operation id companies.fiscal-years.store

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • codestringrequired
    Unique, 10 characters max.
  • starts_onstring <date>required
  • ends_onstring <date>required
Example
{
    "code": "2027",
    "starts_on": "2027-01-01",
    "ends_on": "2027-12-31"
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema FiscalYear

Example
{
    "id": 2,
    "company_id": 7,
    "code": "2026",
    "starts_on": "2026-01-01T00:00:00.000000Z",
    "ends_on": "2026-12-31T00:00:00.000000Z",
    "is_closed": false,
    "closed_at": "2026-03-15T09:41:00+00:00",
    "closed_by": 1,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "periods": [
        {
            "id": 16,
            "fiscal_year_id": 2,
            "number": 3,
            "label": "Mars 2026",
            "starts_on": "2026-03-15T09:41:00+00:00",
            "ends_on": "2026-03-15T09:41:00+00:00",
            "is_locked": false,
            "locked_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "code": "2027",
    "starts_on": "2027-01-01",
    "ends_on": "2027-12-31"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'code' => '2027',
        'starts_on' => '2027-01-01',
        'ends_on' => '2027-12-31',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "code": "2027",
      "starts_on": "2027-01-01",
      "ends_on": "2027-12-31"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "code": "2027",
        "starts_on": "2027-01-01",
        "ends_on": "2027-12-31"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/fiscal-years/{fiscalYear}/periods/{period}Lock or unlock a period write

No entry can be posted in a locked period. Refused with period_locked (reason fiscal_year_closed) when the fiscal year is closed.

Integration tokens need the write ability.

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.fiscal-years.periods.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2
period requiredintegerId of the period.
e.g. 16

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • is_lockedbooleanrequired
Example
{
    "is_locked": true
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema Period

Example
{
    "id": 16,
    "fiscal_year_id": 2,
    "number": 3,
    "label": "Mars 2026",
    "starts_on": "2026-03-15T09:41:00+00:00",
    "ends_on": "2026-03-15T09:41:00+00:00",
    "is_locked": false,
    "locked_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/periods/16" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "is_locked": true
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/periods/16', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'is_locked' => true,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/periods/16", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "is_locked": true
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/periods/16",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "is_locked": True
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/fiscal-years/{fiscalYear}/closeClose or reopen a fiscal year write

Locks every period. Send reopen: true to reopen. For the closing entries and the carry-forward use year-end.

Integration tokens need the write ability.

Operation id companies.fiscal-years.close

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • reopenboolean
Example
{
    "reopen": false
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema FiscalYear

Example
{
    "id": 2,
    "company_id": 7,
    "code": "2026",
    "starts_on": "2026-01-01T00:00:00.000000Z",
    "ends_on": "2026-12-31T00:00:00.000000Z",
    "is_closed": false,
    "closed_at": "2026-03-15T09:41:00+00:00",
    "closed_by": 1,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "periods": [
        {
            "id": 16,
            "fiscal_year_id": 2,
            "number": 3,
            "label": "Mars 2026",
            "starts_on": "2026-03-15T09:41:00+00:00",
            "ends_on": "2026-03-15T09:41:00+00:00",
            "is_locked": false,
            "locked_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/close" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "reopen": false
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/close', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'reopen' => false,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/close", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "reopen": false
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/close",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "reopen": False
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/fiscal-years/{fiscalYear}/year-endYear-end closing write 5 / 1 min

Posts the closing entry (result), opens the next fiscal year when needed, posts the opening entry (carry-forward of the balance sheet accounts) and closes the year. Emits the webhook fiscal_year.closed.

Integration tokens need the write ability.

Rate limit: 5 requests per minute (429 beyond, see Retry-After).

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.fiscal-years.year-end

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
Example
{
    "result": "18420.11",
    "closing_entry": {
        "id": 1284,
        "company_id": 7,
        "fiscal_year_id": 2,
        "period_id": 16,
        "journal_id": 3,
        "number": 412,
        "entry_date": "2026-03-15T00:00:00.000000Z",
        "due_date": "2026-03-15T09:41:00+00:00",
        "label": "Facture Brasserie Dubuisson SA",
        "reference": "F-2026-0412",
        "structured_communication": "000000000101",
        "third_party_id": 18,
        "status": "posted",
        "origin": "manual",
        "created_by": 1,
        "posted_at": "2026-03-15T09:41:00+00:00",
        "reversed_entry_id": 42,
        "reversed_by_entry_id": 42,
        "recurring_entry_id": 42,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal": {
            "id": 3,
            "code": "VEN",
            "type": "sale"
        },
        "third_party": {
            "id": 18,
            "name": "Brasserie Dubuisson SA"
        },
        "lines": [
            {
                "id": 3391,
                "journal_entry_id": 1284,
                "position": 1,
                "account_id": 580,
                "third_party_id": 18,
                "label": "Brasserie Dubuisson SA",
                "debit": "0.00",
                "credit": "1000.00",
                "vat_code_id": 4,
                "vat_base": "1000.00",
                "reconciliation_code": "AB",
                "cost_center_id": 42,
                "project_id": 42,
                "reminder_level": 0,
                "reminder_sent_at": "2026-03-15T09:41:00+00:00",
                "account": {
                    "id": 580,
                    "number": "702000",
                    "label": "Prestations de services"
                },
                "vat_code": {}
            }
        ]
    },
    "opening_entry": {
        "id": 1284,
        "company_id": 7,
        "fiscal_year_id": 2,
        "period_id": 16,
        "journal_id": 3,
        "number": 412,
        "entry_date": "2026-03-15T00:00:00.000000Z",
        "due_date": "2026-03-15T09:41:00+00:00",
        "label": "Facture Brasserie Dubuisson SA",
        "reference": "F-2026-0412",
        "structured_communication": "000000000101",
        "third_party_id": 18,
        "status": "posted",
        "origin": "manual",
        "created_by": 1,
        "posted_at": "2026-03-15T09:41:00+00:00",
        "reversed_entry_id": 42,
        "reversed_by_entry_id": 42,
        "recurring_entry_id": 42,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal": {
            "id": 3,
            "code": "VEN",
            "type": "sale"
        },
        "third_party": {
            "id": 18,
            "name": "Brasserie Dubuisson SA"
        },
        "lines": [
            {
                "id": 3391,
                "journal_entry_id": 1284,
                "position": 1,
                "account_id": 580,
                "third_party_id": 18,
                "label": "Brasserie Dubuisson SA",
                "debit": "0.00",
                "credit": "1000.00",
                "vat_code_id": 4,
                "vat_base": "1000.00",
                "reconciliation_code": "AB",
                "cost_center_id": 42,
                "project_id": 42,
                "reminder_level": 0,
                "reminder_sent_at": "2026-03-15T09:41:00+00:00",
                "account": {
                    "id": 580,
                    "number": "702000",
                    "label": "Prestations de services"
                },
                "vat_code": {}
            }
        ]
    },
    "fiscal_year": {
        "id": 2,
        "company_id": 7,
        "code": "2026",
        "starts_on": "2026-01-01T00:00:00.000000Z",
        "ends_on": "2026-12-31T00:00:00.000000Z",
        "is_closed": false,
        "closed_at": "2026-03-15T09:41:00+00:00",
        "closed_by": 1,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "periods": [
            {
                "id": 16,
                "fiscal_year_id": 2,
                "number": 3,
                "label": "Mars 2026",
                "starts_on": "2026-03-15T09:41:00+00:00",
                "ends_on": "2026-03-15T09:41:00+00:00",
                "is_locked": false,
                "locked_at": "2026-03-15T09:41:00+00:00",
                "lock_version": 3,
                "version": 3
            }
        ]
    },
    "next_fiscal_year": {
        "id": 2,
        "company_id": 7,
        "code": "2026",
        "starts_on": "2026-01-01T00:00:00.000000Z",
        "ends_on": "2026-12-31T00:00:00.000000Z",
        "is_closed": false,
        "closed_at": "2026-03-15T09:41:00+00:00",
        "closed_by": 1,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "periods": [
            {
                "id": 16,
                "fiscal_year_id": 2,
                "number": 3,
                "label": "Mars 2026",
                "starts_on": "2026-03-15T09:41:00+00:00",
                "ends_on": "2026-03-15T09:41:00+00:00",
                "is_locked": false,
                "locked_at": "2026-03-15T09:41:00+00:00",
                "lock_version": 3,
                "version": 3
            }
        ]
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/year-end" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/year-end', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/year-end", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/year-end",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Third parties

Customers and suppliers: sheet, open items, lettering, reminders, totals, VIES.

GET/v1/companies/{company}/third-partiesList the third parties read

Integration tokens need the read ability.

Operation id companies.third-parties.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
typestring
customer supplier
qstringName, code or VAT number.

Common headers: Accept-Language

Responses

200OK

application/json

Schema ThirdParty[]

Array of ThirdParty

Example
[
    {
        "id": 18,
        "company_id": 7,
        "type": "customer",
        "code": "DUBUISSON",
        "name": "Brasserie Dubuisson SA",
        "contact_name": "string",
        "vat_number": "BE0402531376",
        "enterprise_number": "0402531376",
        "legal_form_code": "string",
        "vat_status": "subject",
        "country": "BE",
        "language": "fr",
        "category": "string",
        "currency": "EUR",
        "address": "Chaussée de Mons 28",
        "house_number": "14",
        "box": "string",
        "address_line_2": "string",
        "postal_code": "7904",
        "city": "Pipaix",
        "nace_code": "string",
        "iban": "BE71096123456769",
        "bic": "GKCCBEBB",
        "bank_account": "string",
        "email": "compta@dubuisson.example",
        "phone": "+32 65 31 42 18",
        "fax": "string",
        "website": "https://www.comptoir-montois.be",
        "payment_terms_days": 30,
        "form_281_50_type": "string",
        "profession_281_50": "string",
        "is_natural_person": false,
        "notes": "string",
        "default_vat_code_id": 42,
        "default_account_id": 42,
        "vies_valid": true,
        "vies_checked_at": "2026-03-15T09:41:00+00:00",
        "vies_name": "string",
        "peppol_identifier": "0208:0402531376",
        "peppol_registered": true,
        "peppol_access_point": {},
        "peppol_document_types": [
            {
                "id": "bis_billing_invoice",
                "name": "Invoice BIS Billing 3.0",
                "family": "billing",
                "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
                "document_id": "string"
            }
        ],
        "peppol_checked_at": "2026-03-15T09:41:00+00:00",
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1,
        "default_account": {},
        "default_vat_code": {}
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/third-partiesCreate a third party write

Integration tokens need the write ability.

Operation id companies.third-parties.store

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • typestringrequired
    customer supplier
  • codestring | null
    Unique per type; generated from the name when absent.
  • namestringrequired
  • contact_namestring | null
  • vat_numberstring | null
    Validated per country.
  • enterprise_numberstring | null
  • legal_form_codestring | null
  • house_numberstring | null
  • boxstring | null
  • nace_codestring | null
  • vat_statusstring
    subject not_subject exempt intra_eu non_eu
  • countrystring | null
    ISO 3166-1 alpha-2, BE by default.
  • languagestring
    fr nl en de
  • categorystring | null
  • currencystring
    ISO 4217.
  • addressstring | null
  • address_line_2string | null
  • postal_codestring | null
  • citystring | null
  • ibanstring | null
  • bicstring | null
  • bank_accountstring | null
  • emailstring <email> | null
  • phonestring | null
  • faxstring | null
  • websitestring | null
  • payment_terms_daysinteger
    0 to 365.
  • form_281_50_typestring | null
  • profession_281_50string | null
  • is_natural_personboolean
  • notesstring | null
  • default_vat_code_idinteger | null
  • default_account_idinteger | null
Example
{
    "type": "supplier",
    "name": "Brasserie Dubuisson SA",
    "vat_number": "BE 0402.531.376",
    "address": "Chaussée de Mons 28",
    "postal_code": "7904",
    "city": "Pipaix",
    "iban": "BE71 0961 2345 6769",
    "payment_terms_days": 30
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema ThirdParty

Example
{
    "id": 18,
    "company_id": 7,
    "type": "customer",
    "code": "DUBUISSON",
    "name": "Brasserie Dubuisson SA",
    "contact_name": "string",
    "vat_number": "BE0402531376",
    "enterprise_number": "0402531376",
    "legal_form_code": "string",
    "vat_status": "subject",
    "country": "BE",
    "language": "fr",
    "category": "string",
    "currency": "EUR",
    "address": "Chaussée de Mons 28",
    "house_number": "14",
    "box": "string",
    "address_line_2": "string",
    "postal_code": "7904",
    "city": "Pipaix",
    "nace_code": "string",
    "iban": "BE71096123456769",
    "bic": "GKCCBEBB",
    "bank_account": "string",
    "email": "compta@dubuisson.example",
    "phone": "+32 65 31 42 18",
    "fax": "string",
    "website": "https://www.comptoir-montois.be",
    "payment_terms_days": 30,
    "form_281_50_type": "string",
    "profession_281_50": "string",
    "is_natural_person": false,
    "notes": "string",
    "default_vat_code_id": 42,
    "default_account_id": 42,
    "vies_valid": true,
    "vies_checked_at": "2026-03-15T09:41:00+00:00",
    "vies_name": "string",
    "peppol_identifier": "0208:0402531376",
    "peppol_registered": true,
    "peppol_access_point": {},
    "peppol_document_types": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "peppol_checked_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "default_account": {},
    "default_vat_code": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "type": "supplier",
    "name": "Brasserie Dubuisson SA",
    "vat_number": "BE 0402.531.376",
    "address": "Chaussée de Mons 28",
    "postal_code": "7904",
    "city": "Pipaix",
    "iban": "BE71 0961 2345 6769",
    "payment_terms_days": 30
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'type' => 'supplier',
        'name' => 'Brasserie Dubuisson SA',
        'vat_number' => 'BE 0402.531.376',
        'address' => 'Chaussée de Mons 28',
        'postal_code' => '7904',
        'city' => 'Pipaix',
        'iban' => 'BE71 0961 2345 6769',
        'payment_terms_days' => 30,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "type": "supplier",
      "name": "Brasserie Dubuisson SA",
      "vat_number": "BE 0402.531.376",
      "address": "Chaussée de Mons 28",
      "postal_code": "7904",
      "city": "Pipaix",
      "iban": "BE71 0961 2345 6769",
      "payment_terms_days": 30
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "type": "supplier",
        "name": "Brasserie Dubuisson SA",
        "vat_number": "BE 0402.531.376",
        "address": "Chaussée de Mons 28",
        "postal_code": "7904",
        "city": "Pipaix",
        "iban": "BE71 0961 2345 6769",
        "payment_terms_days": 30
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/third-parties/{thirdParty}Third party sheet read

With its default account and VAT code.

Integration tokens need the read ability.

Operation id companies.third-parties.show

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Common headers: Accept-Language

Responses

200OK

application/json

Schema ThirdParty

Example
{
    "id": 18,
    "company_id": 7,
    "type": "customer",
    "code": "DUBUISSON",
    "name": "Brasserie Dubuisson SA",
    "contact_name": "string",
    "vat_number": "BE0402531376",
    "enterprise_number": "0402531376",
    "legal_form_code": "string",
    "vat_status": "subject",
    "country": "BE",
    "language": "fr",
    "category": "string",
    "currency": "EUR",
    "address": "Chaussée de Mons 28",
    "house_number": "14",
    "box": "string",
    "address_line_2": "string",
    "postal_code": "7904",
    "city": "Pipaix",
    "nace_code": "string",
    "iban": "BE71096123456769",
    "bic": "GKCCBEBB",
    "bank_account": "string",
    "email": "compta@dubuisson.example",
    "phone": "+32 65 31 42 18",
    "fax": "string",
    "website": "https://www.comptoir-montois.be",
    "payment_terms_days": 30,
    "form_281_50_type": "string",
    "profession_281_50": "string",
    "is_natural_person": false,
    "notes": "string",
    "default_vat_code_id": 42,
    "default_account_id": 42,
    "vies_valid": true,
    "vies_checked_at": "2026-03-15T09:41:00+00:00",
    "vies_name": "string",
    "peppol_identifier": "0208:0402531376",
    "peppol_registered": true,
    "peppol_access_point": {},
    "peppol_document_types": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "peppol_checked_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "default_account": {},
    "default_vat_code": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/third-parties/{thirdParty}Update a third party write

Integration tokens need the write ability.

Operation id companies.third-parties.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • codestring | null
    Unique per type; generated from the name when absent.
  • namestring
  • contact_namestring | null
  • vat_numberstring | null
    Validated per country.
  • enterprise_numberstring | null
  • legal_form_codestring | null
  • house_numberstring | null
  • boxstring | null
  • nace_codestring | null
  • vat_statusstring
    subject not_subject exempt intra_eu non_eu
  • countrystring | null
    ISO 3166-1 alpha-2, BE by default.
  • languagestring
    fr nl en de
  • categorystring | null
  • currencystring
    ISO 4217.
  • addressstring | null
  • address_line_2string | null
  • postal_codestring | null
  • citystring | null
  • ibanstring | null
  • bicstring | null
  • bank_accountstring | null
  • emailstring <email> | null
  • phonestring | null
  • faxstring | null
  • websitestring | null
  • payment_terms_daysinteger
    0 to 365.
  • form_281_50_typestring | null
  • profession_281_50string | null
  • is_natural_personboolean
  • notesstring | null
  • default_vat_code_idinteger | null
  • default_account_idinteger | null
Example
{
    "payment_terms_days": 45,
    "email": "compta@dubuisson.example"
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema ThirdParty

Example
{
    "id": 18,
    "company_id": 7,
    "type": "customer",
    "code": "DUBUISSON",
    "name": "Brasserie Dubuisson SA",
    "contact_name": "string",
    "vat_number": "BE0402531376",
    "enterprise_number": "0402531376",
    "legal_form_code": "string",
    "vat_status": "subject",
    "country": "BE",
    "language": "fr",
    "category": "string",
    "currency": "EUR",
    "address": "Chaussée de Mons 28",
    "house_number": "14",
    "box": "string",
    "address_line_2": "string",
    "postal_code": "7904",
    "city": "Pipaix",
    "nace_code": "string",
    "iban": "BE71096123456769",
    "bic": "GKCCBEBB",
    "bank_account": "string",
    "email": "compta@dubuisson.example",
    "phone": "+32 65 31 42 18",
    "fax": "string",
    "website": "https://www.comptoir-montois.be",
    "payment_terms_days": 30,
    "form_281_50_type": "string",
    "profession_281_50": "string",
    "is_natural_person": false,
    "notes": "string",
    "default_vat_code_id": 42,
    "default_account_id": 42,
    "vies_valid": true,
    "vies_checked_at": "2026-03-15T09:41:00+00:00",
    "vies_name": "string",
    "peppol_identifier": "0208:0402531376",
    "peppol_registered": true,
    "peppol_access_point": {},
    "peppol_document_types": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "peppol_checked_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "default_account": {},
    "default_vat_code": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "payment_terms_days": 45,
    "email": "compta@dubuisson.example"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'payment_terms_days' => 45,
        'email' => 'compta@dubuisson.example',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "payment_terms_days": 45,
      "email": "compta@dubuisson.example"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "payment_terms_days": 45,
        "email": "compta@dubuisson.example"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/third-parties/{thirdParty}Delete a third party write

Refused (422) when an entry or a document references it. Goes to the recycle bin.

Integration tokens need the write ability.

Operation id companies.third-parties.destroy

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

204Done, no body.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/third-parties/{thirdParty}/entriesOpen items and entries of a third party read

Integration tokens need the read ability.

Operation id companies.third-parties.entries

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Query parameters

NameTypeDescription
letteredstring
all yes no
fiscal_year_idinteger

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • rowsobject[]
    Properties
    • line_idinteger
      e.g. 3391
    • entry_idinteger
      e.g. 1284
    • journal_codestring
      e.g. VEN
    • entry_numberinteger
      e.g. 412
    • document_numberstring | null
      e.g. 2026/0412
    • period_numberinteger
      e.g. 3
    • entry_datestring <date>
    • due_datestring <date> | null
    • amountstring <decimal>
      e.g. 1210.00
    • debitstring <decimal>
      e.g. 1210.00
    • creditstring <decimal>
      e.g. 0.00
    • reconciliation_codestring | null
    • labelstring | null
    • reminder_levelinteger
      e.g. 0
    • reminder_sent_atstring <date-time> | null
    • is_letteredboolean
      e.g. false
  • summaryobject
    Properties
    • balancestring <decimal>
      e.g. 1210.00
    • open_countinteger
      e.g. 1
    • lettered_countinteger
      e.g. 0
Example
{
    "rows": [
        {
            "line_id": 3391,
            "entry_id": 1284,
            "journal_code": "VEN",
            "entry_number": 412,
            "document_number": "2026/0412",
            "period_number": 3,
            "entry_date": "2026-03-15",
            "due_date": "2026-03-15",
            "amount": "1210.00",
            "debit": "1210.00",
            "credit": "0.00",
            "reconciliation_code": "string",
            "label": "Facture Brasserie Dubuisson",
            "reminder_level": 0,
            "reminder_sent_at": "2026-03-15T09:41:00+00:00",
            "is_lettered": false
        }
    ],
    "summary": {
        "balance": "1210.00",
        "open_count": 1,
        "lettered_count": 0
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/entries" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/entries', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/entries", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/entries",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/third-parties/{thirdParty}/letterLetter lines together write

Matches lines of the third party whose debits and credits balance (a small difference is posted to the difference accounts of the settings).

Integration tokens need the write ability.

Operation id companies.third-parties.letter

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • line_idsinteger[]required
Example
{
    "line_ids": [
        3391,
        3518
    ]
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
  • codestring
    Lettering code given.
    e.g. AB
  • line_idsinteger[]
Example
{
    "code": "AB",
    "line_ids": [
        1
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/letter" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "line_ids": [
        3391,
        3518
    ]
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/letter', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'line_ids' => [
            3391,
            3518,
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/letter", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "line_ids": [
          3391,
          3518
      ]
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/letter",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "line_ids": [
            3391,
            3518
        ]
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/third-parties/{thirdParty}/unletterRemove a lettering write

By lettering code or by lines.

Integration tokens need the write ability.

Operation id companies.third-parties.unletter

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • codestring | null
  • line_idsinteger[]
Example
{
    "code": "AB"
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
  • codesstring[]
  • line_idsinteger[]
Example
{
    "codes": [
        "AB"
    ],
    "line_ids": [
        1
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/unletter" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "code": "AB"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/unletter', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'code' => 'AB',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/unletter", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "code": "AB"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/unletter",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "code": "AB"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/third-parties/{thirdParty}/letter-autoAutomatic lettering write

Letters every group of open lines that balances exactly.

Integration tokens need the write ability.

Operation id companies.third-parties.letter-auto

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
  • groupsinteger
    e.g. 3
  • line_idsinteger[]
Example
{
    "groups": 3,
    "line_ids": [
        1
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/letter-auto" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/letter-auto', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/letter-auto", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/letter-auto",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/third-parties/{thirdParty}/entries/{line}/remindRecord a payment reminder write Not in demo

Raises the reminder level of an open line and stamps the date. No e-mail is sent by this endpoint.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Operation id companies.third-parties.remind

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18
line requiredintegerId of the line.
e.g. 3391

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object

The row, as in the entries list.

Example
{}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/entries/3391/remind" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/entries/3391/remind', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/entries/3391/remind", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/entries/3391/remind",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/third-parties/{thirdParty}/remindersReminders of a third party read

Integration tokens need the read ability.

Operation id companies.third-parties.reminders

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Common headers: Accept-Language

Responses

200OK

application/json

Schema object[]

Array of object

Example
[
    {}
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/reminders" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/reminders', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/reminders", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/reminders",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/third-parties/{thirdParty}/totalsTotals per period read

Integration tokens need the read ability.

Operation id companies.third-parties.totals

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Query parameters

NameTypeDescription
modestring
balance debit credit
fiscal_year_idinteger

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • fiscal_yearobject
    Properties
    • idinteger
    • codestring
      e.g. 2026
  • modestring
    e.g. balance
  • rowsobject[]
    Properties
    • period_numberinteger
      e.g. 1
    • period_labelstring
      e.g. Janvier 2026
    • amountstring <decimal>
  • totalstring <decimal>
Example
{
    "fiscal_year": {
        "id": 42,
        "code": "2026"
    },
    "mode": "balance",
    "rows": [
        {
            "period_number": 1,
            "period_label": "Janvier 2026",
            "amount": "1210.00"
        }
    ],
    "total": "1210.00"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/totals" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/totals', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/totals", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/totals",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/viesCheck a VAT number with VIES read Not in demo 30 / 1 min

Integration tokens need the read ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 30 requests per minute (429 beyond, see Retry-After).

Operation id companies.vies.check

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
vat_number requiredstring
e.g. BE0402531376

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • validboolean | null
    Null when VIES did not answer.
  • namestring | null
    e.g. BRASSERIE DUBUISSON
  • addressstring | null
  • countrystring
    e.g. BE
  • numberstring
    e.g. 0402531376
  • errorstring | null
    invalid_format, service_unavailable or the VIES user error.
Example
{
    "valid": true,
    "name": "BRASSERIE DUBUISSON",
    "address": "Grand-Place 14",
    "country": "BE",
    "number": "0402531376",
    "error": "string"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vies?vat_number=BE0402531376" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vies', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'query' => [
        'vat_number' => 'BE0402531376',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vies?vat_number=BE0402531376", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vies",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    params={
        "vat_number": "BE0402531376"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/third-parties/{thirdParty}/viesCheck the VAT number of a third party with VIES write Not in demo 30 / 1 min

Stores the result on the third party (vies_valid, vies_checked_at, vies_name).

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 30 requests per minute (429 beyond, see Retry-After).

Operation id companies.third-parties.vies

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • validboolean | null
    Null when VIES did not answer.
  • namestring | null
    e.g. BRASSERIE DUBUISSON
  • addressstring | null
  • countrystring
    e.g. BE
  • numberstring
    e.g. 0402531376
  • errorstring | null
    invalid_format, service_unavailable or the VIES user error.
  • third_partyThirdParty
Example
{
    "valid": true,
    "name": "BRASSERIE DUBUISSON",
    "address": "Grand-Place 14",
    "country": "BE",
    "number": "0402531376",
    "error": "string",
    "third_party": {
        "id": 18,
        "company_id": 7,
        "type": "customer",
        "code": "DUBUISSON",
        "name": "Brasserie Dubuisson SA",
        "contact_name": "string",
        "vat_number": "BE0402531376",
        "enterprise_number": "0402531376",
        "legal_form_code": "string",
        "vat_status": "subject",
        "country": "BE",
        "language": "fr",
        "category": "string",
        "currency": "EUR",
        "address": "Chaussée de Mons 28",
        "house_number": "14",
        "box": "string",
        "address_line_2": "string",
        "postal_code": "7904",
        "city": "Pipaix",
        "nace_code": "string",
        "iban": "BE71096123456769",
        "bic": "GKCCBEBB",
        "bank_account": "string",
        "email": "compta@dubuisson.example",
        "phone": "+32 65 31 42 18",
        "fax": "string",
        "website": "https://www.comptoir-montois.be",
        "payment_terms_days": 30,
        "form_281_50_type": "string",
        "profession_281_50": "string",
        "is_natural_person": false,
        "notes": "string",
        "default_vat_code_id": 42,
        "default_account_id": 42,
        "vies_valid": true,
        "vies_checked_at": "2026-03-15T09:41:00+00:00",
        "vies_name": "string",
        "peppol_identifier": "0208:0402531376",
        "peppol_registered": true,
        "peppol_access_point": {},
        "peppol_document_types": [
            {
                "id": "bis_billing_invoice",
                "name": "Invoice BIS Billing 3.0",
                "family": "billing",
                "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
                "document_id": "string"
            }
        ],
        "peppol_checked_at": "2026-03-15T09:41:00+00:00",
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1,
        "default_account": {},
        "default_vat_code": {}
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/vies" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/vies', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/vies", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/vies",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Entries

Journal entries: free entries, invoices and credit notes, reversal.

GET/v1/companies/{company}/entriesList the entries read

Newest first, with their journal, third party and lines.

Integration tokens need the read ability.

Operation id companies.entries.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
journal_idinteger
fiscal_year_idinteger
third_party_idinteger
fromstring <date>Entry date, inclusive.
tostring <date>Entry date, inclusive.
statusstring
posted reversed
qstringLabel, reference, structured communication, third party name, line label or account number prefix.
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 1284,
            "company_id": 7,
            "fiscal_year_id": 2,
            "period_id": 16,
            "journal_id": 3,
            "number": 412,
            "entry_date": "2026-03-15T00:00:00.000000Z",
            "due_date": "2026-03-15T09:41:00+00:00",
            "label": "Facture Brasserie Dubuisson SA",
            "reference": "F-2026-0412",
            "structured_communication": "000000000101",
            "third_party_id": 18,
            "status": "posted",
            "origin": "manual",
            "created_by": 1,
            "posted_at": "2026-03-15T09:41:00+00:00",
            "reversed_entry_id": 42,
            "reversed_by_entry_id": 42,
            "recurring_entry_id": 42,
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "journal": {
                "id": 3,
                "code": "VEN",
                "type": "sale"
            },
            "third_party": {
                "id": 18,
                "name": "Brasserie Dubuisson SA"
            },
            "lines": [
                {}
            ]
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/entriesPost a free entry write

Miscellaneous operation, financial entry…: every line is given, debits must equal credits. The entry is posted at once and numbered in its journal. Accounts are addressed by account_id or by number (account). A date in a locked period or a closed fiscal year is refused with 422 period_locked.

Integration tokens need the write ability.

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.entries.store

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • journal_idintegerrequired
  • entry_datestring <date>required
    Inside an open fiscal year and an unlocked period.
  • due_datestring <date> | null
  • labelstringrequired
    200 characters max.
  • referencestring | null
    60 characters max.
  • structured_communicationstring | null
    Belgian structured communication.
  • third_party_idinteger | null
  • linesobject[]required
    Properties
    • account_idinteger
      Required without account.
    • accountstring
      Account number; required without account_id.
    • debitstring | null
      Decimal, positive.
    • creditstring | null
      Decimal, positive.
    • labelstring | null
    • third_party_idinteger | null
    • vat_code_idinteger | null
    • vat_basestring | null
      Taxable base carried by the line.
    • cost_center_idinteger | null
      Analytic code of the cost_center axis.
    • project_idinteger | null
      Analytic code of the project axis.
Example
{
    "journal_id": 5,
    "entry_date": "2026-03-31",
    "label": "Salaires mars 2026",
    "reference": "SAL-2026-03",
    "lines": [
        {
            "account": "620200",
            "debit": "8420.00",
            "label": "Rémunérations brutes"
        },
        {
            "account": "453000",
            "credit": "2105.00",
            "label": "Précompte professionnel"
        },
        {
            "account": "454000",
            "credit": "1100.48",
            "label": "ONSS"
        },
        {
            "account": "455000",
            "credit": "5214.52",
            "label": "Net à payer"
        }
    ]
}

Responses

201Entry posted

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema JournalEntry

Example
{
    "id": 1284,
    "company_id": 7,
    "fiscal_year_id": 2,
    "period_id": 16,
    "journal_id": 3,
    "number": 412,
    "entry_date": "2026-03-15T00:00:00.000000Z",
    "due_date": "2026-03-15T09:41:00+00:00",
    "label": "Facture Brasserie Dubuisson SA",
    "reference": "F-2026-0412",
    "structured_communication": "000000000101",
    "third_party_id": 18,
    "status": "posted",
    "origin": "manual",
    "created_by": 1,
    "posted_at": "2026-03-15T09:41:00+00:00",
    "reversed_entry_id": 42,
    "reversed_by_entry_id": 42,
    "recurring_entry_id": 42,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal": {
        "id": 3,
        "code": "VEN",
        "type": "sale"
    },
    "third_party": {
        "id": 18,
        "name": "Brasserie Dubuisson SA"
    },
    "lines": [
        {
            "id": 3391,
            "journal_entry_id": 1284,
            "position": 1,
            "account_id": 580,
            "third_party_id": 18,
            "label": "Brasserie Dubuisson SA",
            "debit": "0.00",
            "credit": "1000.00",
            "vat_code_id": 4,
            "vat_base": "1000.00",
            "reconciliation_code": "AB",
            "cost_center_id": 42,
            "project_id": 42,
            "reminder_level": 0,
            "reminder_sent_at": "2026-03-15T09:41:00+00:00",
            "account": {
                "id": 580,
                "number": "702000",
                "label": "Prestations de services"
            },
            "vat_code": {}
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "journal_id": 5,
    "entry_date": "2026-03-31",
    "label": "Salaires mars 2026",
    "reference": "SAL-2026-03",
    "lines": [
        {
            "account": "620200",
            "debit": "8420.00",
            "label": "Rémunérations brutes"
        },
        {
            "account": "453000",
            "credit": "2105.00",
            "label": "Précompte professionnel"
        },
        {
            "account": "454000",
            "credit": "1100.48",
            "label": "ONSS"
        },
        {
            "account": "455000",
            "credit": "5214.52",
            "label": "Net à payer"
        }
    ]
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'journal_id' => 5,
        'entry_date' => '2026-03-31',
        'label' => 'Salaires mars 2026',
        'reference' => 'SAL-2026-03',
        'lines' => [
            [
                'account' => '620200',
                'debit' => '8420.00',
                'label' => 'Rémunérations brutes',
            ],
            [
                'account' => '453000',
                'credit' => '2105.00',
                'label' => 'Précompte professionnel',
            ],
            [
                'account' => '454000',
                'credit' => '1100.48',
                'label' => 'ONSS',
            ],
            [
                'account' => '455000',
                'credit' => '5214.52',
                'label' => 'Net à payer',
            ],
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "journal_id": 5,
      "entry_date": "2026-03-31",
      "label": "Salaires mars 2026",
      "reference": "SAL-2026-03",
      "lines": [
          {
              "account": "620200",
              "debit": "8420.00",
              "label": "Rémunérations brutes"
          },
          {
              "account": "453000",
              "credit": "2105.00",
              "label": "Précompte professionnel"
          },
          {
              "account": "454000",
              "credit": "1100.48",
              "label": "ONSS"
          },
          {
              "account": "455000",
              "credit": "5214.52",
              "label": "Net à payer"
          }
      ]
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "journal_id": 5,
        "entry_date": "2026-03-31",
        "label": "Salaires mars 2026",
        "reference": "SAL-2026-03",
        "lines": [
            {
                "account": "620200",
                "debit": "8420.00",
                "label": "Rémunérations brutes"
            },
            {
                "account": "453000",
                "credit": "2105.00",
                "label": "Précompte professionnel"
            },
            {
                "account": "454000",
                "credit": "1100.48",
                "label": "ONSS"
            },
            {
                "account": "455000",
                "credit": "5214.52",
                "label": "Net à payer"
            }
        ]
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/entries/invoicePost an invoice or a credit note write

Purchase or sale invoice (journal of type purchase / sale) or credit note (journal of type purchase_credit_note / sale_credit_note). Send the net lines with their VAT code: the VAT lines and the third party line are generated, including reverse charge (intra-EU, co-contractor). The label defaults to « Facture <third party> ». A date in a locked period or a closed fiscal year is refused with 422 period_locked.

Integration tokens need the write ability.

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.entries.invoice

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • journal_idintegerrequired
    Journal of a purchase or sale type.
  • third_party_idintegerrequired
  • entry_datestring <date>required
  • due_datestring <date> | null
  • labelstring | null
  • referencestring | null
    Invoice number.
  • structured_communicationstring | null
  • linesobject[]required
    Properties
    • account_idinteger
      Required without account.
    • accountstring
      Account number.
    • amountstringrequired
      Net amount (excl. VAT), decimal.
    • vat_code_idinteger | null
    • vat_codestring | null
      Code of the VAT code (V21, A06, AIC21…).
    • labelstring | null
    • cost_center_idinteger | null
      Analytic code of the cost_center axis.
    • project_idinteger | null
      Analytic code of the project axis.
Example
{
    "journal_id": 1,
    "third_party_id": 18,
    "entry_date": "2026-03-15",
    "due_date": "2026-04-14",
    "reference": "F-2026-0412",
    "lines": [
        {
            "account": "604000",
            "amount": "507.00",
            "vat_code": "A21",
            "label": "Fûts Bush Caractère 20 L"
        },
        {
            "account": "613200",
            "amount": "35.00",
            "vat_code": "A21",
            "label": "Consigne et transport"
        }
    ]
}

Responses

201Invoice posted

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema JournalEntry

Example
{
    "id": 1284,
    "company_id": 7,
    "fiscal_year_id": 2,
    "period_id": 16,
    "journal_id": 1,
    "number": 412,
    "entry_date": "2026-03-15T00:00:00.000000Z",
    "due_date": "2026-04-14T00:00:00.000000Z",
    "label": "Facture Brasserie Dubuisson SA",
    "reference": "F-2026-0412",
    "structured_communication": null,
    "third_party_id": 18,
    "status": "posted",
    "origin": "manual",
    "created_by": 12,
    "posted_at": "2026-03-16T08:12:40.000000Z",
    "reversed_entry_id": null,
    "reversed_by_entry_id": null,
    "recurring_entry_id": null,
    "created_at": "2026-03-16T08:12:40.000000Z",
    "updated_at": "2026-03-16T08:12:40.000000Z",
    "lock_version": 1,
    "version": 1,
    "lines": [
        {
            "id": 3391,
            "journal_entry_id": 1284,
            "position": 1,
            "account_id": 361,
            "third_party_id": null,
            "label": "Fûts Bush Caractère 20 L",
            "debit": "507.00",
            "credit": "0.00",
            "vat_code_id": 25,
            "vat_base": "507.00",
            "reconciliation_code": null,
            "cost_center_id": null,
            "project_id": null,
            "reminder_level": 0,
            "reminder_sent_at": null,
            "account": {
                "id": 361,
                "number": "604000",
                "label": "Achats de marchandises"
            }
        },
        {
            "id": 3392,
            "journal_entry_id": 1284,
            "position": 2,
            "account_id": 384,
            "third_party_id": null,
            "label": "Consigne et transport",
            "debit": "35.00",
            "credit": "0.00",
            "vat_code_id": 25,
            "vat_base": "35.00",
            "reconciliation_code": null,
            "cost_center_id": null,
            "project_id": null,
            "reminder_level": 0,
            "reminder_sent_at": null,
            "account": {
                "id": 384,
                "number": "613200",
                "label": "Transports et déplacements"
            }
        },
        {
            "id": 3393,
            "journal_entry_id": 1284,
            "position": 3,
            "account_id": 234,
            "third_party_id": null,
            "label": "TVA déductible",
            "debit": "113.82",
            "credit": "0.00",
            "vat_code_id": null,
            "vat_base": null,
            "reconciliation_code": null,
            "cost_center_id": null,
            "project_id": null,
            "reminder_level": 0,
            "reminder_sent_at": null,
            "account": {
                "id": 234,
                "number": "411100",
                "label": "TVA déductible sur achats"
            }
        },
        {
            "id": 3394,
            "journal_entry_id": 1284,
            "position": 4,
            "account_id": 263,
            "third_party_id": 18,
            "label": "Brasserie Dubuisson SA",
            "debit": "0.00",
            "credit": "655.82",
            "vat_code_id": null,
            "vat_base": null,
            "reconciliation_code": null,
            "cost_center_id": null,
            "project_id": null,
            "reminder_level": 0,
            "reminder_sent_at": null,
            "account": {
                "id": 263,
                "number": "440000",
                "label": "Fournisseurs"
            }
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/invoice" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "journal_id": 1,
    "third_party_id": 18,
    "entry_date": "2026-03-15",
    "due_date": "2026-04-14",
    "reference": "F-2026-0412",
    "lines": [
        {
            "account": "604000",
            "amount": "507.00",
            "vat_code": "A21",
            "label": "Fûts Bush Caractère 20 L"
        },
        {
            "account": "613200",
            "amount": "35.00",
            "vat_code": "A21",
            "label": "Consigne et transport"
        }
    ]
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/invoice', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'journal_id' => 1,
        'third_party_id' => 18,
        'entry_date' => '2026-03-15',
        'due_date' => '2026-04-14',
        'reference' => 'F-2026-0412',
        'lines' => [
            [
                'account' => '604000',
                'amount' => '507.00',
                'vat_code' => 'A21',
                'label' => 'Fûts Bush Caractère 20 L',
            ],
            [
                'account' => '613200',
                'amount' => '35.00',
                'vat_code' => 'A21',
                'label' => 'Consigne et transport',
            ],
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/invoice", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "journal_id": 1,
      "third_party_id": 18,
      "entry_date": "2026-03-15",
      "due_date": "2026-04-14",
      "reference": "F-2026-0412",
      "lines": [
          {
              "account": "604000",
              "amount": "507.00",
              "vat_code": "A21",
              "label": "Fûts Bush Caractère 20 L"
          },
          {
              "account": "613200",
              "amount": "35.00",
              "vat_code": "A21",
              "label": "Consigne et transport"
          }
      ]
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/invoice",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "journal_id": 1,
        "third_party_id": 18,
        "entry_date": "2026-03-15",
        "due_date": "2026-04-14",
        "reference": "F-2026-0412",
        "lines": [
            {
                "account": "604000",
                "amount": "507.00",
                "vat_code": "A21",
                "label": "Fûts Bush Caractère 20 L"
            },
            {
                "account": "613200",
                "amount": "35.00",
                "vat_code": "A21",
                "label": "Consigne et transport"
            }
        ]
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/entries/{journalEntry}Entry read

With journal, third party, fiscal year, period and lines (account and VAT code).

Integration tokens need the read ability.

Operation id companies.entries.show

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
journalEntry requiredintegerId of the journal entry.
e.g. 1284

Common headers: Accept-Language

Responses

200OK

application/json

Schema JournalEntry

Example
{
    "id": 1284,
    "company_id": 7,
    "fiscal_year_id": 2,
    "period_id": 16,
    "journal_id": 1,
    "number": 412,
    "entry_date": "2026-03-15T00:00:00.000000Z",
    "due_date": "2026-04-14T00:00:00.000000Z",
    "label": "Facture Brasserie Dubuisson SA",
    "reference": "F-2026-0412",
    "structured_communication": null,
    "third_party_id": 18,
    "status": "posted",
    "origin": "manual",
    "created_by": 12,
    "posted_at": "2026-03-16T08:12:40.000000Z",
    "reversed_entry_id": null,
    "reversed_by_entry_id": null,
    "recurring_entry_id": null,
    "created_at": "2026-03-16T08:12:40.000000Z",
    "updated_at": "2026-03-16T08:12:40.000000Z",
    "lock_version": 1,
    "version": 1,
    "lines": [
        {
            "id": 3391,
            "journal_entry_id": 1284,
            "position": 1,
            "account_id": 361,
            "third_party_id": null,
            "label": "Fûts Bush Caractère 20 L",
            "debit": "507.00",
            "credit": "0.00",
            "vat_code_id": 25,
            "vat_base": "507.00",
            "reconciliation_code": null,
            "cost_center_id": null,
            "project_id": null,
            "reminder_level": 0,
            "reminder_sent_at": null,
            "account": {
                "id": 361,
                "number": "604000",
                "label": "Achats de marchandises"
            }
        },
        {
            "id": 3392,
            "journal_entry_id": 1284,
            "position": 2,
            "account_id": 384,
            "third_party_id": null,
            "label": "Consigne et transport",
            "debit": "35.00",
            "credit": "0.00",
            "vat_code_id": 25,
            "vat_base": "35.00",
            "reconciliation_code": null,
            "cost_center_id": null,
            "project_id": null,
            "reminder_level": 0,
            "reminder_sent_at": null,
            "account": {
                "id": 384,
                "number": "613200",
                "label": "Transports et déplacements"
            }
        },
        {
            "id": 3393,
            "journal_entry_id": 1284,
            "position": 3,
            "account_id": 234,
            "third_party_id": null,
            "label": "TVA déductible",
            "debit": "113.82",
            "credit": "0.00",
            "vat_code_id": null,
            "vat_base": null,
            "reconciliation_code": null,
            "cost_center_id": null,
            "project_id": null,
            "reminder_level": 0,
            "reminder_sent_at": null,
            "account": {
                "id": 234,
                "number": "411100",
                "label": "TVA déductible sur achats"
            }
        },
        {
            "id": 3394,
            "journal_entry_id": 1284,
            "position": 4,
            "account_id": 263,
            "third_party_id": 18,
            "label": "Brasserie Dubuisson SA",
            "debit": "0.00",
            "credit": "655.82",
            "vat_code_id": null,
            "vat_base": null,
            "reconciliation_code": null,
            "cost_center_id": null,
            "project_id": null,
            "reminder_level": 0,
            "reminder_sent_at": null,
            "account": {
                "id": 263,
                "number": "440000",
                "label": "Fournisseurs"
            }
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/1284" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/1284', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/1284", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/1284",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/entries/{journalEntry}Delete an entry write

Always refused (422) for a posted entry: numbering is continuous and the audit trail is kept. Use reverse. In a locked period the refusal carries period_locked.

Integration tokens need the write ability.

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.entries.destroy

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
journalEntry requiredintegerId of the journal entry.
e.g. 1284

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

204Done, no body.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/1284" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/1284', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/1284", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/1284",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/entries/{journalEntry}/reverseReverse an entry write

Posts the mirror entry (« Extourne de VEN 2026/000412 ») linked to the original, which becomes reversed. The linked document or bank transaction goes back to pending, letterings of the lines are removed and a depreciation line goes back to planned.

Integration tokens need the write ability.

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.entries.reverse

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
journalEntry requiredintegerId of the journal entry.
e.g. 1284

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • entry_datestring <date> | null
    Date of the reversal; the original date by default.
  • labelstring | null
Example
{
    "entry_date": "2026-03-31"
}

Responses

201Reversal entry

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema JournalEntry

Example
{
    "id": 1284,
    "company_id": 7,
    "fiscal_year_id": 2,
    "period_id": 16,
    "journal_id": 3,
    "number": 412,
    "entry_date": "2026-03-15T00:00:00.000000Z",
    "due_date": "2026-03-15T09:41:00+00:00",
    "label": "Facture Brasserie Dubuisson SA",
    "reference": "F-2026-0412",
    "structured_communication": "000000000101",
    "third_party_id": 18,
    "status": "posted",
    "origin": "manual",
    "created_by": 1,
    "posted_at": "2026-03-15T09:41:00+00:00",
    "reversed_entry_id": 42,
    "reversed_by_entry_id": 42,
    "recurring_entry_id": 42,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal": {
        "id": 3,
        "code": "VEN",
        "type": "sale"
    },
    "third_party": {
        "id": 18,
        "name": "Brasserie Dubuisson SA"
    },
    "lines": [
        {
            "id": 3391,
            "journal_entry_id": 1284,
            "position": 1,
            "account_id": 580,
            "third_party_id": 18,
            "label": "Brasserie Dubuisson SA",
            "debit": "0.00",
            "credit": "1000.00",
            "vat_code_id": 4,
            "vat_base": "1000.00",
            "reconciliation_code": "AB",
            "cost_center_id": 42,
            "project_id": 42,
            "reminder_level": 0,
            "reminder_sent_at": "2026-03-15T09:41:00+00:00",
            "account": {
                "id": 580,
                "number": "702000",
                "label": "Prestations de services"
            },
            "vat_code": {}
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/1284/reverse" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "entry_date": "2026-03-31"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/1284/reverse', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'entry_date' => '2026-03-31',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/1284/reverse", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "entry_date": "2026-03-31"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/1284/reverse",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "entry_date": "2026-03-31"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Recurring entries

Recurring entry templates and the quality checks of the file.

GET/v1/companies/{company}/recurring-entriesList the recurring entries read

Integration tokens need the read ability.

Operation id companies.recurring.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema RecurringEntry[]

Array of RecurringEntry

Example
[
    {
        "id": 5,
        "company_id": 7,
        "journal_id": 5,
        "label": "Loyer mensuel",
        "reference": "F-2026-0412",
        "third_party_id": 18,
        "frequency": "monthly",
        "next_date": "2026-04-01T00:00:00.000000Z",
        "end_date": "2026-03-15T09:41:00+00:00",
        "lines": [
            {
                "account_id": 368,
                "debit": "1500.00",
                "credit": "0.00",
                "label": "Facture Brasserie Dubuisson",
                "third_party_id": 18
            }
        ],
        "is_active": true,
        "last_generated_on": "2026-03-15",
        "generated_count": 3,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1,
        "journal": {
            "id": 42,
            "code": "OD",
            "label": "Opérations diverses"
        },
        "third_party": {}
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/recurring-entriesCreate a recurring entry write

Template posted automatically every night once next_date is reached (or on demand with generate).

Integration tokens need the write ability.

Operation id companies.recurring.store

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • journal_idintegerrequired
  • labelstringrequired
  • referencestring | null
  • third_party_idinteger | null
  • frequencystringrequired
    monthly quarterly yearly
  • next_datestring <date>required
  • end_datestring <date> | null
  • is_activeboolean
  • linesobject[]required
    Properties
    • account_idintegerrequired
      Postable account.
    • debitstring | null
      Decimal.
    • creditstring | null
      Decimal.
    • labelstring | null
    • third_party_idinteger | null
Example
{
    "journal_id": 5,
    "label": "Loyer mensuel",
    "frequency": "monthly",
    "next_date": "2026-04-01",
    "lines": [
        {
            "account_id": 368,
            "debit": "1500.00"
        },
        {
            "account_id": 263,
            "credit": "1500.00",
            "third_party_id": 22
        }
    ]
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema RecurringEntry

Example
{
    "id": 5,
    "company_id": 7,
    "journal_id": 5,
    "label": "Loyer mensuel",
    "reference": "F-2026-0412",
    "third_party_id": 18,
    "frequency": "monthly",
    "next_date": "2026-04-01T00:00:00.000000Z",
    "end_date": "2026-03-15T09:41:00+00:00",
    "lines": [
        {
            "account_id": 368,
            "debit": "1500.00",
            "credit": "0.00",
            "label": "Facture Brasserie Dubuisson",
            "third_party_id": 18
        }
    ],
    "is_active": true,
    "last_generated_on": "2026-03-15",
    "generated_count": 3,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "journal": {
        "id": 42,
        "code": "OD",
        "label": "Opérations diverses"
    },
    "third_party": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "journal_id": 5,
    "label": "Loyer mensuel",
    "frequency": "monthly",
    "next_date": "2026-04-01",
    "lines": [
        {
            "account_id": 368,
            "debit": "1500.00"
        },
        {
            "account_id": 263,
            "credit": "1500.00",
            "third_party_id": 22
        }
    ]
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'journal_id' => 5,
        'label' => 'Loyer mensuel',
        'frequency' => 'monthly',
        'next_date' => '2026-04-01',
        'lines' => [
            [
                'account_id' => 368,
                'debit' => '1500.00',
            ],
            [
                'account_id' => 263,
                'credit' => '1500.00',
                'third_party_id' => 22,
            ],
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "journal_id": 5,
      "label": "Loyer mensuel",
      "frequency": "monthly",
      "next_date": "2026-04-01",
      "lines": [
          {
              "account_id": 368,
              "debit": "1500.00"
          },
          {
              "account_id": 263,
              "credit": "1500.00",
              "third_party_id": 22
          }
      ]
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "journal_id": 5,
        "label": "Loyer mensuel",
        "frequency": "monthly",
        "next_date": "2026-04-01",
        "lines": [
            {
                "account_id": 368,
                "debit": "1500.00"
            },
            {
                "account_id": 263,
                "credit": "1500.00",
                "third_party_id": 22
            }
        ]
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/recurring-entries/generateGenerate every due entry write

Integration tokens need the write ability.

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.recurring.generate-all

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
  • generatedinteger
    e.g. 2
  • entriesobject[]
    Properties
    • idinteger
    • referencestring
      e.g. OD 2026/000031
    • entry_datestring <date>
Example
{
    "generated": 2,
    "entries": [
        {
            "id": 42,
            "reference": "OD 2026/000031",
            "entry_date": "2026-03-15"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/generate" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/generate', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/generate", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/generate",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/recurring-entries/{recurringEntry}Update a recurring entry write

Integration tokens need the write ability.

Operation id companies.recurring.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
recurringEntry requiredintegerId of the recurring entry template.
e.g. 5

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • journal_idinteger
  • labelstring
  • referencestring | null
  • third_party_idinteger | null
  • frequencystring
    monthly quarterly yearly
  • next_datestring <date>
  • end_datestring <date> | null
  • is_activeboolean
  • linesobject[]
    Properties
    • account_idintegerrequired
      Postable account.
    • debitstring | null
      Decimal.
    • creditstring | null
      Decimal.
    • labelstring | null
    • third_party_idinteger | null
Example
{
    "is_active": false
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema RecurringEntry

Example
{
    "id": 5,
    "company_id": 7,
    "journal_id": 5,
    "label": "Loyer mensuel",
    "reference": "F-2026-0412",
    "third_party_id": 18,
    "frequency": "monthly",
    "next_date": "2026-04-01T00:00:00.000000Z",
    "end_date": "2026-03-15T09:41:00+00:00",
    "lines": [
        {
            "account_id": 368,
            "debit": "1500.00",
            "credit": "0.00",
            "label": "Facture Brasserie Dubuisson",
            "third_party_id": 18
        }
    ],
    "is_active": true,
    "last_generated_on": "2026-03-15",
    "generated_count": 3,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "journal": {
        "id": 42,
        "code": "OD",
        "label": "Opérations diverses"
    },
    "third_party": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/5" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "is_active": false
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/5', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'is_active' => false,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/5", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "is_active": false
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/5",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "is_active": False
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/recurring-entries/{recurringEntry}Delete a recurring entry write

Integration tokens need the write ability.

Operation id companies.recurring.destroy

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
recurringEntry requiredintegerId of the recurring entry template.
e.g. 5

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

204Done, no body.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/5" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/5', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/5", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/5",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/recurring-entries/{recurringEntry}/generateGenerate the due entries of one template write

Integration tokens need the write ability.

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.recurring.generate

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
recurringEntry requiredintegerId of the recurring entry template.
e.g. 5

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
  • generatedinteger
    e.g. 1
  • entriesobject[]
    Properties
    • idinteger
    • referencestring
      e.g. OD 2026/000031
    • entry_datestring <date>
Example
{
    "generated": 1,
    "entries": [
        {
            "id": 42,
            "reference": "OD 2026/000031",
            "entry_date": "2026-03-15"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/5/generate" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/5/generate', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/5/generate", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/5/generate",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/qualityQuality checks read

Continuous control of the file: documents and bank transactions pending, unbalanced entries, missing numbers, third parties without VAT number, VAT declarations late…

Integration tokens need the read ability.

Operation id companies.quality

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • checked_atstring <date-time>
  • scoreinteger
    Checks passed.
    e.g. 8
  • totalinteger
    e.g. 10
  • checksobject[]
    Properties
    • codestring
      e.g. bank_pending
    • severitystring
      ok info warning error
    • countinteger
      e.g. 3
    • detailobject | null
Example
{
    "checked_at": "2026-03-15T09:41:00+00:00",
    "score": 8,
    "total": 10,
    "checks": [
        {
            "code": "bank_pending",
            "severity": "ok",
            "count": 3,
            "detail": {}
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/quality" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/quality', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/quality", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/quality",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Documents

Invoices and receipts of the file: allocation, booking.

GET/v1/companies/{company}/documentsList the documents read

Invoices, credit notes and receipts of the file (synchronised from Novadesko or created by the importer).

Integration tokens need the read ability.

Operation id companies.documents.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
typestring
directionstring
sale purchase
statusstring
pending booked ignored
fromstring <date>
tostring <date>
qstringNumber, third party or subject.
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 87,
            "company_id": 7,
            "source": "novadesko",
            "origin": "string",
            "external_id": "string",
            "type": "purchases",
            "direction": "sale",
            "is_credit_note": false,
            "nature": "string",
            "number": "F-2026-0412",
            "payment_provider": "string",
            "number_series": "TK",
            "document_date": "2026-03-15T00:00:00.000000Z",
            "due_date": "2026-03-15T09:41:00+00:00",
            "subject": "Vos documents comptables",
            "communication": "string",
            "currency": "EUR",
            "amount_net": "507.00",
            "amount_vat": "106.47",
            "amount_gross": "613.47",
            "is_paid": true,
            "third_party_id": 18,
            "third_party_name": "Brasserie Dubuisson SA",
            "third_party_vat": "string",
            "pdf_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "xml_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "status": "pending",
            "journal_entry_id": 1284,
            "accountant_locked": true,
            "novadesko_push_status": "string",
            "novadesko_pushed_at": "2026-03-15T09:41:00+00:00",
            "novadesko_push_error": "string",
            "document_import_id": 42,
            "synced_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "deleted_at": "2026-03-15T09:41:00+00:00",
            "deleted_by": 1,
            "third_party": {},
            "lines": [
                {}
            ],
            "journal_entry": null
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/documents/book-allBook every pending document write 5 / 1 min

Books what can be booked; the others stay pending with the reason (a locked period is reported per document in skipped_documents).

Integration tokens need the write ability.

Rate limit: 5 requests per minute (429 beyond, see Retry-After).

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.documents.book-all

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
typestring
directionstring
sale purchase

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • bookedinteger
    e.g. 42
  • skippedinteger
    e.g. 3
  • skipped_documentsobject[]
    Properties
    • idinteger
    • numberstring | null
    • third_partystring | null
    • reasonstring
      e.g. Aucun compte d'imputation sur la ligne 2.
Example
{
    "booked": 42,
    "skipped": 3,
    "skipped_documents": [
        {
            "id": 42,
            "number": "string",
            "third_party": "string",
            "reason": "Aucun compte d'imputation sur la ligne 2."
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/book-all" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/book-all', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/book-all", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/book-all",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/documents/{importedDocument}Document read

With its lines (recorded and actual accounts) and the entry it was booked to.

Integration tokens need the read ability.

Operation id companies.documents.show

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
importedDocument requiredintegerId of the document.
e.g. 87

Common headers: Accept-Language

Responses

200OK

application/json

Schema ImportedDocument

Example
{
    "id": 87,
    "company_id": 7,
    "source": "novadesko",
    "origin": "string",
    "external_id": "string",
    "type": "purchases",
    "direction": "sale",
    "is_credit_note": false,
    "nature": "string",
    "number": "F-2026-0412",
    "payment_provider": "string",
    "number_series": "TK",
    "document_date": "2026-03-15T00:00:00.000000Z",
    "due_date": "2026-03-15T09:41:00+00:00",
    "subject": "Vos documents comptables",
    "communication": "string",
    "currency": "EUR",
    "amount_net": "507.00",
    "amount_vat": "106.47",
    "amount_gross": "613.47",
    "is_paid": true,
    "third_party_id": 18,
    "third_party_name": "Brasserie Dubuisson SA",
    "third_party_vat": "string",
    "pdf_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "xml_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "status": "pending",
    "journal_entry_id": 1284,
    "accountant_locked": true,
    "novadesko_push_status": "string",
    "novadesko_pushed_at": "2026-03-15T09:41:00+00:00",
    "novadesko_push_error": "string",
    "document_import_id": 42,
    "synced_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "third_party": {},
    "lines": [
        {
            "id": 640,
            "imported_document_id": 87,
            "external_id": "string",
            "position": 1,
            "description": "Fûts Bush Caractère 20 L",
            "quantity": "6.000",
            "unit_price": "84.5000",
            "discount_pct": "1210.00",
            "tax_rate": "21.00",
            "amount_net": "507.00",
            "amount_vat": "106.47",
            "recorded_account_number": "604000",
            "recorded_account_id": 42,
            "actual_account_id": 42,
            "vat_code_id": 4,
            "purchase_category": "string",
            "corrected_at": "2026-03-15T09:41:00+00:00",
            "corrected_by": 1,
            "correction_pushed": true,
            "recorded_account": {},
            "actual_account": {},
            "vat_code": {}
        }
    ],
    "journal_entry": {
        "id": 1284,
        "company_id": 7,
        "fiscal_year_id": 2,
        "period_id": 16,
        "journal_id": 3,
        "number": 412,
        "entry_date": "2026-03-15T00:00:00.000000Z",
        "due_date": "2026-03-15T09:41:00+00:00",
        "label": "Facture Brasserie Dubuisson SA",
        "reference": "F-2026-0412",
        "structured_communication": "000000000101",
        "third_party_id": 18,
        "status": "posted",
        "origin": "manual",
        "created_by": 1,
        "posted_at": "2026-03-15T09:41:00+00:00",
        "reversed_entry_id": 42,
        "reversed_by_entry_id": 42,
        "recurring_entry_id": 42,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal": {
            "id": 3,
            "code": "VEN",
            "type": "sale"
        },
        "third_party": {
            "id": 18,
            "name": "Brasserie Dubuisson SA"
        },
        "lines": [
            {}
        ]
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/documents/{importedDocument}/lines/{line}Correct the allocation of a line write

Sets the account chosen by the accountant (« actual » layer); account_id: null goes back to the recorded account.

Integration tokens need the write ability.

Operation id companies.documents.lines.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
importedDocument requiredintegerId of the document.
e.g. 87
line requiredintegerId of the line.
e.g. 3391

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • account_idinteger | null
    Postable account.
  • vat_code_idinteger | null
Example
{
    "account_id": 361
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema ImportedDocumentLine

Example
{
    "id": 640,
    "imported_document_id": 87,
    "external_id": "string",
    "position": 1,
    "description": "Fûts Bush Caractère 20 L",
    "quantity": "6.000",
    "unit_price": "84.5000",
    "discount_pct": "1210.00",
    "tax_rate": "21.00",
    "amount_net": "507.00",
    "amount_vat": "106.47",
    "recorded_account_number": "604000",
    "recorded_account_id": 42,
    "actual_account_id": 42,
    "vat_code_id": 4,
    "purchase_category": "string",
    "corrected_at": "2026-03-15T09:41:00+00:00",
    "corrected_by": 1,
    "correction_pushed": true,
    "recorded_account": {},
    "actual_account": {},
    "vat_code": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87/lines/3391" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "account_id": 361
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87/lines/3391', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'account_id' => 361,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87/lines/3391", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "account_id": 361
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87/lines/3391",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "account_id": 361
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/documents/{importedDocument}/bookBook a document write

Posts the entry of the document in the journal resolved by the journal rules.

Integration tokens need the write ability.

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.documents.book

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
importedDocument requiredintegerId of the document.
e.g. 87

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

201Booked, with journal_entry

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema ImportedDocument

Example
{
    "id": 87,
    "company_id": 7,
    "source": "novadesko",
    "origin": "string",
    "external_id": "string",
    "type": "purchases",
    "direction": "sale",
    "is_credit_note": false,
    "nature": "string",
    "number": "F-2026-0412",
    "payment_provider": "string",
    "number_series": "TK",
    "document_date": "2026-03-15T00:00:00.000000Z",
    "due_date": "2026-03-15T09:41:00+00:00",
    "subject": "Vos documents comptables",
    "communication": "string",
    "currency": "EUR",
    "amount_net": "507.00",
    "amount_vat": "106.47",
    "amount_gross": "613.47",
    "is_paid": true,
    "third_party_id": 18,
    "third_party_name": "Brasserie Dubuisson SA",
    "third_party_vat": "string",
    "pdf_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "xml_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "status": "pending",
    "journal_entry_id": 1284,
    "accountant_locked": true,
    "novadesko_push_status": "string",
    "novadesko_pushed_at": "2026-03-15T09:41:00+00:00",
    "novadesko_push_error": "string",
    "document_import_id": 42,
    "synced_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "third_party": {},
    "lines": [
        {
            "id": 640,
            "imported_document_id": 87,
            "external_id": "string",
            "position": 1,
            "description": "Fûts Bush Caractère 20 L",
            "quantity": "6.000",
            "unit_price": "84.5000",
            "discount_pct": "1210.00",
            "tax_rate": "21.00",
            "amount_net": "507.00",
            "amount_vat": "106.47",
            "recorded_account_number": "604000",
            "recorded_account_id": 42,
            "actual_account_id": 42,
            "vat_code_id": 4,
            "purchase_category": "string",
            "corrected_at": "2026-03-15T09:41:00+00:00",
            "corrected_by": 1,
            "correction_pushed": true,
            "recorded_account": {},
            "actual_account": {},
            "vat_code": {}
        }
    ],
    "journal_entry": {
        "id": 1284,
        "company_id": 7,
        "fiscal_year_id": 2,
        "period_id": 16,
        "journal_id": 3,
        "number": 412,
        "entry_date": "2026-03-15T00:00:00.000000Z",
        "due_date": "2026-03-15T09:41:00+00:00",
        "label": "Facture Brasserie Dubuisson SA",
        "reference": "F-2026-0412",
        "structured_communication": "000000000101",
        "third_party_id": 18,
        "status": "posted",
        "origin": "manual",
        "created_by": 1,
        "posted_at": "2026-03-15T09:41:00+00:00",
        "reversed_entry_id": 42,
        "reversed_by_entry_id": 42,
        "recurring_entry_id": 42,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal": {
            "id": 3,
            "code": "VEN",
            "type": "sale"
        },
        "third_party": {
            "id": 18,
            "name": "Brasserie Dubuisson SA"
        },
        "lines": [
            {}
        ]
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87/book" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87/book', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87/book", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87/book",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/documents/{importedDocument}/ignoreIgnore or restore a document write

An ignored document is left out of the booking; restore: true puts it back to pending. Refused for a booked document.

Integration tokens need the write ability.

Operation id companies.documents.ignore

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
importedDocument requiredintegerId of the document.
e.g. 87

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • restoreboolean
Example
{
    "restore": false
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema ImportedDocument

Example
{
    "id": 87,
    "company_id": 7,
    "source": "novadesko",
    "origin": "string",
    "external_id": "string",
    "type": "purchases",
    "direction": "sale",
    "is_credit_note": false,
    "nature": "string",
    "number": "F-2026-0412",
    "payment_provider": "string",
    "number_series": "TK",
    "document_date": "2026-03-15T00:00:00.000000Z",
    "due_date": "2026-03-15T09:41:00+00:00",
    "subject": "Vos documents comptables",
    "communication": "string",
    "currency": "EUR",
    "amount_net": "507.00",
    "amount_vat": "106.47",
    "amount_gross": "613.47",
    "is_paid": true,
    "third_party_id": 18,
    "third_party_name": "Brasserie Dubuisson SA",
    "third_party_vat": "string",
    "pdf_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "xml_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "status": "pending",
    "journal_entry_id": 1284,
    "accountant_locked": true,
    "novadesko_push_status": "string",
    "novadesko_pushed_at": "2026-03-15T09:41:00+00:00",
    "novadesko_push_error": "string",
    "document_import_id": 42,
    "synced_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "third_party": {},
    "lines": [
        {
            "id": 640,
            "imported_document_id": 87,
            "external_id": "string",
            "position": 1,
            "description": "Fûts Bush Caractère 20 L",
            "quantity": "6.000",
            "unit_price": "84.5000",
            "discount_pct": "1210.00",
            "tax_rate": "21.00",
            "amount_net": "507.00",
            "amount_vat": "106.47",
            "recorded_account_number": "604000",
            "recorded_account_id": 42,
            "actual_account_id": 42,
            "vat_code_id": 4,
            "purchase_category": "string",
            "corrected_at": "2026-03-15T09:41:00+00:00",
            "corrected_by": 1,
            "correction_pushed": true,
            "recorded_account": {},
            "actual_account": {},
            "vat_code": {}
        }
    ],
    "journal_entry": {
        "id": 1284,
        "company_id": 7,
        "fiscal_year_id": 2,
        "period_id": 16,
        "journal_id": 3,
        "number": 412,
        "entry_date": "2026-03-15T00:00:00.000000Z",
        "due_date": "2026-03-15T09:41:00+00:00",
        "label": "Facture Brasserie Dubuisson SA",
        "reference": "F-2026-0412",
        "structured_communication": "000000000101",
        "third_party_id": 18,
        "status": "posted",
        "origin": "manual",
        "created_by": 1,
        "posted_at": "2026-03-15T09:41:00+00:00",
        "reversed_entry_id": 42,
        "reversed_by_entry_id": 42,
        "recurring_entry_id": 42,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal": {
            "id": 3,
            "code": "VEN",
            "type": "sale"
        },
        "third_party": {
            "id": 18,
            "name": "Brasserie Dubuisson SA"
        },
        "lines": [
            {}
        ]
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87/ignore" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "restore": false
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87/ignore', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'restore' => false,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87/ignore", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "restore": false
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/87/ignore",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "restore": False
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Document importer

Upload of PDF, images, UBL / CII XML and ZIP files, analysis, validation.

GET/v1/companies/{company}/document-importsList the imports read

Polling list of the uploaded files, without raw_text.

Integration tokens need the read ability.

Operation id companies.document-imports.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
batch_idstring <uuid>
statusstringComma-separated statuses.
e.g. ready,needs_review
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 311,
            "company_id": 7,
            "uploaded_by": 1,
            "batch_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "parent_import_id": 42,
            "original_name": "facture-dubuisson-0412.pdf",
            "mime": "application/pdf",
            "size": 184320,
            "file_hash": "string",
            "kind": "pdf",
            "status": "queued",
            "progress": 100,
            "step": "upload",
            "engine": "api",
            "extracted": null,
            "raw_text": "string",
            "warnings": [
                "string"
            ],
            "error": "string",
            "suggested_third_party_id": 42,
            "suggested_direction": "string",
            "duplicate_of_import_id": 42,
            "duplicate_of_document_id": 42,
            "imported_document_id": 42,
            "novadesko_document_id": "string",
            "novadesko_locked_at": "2026-03-15T09:41:00+00:00",
            "started_at": "2026-03-15T09:41:00+00:00",
            "finished_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "deleted_at": "2026-03-15T09:41:00+00:00",
            "deleted_by": 1,
            "suggested_third_party": {}
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/document-importsUpload files write Not in demo 30 / 1 min

Multipart upload of 1 to 20 files, 25 MB each: PDF, images (JPEG, PNG, HEIC, WebP), UBL / CII XML, or a ZIP of those (50 files max, expanded into child imports). Files are stored and queued; call process for a synchronous analysis or let the scheduler analyse them within a minute.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 30 requests per minute (429 beyond, see Retry-After).

Operation id companies.document-imports.store

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

multipart/form-data

Schema object
  • files[]string <binary>[]required
  • batch_idstring <uuid>
    Reuse a batch to add files to it.

Responses

201Files stored

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
Example
{
    "batch_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "imports": [
        {
            "id": 311,
            "company_id": 7,
            "uploaded_by": 1,
            "batch_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "parent_import_id": 42,
            "original_name": "facture-dubuisson-0412.pdf",
            "mime": "application/pdf",
            "size": 184320,
            "file_hash": "string",
            "kind": "pdf",
            "status": "queued",
            "progress": 100,
            "step": "upload",
            "engine": "api",
            "extracted": null,
            "raw_text": "string",
            "warnings": [
                "string"
            ],
            "error": "string",
            "suggested_third_party_id": 42,
            "suggested_direction": "string",
            "duplicate_of_import_id": 42,
            "duplicate_of_document_id": 42,
            "imported_document_id": 42,
            "novadesko_document_id": "string",
            "novadesko_locked_at": "2026-03-15T09:41:00+00:00",
            "started_at": "2026-03-15T09:41:00+00:00",
            "finished_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "deleted_at": "2026-03-15T09:41:00+00:00",
            "deleted_by": 1,
            "suggested_third_party": {}
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -F "files[]=@facture-0412.pdf" \
  -F "files[]=@facture-0413.pdf"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'multipart' => [
        ['name' => 'files[]', 'contents' => fopen('facture-0412.pdf', 'r'), 'filename' => 'facture-0412.pdf'],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const form = new FormData();
form.append("files[]", fileInput.files[0]);

const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: form,
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    files=[("files[]", open("facture-0412.pdf", "rb"))],
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/document-imports/enginesAnalysis engines read

Engines able to read a document and whether each is configured.

Integration tokens need the read ability.

Operation id companies.document-imports.engines

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • enginesobject[]
    Properties
    • idstring
      e.g. api
    • configuredboolean
Example
{
    "engines": [
        {
            "id": "api",
            "configured": true
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/engines" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/engines', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/engines", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/engines",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/document-imports/{documentImport}Import read

With the extracted data and the text layer.

Integration tokens need the read ability.

Operation id companies.document-imports.show

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
documentImport requiredintegerId of the import (uploaded file).
e.g. 311

Common headers: Accept-Language

Responses

200OK

application/json

Schema DocumentImport

Example
{
    "id": 311,
    "company_id": 7,
    "uploaded_by": 1,
    "batch_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "parent_import_id": 42,
    "original_name": "facture-dubuisson-0412.pdf",
    "mime": "application/pdf",
    "size": 184320,
    "file_hash": "string",
    "kind": "pdf",
    "status": "queued",
    "progress": 100,
    "step": "upload",
    "engine": "api",
    "extracted": {
        "direction": "purchase",
        "is_credit_note": false,
        "number": "F-2026-0412",
        "document_date": "2026-03-15",
        "due_date": "2026-03-15",
        "currency": "EUR",
        "supplier": {
            "name": "Brasserie Dubuisson SA",
            "vat_number": "BE0402531376",
            "enterprise_number": "0477472701",
            "address": "Grand-Place 14",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE",
            "iban": "BE68539007547034",
            "email": "claire.dumont@fiduciaire-dumont.be"
        },
        "customer": {},
        "amount_net": "507.00",
        "amount_vat": "106.47",
        "amount_gross": "613.47",
        "structured_communication": "000000000101",
        "confidence": 0.93,
        "lines": [
            {
                "description": "Fûts Bush Caractère 20 L",
                "quantity": 6,
                "unit_price": 84.5,
                "tax_rate": 21,
                "amount_net": "507.00",
                "amount_vat": "106.47",
                "account_id": 580,
                "account_number": "604000",
                "vat_code_id": 4,
                "vat_code": "A21"
            }
        ]
    },
    "raw_text": "string",
    "warnings": [
        "string"
    ],
    "error": "string",
    "suggested_third_party_id": 42,
    "suggested_direction": "string",
    "duplicate_of_import_id": 42,
    "duplicate_of_document_id": 42,
    "imported_document_id": 42,
    "novadesko_document_id": "string",
    "novadesko_locked_at": "2026-03-15T09:41:00+00:00",
    "started_at": "2026-03-15T09:41:00+00:00",
    "finished_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "suggested_third_party": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/document-imports/{documentImport}Correct the extracted data write

Saves corrections without validating. Only for the statuses ready, needs_review and duplicate.

Integration tokens need the write ability.

Operation id companies.document-imports.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
documentImport requiredintegerId of the import (uploaded file).
e.g. 311

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
Example
{
    "extracted": {
        "direction": "purchase",
        "is_credit_note": false,
        "number": "F-2026-0412",
        "document_date": "2026-03-15",
        "due_date": "2026-03-15",
        "currency": "EUR",
        "supplier": {
            "name": "Brasserie Dubuisson SA",
            "vat_number": "BE0402531376",
            "enterprise_number": "0477472701",
            "address": "Grand-Place 14",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE",
            "iban": "BE68539007547034",
            "email": "claire.dumont@fiduciaire-dumont.be"
        },
        "customer": {},
        "amount_net": "507.00",
        "amount_vat": "106.47",
        "amount_gross": "613.47",
        "structured_communication": "000000000101",
        "confidence": 0.93,
        "lines": [
            {
                "description": "Fûts Bush Caractère 20 L",
                "quantity": 6,
                "unit_price": 84.5,
                "tax_rate": 21,
                "amount_net": "507.00",
                "amount_vat": "106.47",
                "account_id": 580,
                "account_number": "604000",
                "vat_code_id": 4,
                "vat_code": "A21"
            }
        ]
    }
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema DocumentImport

Example
{
    "id": 311,
    "company_id": 7,
    "uploaded_by": 1,
    "batch_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "parent_import_id": 42,
    "original_name": "facture-dubuisson-0412.pdf",
    "mime": "application/pdf",
    "size": 184320,
    "file_hash": "string",
    "kind": "pdf",
    "status": "queued",
    "progress": 100,
    "step": "upload",
    "engine": "api",
    "extracted": {
        "direction": "purchase",
        "is_credit_note": false,
        "number": "F-2026-0412",
        "document_date": "2026-03-15",
        "due_date": "2026-03-15",
        "currency": "EUR",
        "supplier": {
            "name": "Brasserie Dubuisson SA",
            "vat_number": "BE0402531376",
            "enterprise_number": "0477472701",
            "address": "Grand-Place 14",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE",
            "iban": "BE68539007547034",
            "email": "claire.dumont@fiduciaire-dumont.be"
        },
        "customer": {},
        "amount_net": "507.00",
        "amount_vat": "106.47",
        "amount_gross": "613.47",
        "structured_communication": "000000000101",
        "confidence": 0.93,
        "lines": [
            {
                "description": "Fûts Bush Caractère 20 L",
                "quantity": 6,
                "unit_price": 84.5,
                "tax_rate": 21,
                "amount_net": "507.00",
                "amount_vat": "106.47",
                "account_id": 580,
                "account_number": "604000",
                "vat_code_id": 4,
                "vat_code": "A21"
            }
        ]
    },
    "raw_text": "string",
    "warnings": [
        "string"
    ],
    "error": "string",
    "suggested_third_party_id": 42,
    "suggested_direction": "string",
    "duplicate_of_import_id": 42,
    "duplicate_of_document_id": 42,
    "imported_document_id": 42,
    "novadesko_document_id": "string",
    "novadesko_locked_at": "2026-03-15T09:41:00+00:00",
    "started_at": "2026-03-15T09:41:00+00:00",
    "finished_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "suggested_third_party": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "extracted": {
        "direction": "purchase",
        "is_credit_note": false,
        "number": "F-2026-0412",
        "document_date": "2026-03-15",
        "due_date": "2026-03-15",
        "currency": "EUR",
        "supplier": {
            "name": "Brasserie Dubuisson SA",
            "vat_number": "BE0402531376",
            "enterprise_number": "0477472701",
            "address": "Grand-Place 14",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE",
            "iban": "BE68539007547034",
            "email": "claire.dumont@fiduciaire-dumont.be"
        },
        "customer": {},
        "amount_net": "507.00",
        "amount_vat": "106.47",
        "amount_gross": "613.47",
        "structured_communication": "000000000101",
        "confidence": 0.93,
        "lines": [
            {
                "description": "Fûts Bush Caractère 20 L",
                "quantity": 6,
                "unit_price": 84.5,
                "tax_rate": 21,
                "amount_net": "507.00",
                "amount_vat": "106.47",
                "account_id": 580,
                "account_number": "604000",
                "vat_code_id": 4,
                "vat_code": "A21"
            }
        ]
    }
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'extracted' => [
            'direction' => 'purchase',
            'is_credit_note' => false,
            'number' => 'F-2026-0412',
            'document_date' => '2026-03-15',
            'due_date' => '2026-03-15',
            'currency' => 'EUR',
            'supplier' => [
                'name' => 'Brasserie Dubuisson SA',
                'vat_number' => 'BE0402531376',
                'enterprise_number' => '0477472701',
                'address' => 'Grand-Place 14',
                'postal_code' => '7000',
                'city' => 'Mons',
                'country' => 'BE',
                'iban' => 'BE68539007547034',
                'email' => 'claire.dumont@fiduciaire-dumont.be',
            ],
            'customer' => [],
            'amount_net' => '507.00',
            'amount_vat' => '106.47',
            'amount_gross' => '613.47',
            'structured_communication' => '000000000101',
            'confidence' => 0.93,
            'lines' => [
                [
                    'description' => 'Fûts Bush Caractère 20 L',
                    'quantity' => 6,
                    'unit_price' => 84.5,
                    'tax_rate' => 21,
                    'amount_net' => '507.00',
                    'amount_vat' => '106.47',
                    'account_id' => 580,
                    'account_number' => '604000',
                    'vat_code_id' => 4,
                    'vat_code' => 'A21',
                ],
            ],
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "extracted": {
          "direction": "purchase",
          "is_credit_note": false,
          "number": "F-2026-0412",
          "document_date": "2026-03-15",
          "due_date": "2026-03-15",
          "currency": "EUR",
          "supplier": {
              "name": "Brasserie Dubuisson SA",
              "vat_number": "BE0402531376",
              "enterprise_number": "0477472701",
              "address": "Grand-Place 14",
              "postal_code": "7000",
              "city": "Mons",
              "country": "BE",
              "iban": "BE68539007547034",
              "email": "claire.dumont@fiduciaire-dumont.be"
          },
          "customer": {},
          "amount_net": "507.00",
          "amount_vat": "106.47",
          "amount_gross": "613.47",
          "structured_communication": "000000000101",
          "confidence": 0.93,
          "lines": [
              {
                  "description": "Fûts Bush Caractère 20 L",
                  "quantity": 6,
                  "unit_price": 84.5,
                  "tax_rate": 21,
                  "amount_net": "507.00",
                  "amount_vat": "106.47",
                  "account_id": 580,
                  "account_number": "604000",
                  "vat_code_id": 4,
                  "vat_code": "A21"
              }
          ]
      }
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "extracted": {
            "direction": "purchase",
            "is_credit_note": False,
            "number": "F-2026-0412",
            "document_date": "2026-03-15",
            "due_date": "2026-03-15",
            "currency": "EUR",
            "supplier": {
                "name": "Brasserie Dubuisson SA",
                "vat_number": "BE0402531376",
                "enterprise_number": "0477472701",
                "address": "Grand-Place 14",
                "postal_code": "7000",
                "city": "Mons",
                "country": "BE",
                "iban": "BE68539007547034",
                "email": "claire.dumont@fiduciaire-dumont.be"
            },
            "customer": {},
            "amount_net": "507.00",
            "amount_vat": "106.47",
            "amount_gross": "613.47",
            "structured_communication": "000000000101",
            "confidence": 0.93,
            "lines": [
                {
                    "description": "Fûts Bush Caractère 20 L",
                    "quantity": 6,
                    "unit_price": 84.5,
                    "tax_rate": 21,
                    "amount_net": "507.00",
                    "amount_vat": "106.47",
                    "account_id": 580,
                    "account_number": "604000",
                    "vat_code_id": 4,
                    "vat_code": "A21"
                }
            ]
        }
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/document-imports/{documentImport}Delete an import write

Goes to the recycle bin. A validated import keeps its document.

Integration tokens need the write ability.

Operation id companies.document-imports.destroy

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
documentImport requiredintegerId of the import (uploaded file).
e.g. 311

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-Trashed

application/json

Schema object
  • deletedboolean
Example
{
    "deleted": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/document-imports/{documentImport}/processAnalyse an import now write Not in demo 120 / 1 min

Synchronous analysis (up to two minutes): text layer, extraction, account suggestions, third party matching, duplicate detection. Already analysed: returns the result.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 120 requests per minute (429 beyond, see Retry-After).

Operation id companies.document-imports.process

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
documentImport requiredintegerId of the import (uploaded file).
e.g. 311

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema DocumentImport

Example
{
    "id": 311,
    "company_id": 7,
    "uploaded_by": 1,
    "batch_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "parent_import_id": 42,
    "original_name": "facture-dubuisson-0412.pdf",
    "mime": "application/pdf",
    "size": 184320,
    "file_hash": "string",
    "kind": "pdf",
    "status": "queued",
    "progress": 100,
    "step": "upload",
    "engine": "api",
    "extracted": {
        "direction": "purchase",
        "is_credit_note": false,
        "number": "F-2026-0412",
        "document_date": "2026-03-15",
        "due_date": "2026-03-15",
        "currency": "EUR",
        "supplier": {
            "name": "Brasserie Dubuisson SA",
            "vat_number": "BE0402531376",
            "enterprise_number": "0477472701",
            "address": "Grand-Place 14",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE",
            "iban": "BE68539007547034",
            "email": "claire.dumont@fiduciaire-dumont.be"
        },
        "customer": {},
        "amount_net": "507.00",
        "amount_vat": "106.47",
        "amount_gross": "613.47",
        "structured_communication": "000000000101",
        "confidence": 0.93,
        "lines": [
            {
                "description": "Fûts Bush Caractère 20 L",
                "quantity": 6,
                "unit_price": 84.5,
                "tax_rate": 21,
                "amount_net": "507.00",
                "amount_vat": "106.47",
                "account_id": 580,
                "account_number": "604000",
                "vat_code_id": 4,
                "vat_code": "A21"
            }
        ]
    },
    "raw_text": "string",
    "warnings": [
        "string"
    ],
    "error": "string",
    "suggested_third_party_id": 42,
    "suggested_direction": "string",
    "duplicate_of_import_id": 42,
    "duplicate_of_document_id": 42,
    "imported_document_id": 42,
    "novadesko_document_id": "string",
    "novadesko_locked_at": "2026-03-15T09:41:00+00:00",
    "started_at": "2026-03-15T09:41:00+00:00",
    "finished_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "suggested_third_party": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/process" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/process', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/process", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/process",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/document-imports/{documentImport}/retryAnalyse again write Not in demo 60 / 1 min

force re-analyses a file flagged as the duplicate of another import.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 60 requests per minute (429 beyond, see Retry-After).

Operation id companies.document-imports.retry

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
documentImport requiredintegerId of the import (uploaded file).
e.g. 311

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • forceboolean
Example
{
    "force": true
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema DocumentImport

Example
{
    "id": 311,
    "company_id": 7,
    "uploaded_by": 1,
    "batch_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "parent_import_id": 42,
    "original_name": "facture-dubuisson-0412.pdf",
    "mime": "application/pdf",
    "size": 184320,
    "file_hash": "string",
    "kind": "pdf",
    "status": "queued",
    "progress": 100,
    "step": "upload",
    "engine": "api",
    "extracted": {
        "direction": "purchase",
        "is_credit_note": false,
        "number": "F-2026-0412",
        "document_date": "2026-03-15",
        "due_date": "2026-03-15",
        "currency": "EUR",
        "supplier": {
            "name": "Brasserie Dubuisson SA",
            "vat_number": "BE0402531376",
            "enterprise_number": "0477472701",
            "address": "Grand-Place 14",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE",
            "iban": "BE68539007547034",
            "email": "claire.dumont@fiduciaire-dumont.be"
        },
        "customer": {},
        "amount_net": "507.00",
        "amount_vat": "106.47",
        "amount_gross": "613.47",
        "structured_communication": "000000000101",
        "confidence": 0.93,
        "lines": [
            {
                "description": "Fûts Bush Caractère 20 L",
                "quantity": 6,
                "unit_price": 84.5,
                "tax_rate": 21,
                "amount_net": "507.00",
                "amount_vat": "106.47",
                "account_id": 580,
                "account_number": "604000",
                "vat_code_id": 4,
                "vat_code": "A21"
            }
        ]
    },
    "raw_text": "string",
    "warnings": [
        "string"
    ],
    "error": "string",
    "suggested_third_party_id": 42,
    "suggested_direction": "string",
    "duplicate_of_import_id": 42,
    "duplicate_of_document_id": 42,
    "imported_document_id": 42,
    "novadesko_document_id": "string",
    "novadesko_locked_at": "2026-03-15T09:41:00+00:00",
    "started_at": "2026-03-15T09:41:00+00:00",
    "finished_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "suggested_third_party": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/retry" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "force": true
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/retry', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'force' => true,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/retry", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "force": true
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/retry",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "force": True
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/document-imports/{documentImport}/validateValidate an import write 120 / 1 min

Creates the document (locked for the shop), books it unless book: false, and pushes it to Novadesko when the file is linked (never from the demo). The third party is third_party_id, or created from new_third_party.

Integration tokens need the write ability.

Rate limit: 120 requests per minute (429 beyond, see Retry-After).

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.document-imports.validate

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
documentImport requiredintegerId of the import (uploaded file).
e.g. 311

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • third_party_idinteger | null
  • new_third_partyobject
    Properties
    • typestring
      supplier customer
    • namestringrequired
    • vat_numberstring | null
    • enterprise_numberstring | null
    • addressstring | null
    • postal_codestring | null
    • citystring | null
    • countrystring | null
    • ibanstring | null
    • bicstring | null
    • emailstring <email> | null
    • phonestring | null
  • directionstring
    purchase sale
  • linesobject[]
    Properties
    • account_idinteger | null
    • vat_code_idinteger | null
  • bookboolean
    True by default.
  • push_to_novadeskoboolean | null
  • forceboolean
    Validate despite a duplicate warning.
Example
{
    "third_party_id": 18,
    "direction": "purchase",
    "lines": [
        {
            "account_id": 361,
            "vat_code_id": 25
        }
    ],
    "book": true
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
Example
{
    "import": {
        "id": 311,
        "company_id": 7,
        "uploaded_by": 1,
        "batch_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
        "parent_import_id": 42,
        "original_name": "facture-dubuisson-0412.pdf",
        "mime": "application/pdf",
        "size": 184320,
        "file_hash": "string",
        "kind": "pdf",
        "status": "queued",
        "progress": 100,
        "step": "upload",
        "engine": "api",
        "extracted": {
            "direction": "purchase",
            "is_credit_note": false,
            "number": "F-2026-0412",
            "document_date": "2026-03-15",
            "due_date": "2026-03-15",
            "currency": "EUR",
            "supplier": {
                "name": "Brasserie Dubuisson SA",
                "vat_number": "BE0402531376",
                "enterprise_number": "0477472701",
                "address": "Grand-Place 14",
                "postal_code": "7000",
                "city": "Mons",
                "country": "BE",
                "iban": "BE68539007547034",
                "email": "claire.dumont@fiduciaire-dumont.be"
            },
            "customer": {},
            "amount_net": "507.00",
            "amount_vat": "106.47",
            "amount_gross": "613.47",
            "structured_communication": "000000000101",
            "confidence": 0.93,
            "lines": [
                {
                    "description": "Fûts Bush Caractère 20 L",
                    "quantity": 6,
                    "unit_price": 84.5,
                    "tax_rate": 21,
                    "amount_net": "507.00",
                    "amount_vat": "106.47",
                    "account_id": 580,
                    "account_number": "604000",
                    "vat_code_id": 4,
                    "vat_code": "A21"
                }
            ]
        },
        "raw_text": "string",
        "warnings": [
            "string"
        ],
        "error": "string",
        "suggested_third_party_id": 42,
        "suggested_direction": "string",
        "duplicate_of_import_id": 42,
        "duplicate_of_document_id": 42,
        "imported_document_id": 42,
        "novadesko_document_id": "string",
        "novadesko_locked_at": "2026-03-15T09:41:00+00:00",
        "started_at": "2026-03-15T09:41:00+00:00",
        "finished_at": "2026-03-15T09:41:00+00:00",
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1,
        "suggested_third_party": {}
    },
    "document": {
        "id": 87,
        "company_id": 7,
        "source": "novadesko",
        "origin": "string",
        "external_id": "string",
        "type": "purchases",
        "direction": "sale",
        "is_credit_note": false,
        "nature": "string",
        "number": "F-2026-0412",
        "payment_provider": "string",
        "number_series": "TK",
        "document_date": "2026-03-15T00:00:00.000000Z",
        "due_date": "2026-03-15T09:41:00+00:00",
        "subject": "Vos documents comptables",
        "communication": "string",
        "currency": "EUR",
        "amount_net": "507.00",
        "amount_vat": "106.47",
        "amount_gross": "613.47",
        "is_paid": true,
        "third_party_id": 18,
        "third_party_name": "Brasserie Dubuisson SA",
        "third_party_vat": "string",
        "pdf_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "xml_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "status": "pending",
        "journal_entry_id": 1284,
        "accountant_locked": true,
        "novadesko_push_status": "string",
        "novadesko_pushed_at": "2026-03-15T09:41:00+00:00",
        "novadesko_push_error": "string",
        "document_import_id": 42,
        "synced_at": "2026-03-15T09:41:00+00:00",
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1,
        "third_party": {},
        "lines": [
            {
                "id": 640,
                "imported_document_id": 87,
                "external_id": "string",
                "position": 1,
                "description": "Fûts Bush Caractère 20 L",
                "quantity": "6.000",
                "unit_price": "84.5000",
                "discount_pct": "1210.00",
                "tax_rate": "21.00",
                "amount_net": "507.00",
                "amount_vat": "106.47",
                "recorded_account_number": "604000",
                "recorded_account_id": 42,
                "actual_account_id": 42,
                "vat_code_id": 4,
                "purchase_category": "string",
                "corrected_at": "2026-03-15T09:41:00+00:00",
                "corrected_by": 1,
                "correction_pushed": true,
                "recorded_account": {},
                "actual_account": {},
                "vat_code": {}
            }
        ],
        "journal_entry": {
            "id": 1284,
            "company_id": 7,
            "fiscal_year_id": 2,
            "period_id": 16,
            "journal_id": 3,
            "number": 412,
            "entry_date": "2026-03-15T00:00:00.000000Z",
            "due_date": "2026-03-15T09:41:00+00:00",
            "label": "Facture Brasserie Dubuisson SA",
            "reference": "F-2026-0412",
            "structured_communication": "000000000101",
            "third_party_id": 18,
            "status": "posted",
            "origin": "manual",
            "created_by": 1,
            "posted_at": "2026-03-15T09:41:00+00:00",
            "reversed_entry_id": 42,
            "reversed_by_entry_id": 42,
            "recurring_entry_id": 42,
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "journal": {
                "id": 3,
                "code": "VEN",
                "type": "sale"
            },
            "third_party": {
                "id": 18,
                "name": "Brasserie Dubuisson SA"
            },
            "lines": [
                {}
            ]
        }
    },
    "entry": {
        "id": 1284,
        "company_id": 7,
        "fiscal_year_id": 2,
        "period_id": 16,
        "journal_id": 3,
        "number": 412,
        "entry_date": "2026-03-15T00:00:00.000000Z",
        "due_date": "2026-03-15T09:41:00+00:00",
        "label": "Facture Brasserie Dubuisson SA",
        "reference": "F-2026-0412",
        "structured_communication": "000000000101",
        "third_party_id": 18,
        "status": "posted",
        "origin": "manual",
        "created_by": 1,
        "posted_at": "2026-03-15T09:41:00+00:00",
        "reversed_entry_id": 42,
        "reversed_by_entry_id": 42,
        "recurring_entry_id": 42,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal": {
            "id": 3,
            "code": "VEN",
            "type": "sale"
        },
        "third_party": {
            "id": 18,
            "name": "Brasserie Dubuisson SA"
        },
        "lines": [
            {
                "id": 3391,
                "journal_entry_id": 1284,
                "position": 1,
                "account_id": 580,
                "third_party_id": 18,
                "label": "Brasserie Dubuisson SA",
                "debit": "0.00",
                "credit": "1000.00",
                "vat_code_id": 4,
                "vat_base": "1000.00",
                "reconciliation_code": "AB",
                "cost_center_id": 42,
                "project_id": 42,
                "reminder_level": 0,
                "reminder_sent_at": "2026-03-15T09:41:00+00:00",
                "account": {
                    "id": 580,
                    "number": "702000",
                    "label": "Prestations de services"
                },
                "vat_code": {}
            }
        ]
    },
    "novadesko": {
        "status": "skipped",
        "message": "OK"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/validate" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "third_party_id": 18,
    "direction": "purchase",
    "lines": [
        {
            "account_id": 361,
            "vat_code_id": 25
        }
    ],
    "book": true
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/validate', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'third_party_id' => 18,
        'direction' => 'purchase',
        'lines' => [
            [
                'account_id' => 361,
                'vat_code_id' => 25,
            ],
        ],
        'book' => true,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/validate", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "third_party_id": 18,
      "direction": "purchase",
      "lines": [
          {
              "account_id": 361,
              "vat_code_id": 25
          }
      ],
      "book": true
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/validate",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "third_party_id": 18,
        "direction": "purchase",
        "lines": [
            {
                "account_id": 361,
                "vat_code_id": 25
            }
        ],
        "book": True
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/document-imports/{documentImport}/fileSigned preview of an uploaded file Signed URL 240 / 1 min

Serves the file inline (or its preview: PDF embedded in a UBL, JPEG converted from HEIC).

Authorised by the signature of the URL (query parameters signature and expires), not by a bearer token. The URL is issued by another endpoint and expires.

Rate limit: 240 requests per minute (429 beyond, see Retry-After).

Operation id document-imports.file

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
documentImport requiredintegerId of the import (uploaded file).
e.g. 311

Query parameters

NameTypeDescription
previewstring0 serves the original file.
0 1

Common headers: signature expires

Responses

200The file, inline.

Response headers Content-Disposition X-RateLimit-Limit X-RateLimit-Remaining

application/pdf

image/jpeg

image/png

application/xml

403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/file" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/file', [
    'headers' => [
        'Accept' => 'application/json',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/file", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/document-imports/311/file",
    headers={
        "Accept": "application/json",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Bank

Bank transactions (CODA), matching, rules, treasury, SEPA payment files.

GET/v1/companies/{company}/bank-transactionsList the bank transactions read

Transactions of the CODA statements with the proposed match.

Integration tokens need the read ability.

Operation id companies.bank-transactions.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
unmatchedbooleanPending and without proposal.
journal_idinteger
statusstring
pending booked ignored
fromstring <date>Value date.
tostring <date>
qstringCounterpart, communication or description.
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 100, maximum 500).
e.g. 100

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 951,
            "company_id": 7,
            "source": "novadesko",
            "external_id": "string",
            "account_iban": "BE68539007547034",
            "account_bank": "string",
            "journal_id": 7,
            "amount": "1210.00",
            "currency": "EUR",
            "value_date": "2026-03-18T00:00:00.000000Z",
            "execution_date": "2026-03-15T09:41:00+00:00",
            "counterpart_name": "ACME SA",
            "counterpart_iban": "string",
            "communication": "+++000/0000/00101+++",
            "description": "Description",
            "status": "pending",
            "journal_entry_id": 1284,
            "matched_journal_entry_id": 42,
            "match_confidence": "high",
            "match_reason": "structured_communication",
            "matched_at": "2026-03-15T09:41:00+00:00",
            "booked_account_id": 42,
            "matched_rule_id": 42,
            "synced_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "journal": {},
            "links": [
                {}
            ],
            "matched_entry": {},
            "booked_account": {},
            "matched_rule": {},
            "journal_entry": {}
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/bank-transactions/matchPropose the matches write 10 / 1 min

Looks for the invoice paid by each pending transaction (structured communication, Novadesko link, amount and third party) and applies the bank rules.

Integration tokens need the write ability.

Rate limit: 10 requests per minute (429 beyond, see Retry-After).

Operation id companies.bank-transactions.match

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • proposalsinteger
    e.g. 17
Example
{
    "proposals": 17
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/match" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/match', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/match", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/match",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/bank-transactions/book-matchedBook the matched transactions write 5 / 1 min

Books every transaction with a high-confidence match (and medium ones with include_medium).

Integration tokens need the write ability.

Rate limit: 5 requests per minute (429 beyond, see Retry-After).

Operation id companies.bank-transactions.book-matched

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • include_mediumboolean
Example
{
    "include_medium": false
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • bookedinteger
    e.g. 14
  • skippedobject[]
    Properties
    • idinteger
    • reasonstring
Example
{
    "booked": 14,
    "skipped": [
        {
            "id": 42,
            "reason": "string"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/book-matched" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "include_medium": false
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/book-matched', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'include_medium' => false,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/book-matched", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "include_medium": false
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/book-matched",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "include_medium": False
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/bank-transactions/{bankTransaction}/bookBook a transaction write

Payment of the matched invoice (lettered with it), or allocation to the chosen account (fees, VAT, salaries…).

Integration tokens need the write ability.

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.bank-transactions.book

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
bankTransaction requiredintegerId of the bank transaction.
e.g. 951

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • account_idinteger | null
    Postable account; absent = payment of the matched invoice.
  • third_party_idinteger | null
  • labelstring | null
Example
{
    "account_id": 517,
    "label": "Frais de tenue de compte"
}

Responses

201Booked, with journal_entry

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema BankTransaction

Example
{
    "id": 951,
    "company_id": 7,
    "source": "novadesko",
    "external_id": "string",
    "account_iban": "BE68539007547034",
    "account_bank": "string",
    "journal_id": 7,
    "amount": "1210.00",
    "currency": "EUR",
    "value_date": "2026-03-18T00:00:00.000000Z",
    "execution_date": "2026-03-15T09:41:00+00:00",
    "counterpart_name": "ACME SA",
    "counterpart_iban": "string",
    "communication": "+++000/0000/00101+++",
    "description": "Description",
    "status": "pending",
    "journal_entry_id": 1284,
    "matched_journal_entry_id": 42,
    "match_confidence": "high",
    "match_reason": "structured_communication",
    "matched_at": "2026-03-15T09:41:00+00:00",
    "booked_account_id": 42,
    "matched_rule_id": 42,
    "synced_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal": {},
    "links": [
        {}
    ],
    "matched_entry": {},
    "booked_account": {},
    "matched_rule": {},
    "journal_entry": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/951/book" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "account_id": 517,
    "label": "Frais de tenue de compte"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/951/book', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'account_id' => 517,
        'label' => 'Frais de tenue de compte',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/951/book", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "account_id": 517,
      "label": "Frais de tenue de compte"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/951/book",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "account_id": 517,
        "label": "Frais de tenue de compte"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/bank-transactions/{bankTransaction}/ignoreIgnore or restore a transaction write

Integration tokens need the write ability.

Operation id companies.bank-transactions.ignore

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
bankTransaction requiredintegerId of the bank transaction.
e.g. 951

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • restoreboolean
Example
{
    "restore": false
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema BankTransaction

Example
{
    "id": 951,
    "company_id": 7,
    "source": "novadesko",
    "external_id": "string",
    "account_iban": "BE68539007547034",
    "account_bank": "string",
    "journal_id": 7,
    "amount": "1210.00",
    "currency": "EUR",
    "value_date": "2026-03-18T00:00:00.000000Z",
    "execution_date": "2026-03-15T09:41:00+00:00",
    "counterpart_name": "ACME SA",
    "counterpart_iban": "string",
    "communication": "+++000/0000/00101+++",
    "description": "Description",
    "status": "pending",
    "journal_entry_id": 1284,
    "matched_journal_entry_id": 42,
    "match_confidence": "high",
    "match_reason": "structured_communication",
    "matched_at": "2026-03-15T09:41:00+00:00",
    "booked_account_id": 42,
    "matched_rule_id": 42,
    "synced_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal": {},
    "links": [
        {}
    ],
    "matched_entry": {},
    "booked_account": {},
    "matched_rule": {},
    "journal_entry": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/951/ignore" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "restore": false
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/951/ignore', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'restore' => false,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/951/ignore", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "restore": false
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/951/ignore",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "restore": False
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/treasuryTreasury read

Accounting balance of each financial journal against the last statement, with the pending transactions.

Integration tokens need the read ability.

Operation id companies.treasury

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema Treasury

Example
{
    "accounts": [
        {
            "journal_id": 7,
            "code": "BNP",
            "label": "BNP Paribas Fortis",
            "iban": "BE68539007547034",
            "account": "550000",
            "accounting_balance": "19630.11",
            "last_statement_balance": "19630.11",
            "last_statement_date": "2026-03-15",
            "pending_count": 3,
            "pending_amount": "1842.50",
            "difference": "0.00"
        }
    ],
    "total_accounting_balance": "21480.61"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/treasury" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/treasury', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/treasury", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/treasury",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/bank-rulesList the bank rules read

Integration tokens need the read ability.

Operation id companies.bank-rules.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema BankRule[]

Array of BankRule

Example
[
    {
        "id": 6,
        "company_id": 7,
        "name": "Frais bancaires",
        "field": "counterpart_name",
        "operator": "contains",
        "pattern": "frais de tenue",
        "direction": "in",
        "account_id": 517,
        "third_party_id": 18,
        "label": "Facture Brasserie Dubuisson",
        "priority": 100,
        "is_active": true,
        "applied_count": 14,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1,
        "account": {
            "id": 580,
            "number": "702000",
            "label": "Prestations de services"
        },
        "third_party": {}
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/bank-rulesCreate a bank rule write

Allocates the transactions whose field matches the pattern to an account.

Integration tokens need the write ability.

Operation id companies.bank-rules.store

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • namestringrequired
  • fieldstringrequired
    counterpart_name counterpart_iban communication description any
  • operatorstring
    contains equals starts
  • patternstringrequired
  • directionstring
    in out any
  • account_idintegerrequired
    Postable account.
  • third_party_idinteger | null
  • labelstring | null
  • priorityinteger
    1 to 999.
  • is_activeboolean
Example
{
    "name": "Frais bancaires",
    "field": "description",
    "operator": "contains",
    "pattern": "frais de tenue",
    "direction": "out",
    "account_id": 517
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema BankRule

Example
{
    "id": 6,
    "company_id": 7,
    "name": "Frais bancaires",
    "field": "counterpart_name",
    "operator": "contains",
    "pattern": "frais de tenue",
    "direction": "in",
    "account_id": 517,
    "third_party_id": 18,
    "label": "Facture Brasserie Dubuisson",
    "priority": 100,
    "is_active": true,
    "applied_count": 14,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "third_party": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "name": "Frais bancaires",
    "field": "description",
    "operator": "contains",
    "pattern": "frais de tenue",
    "direction": "out",
    "account_id": 517
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'name' => 'Frais bancaires',
        'field' => 'description',
        'operator' => 'contains',
        'pattern' => 'frais de tenue',
        'direction' => 'out',
        'account_id' => 517,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "name": "Frais bancaires",
      "field": "description",
      "operator": "contains",
      "pattern": "frais de tenue",
      "direction": "out",
      "account_id": 517
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "name": "Frais bancaires",
        "field": "description",
        "operator": "contains",
        "pattern": "frais de tenue",
        "direction": "out",
        "account_id": 517
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/bank-rules/{bankRule}Update a bank rule write

Integration tokens need the write ability.

Operation id companies.bank-rules.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
bankRule requiredintegerId of the bank rule.
e.g. 6

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • namestring
  • fieldstring
    counterpart_name counterpart_iban communication description any
  • operatorstring
    contains equals starts
  • patternstring
  • directionstring
    in out any
  • account_idinteger
    Postable account.
  • third_party_idinteger | null
  • labelstring | null
  • priorityinteger
    1 to 999.
  • is_activeboolean
Example
{
    "is_active": false
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema BankRule

Example
{
    "id": 6,
    "company_id": 7,
    "name": "Frais bancaires",
    "field": "counterpart_name",
    "operator": "contains",
    "pattern": "frais de tenue",
    "direction": "in",
    "account_id": 517,
    "third_party_id": 18,
    "label": "Facture Brasserie Dubuisson",
    "priority": 100,
    "is_active": true,
    "applied_count": 14,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "third_party": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules/6" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "is_active": false
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules/6', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'is_active' => false,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules/6", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "is_active": false
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules/6",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "is_active": False
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/bank-rules/{bankRule}Delete a bank rule write

Integration tokens need the write ability.

Operation id companies.bank-rules.destroy

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
bankRule requiredintegerId of the bank rule.
e.g. 6

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

204Done, no body.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules/6" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules/6', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules/6", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-rules/6",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/coda-filesList the CODA files read

Integration tokens need the read ability.

Operation id companies.coda-files.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
journal_idinteger
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 31,
            "company_id": 7,
            "source": "novadesko",
            "external_id": "string",
            "filename": "CODA_2026_031.cod",
            "source_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "account_iban": "BE68539007547034",
            "account_bank": "string",
            "journal_id": 3,
            "statement_number": "031",
            "sequence": "string",
            "opening_balance": "18420.11",
            "closing_balance": "19630.11",
            "period_from": "2026-03-15T09:41:00+00:00",
            "period_to": "2026-03-15T09:41:00+00:00",
            "transactions_count": 12,
            "status": "imported",
            "synced_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "journal": {}
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/coda-files" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/coda-files', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/coda-files", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/coda-files",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/coda-files/{codaFile}/downloadDownload a CODA file read

Original statement file.

Integration tokens need the read ability.

Operation id companies.coda-files.download

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
codaFile requiredintegerId of the CODA file.
e.g. 31

Common headers: Accept-Language

Responses

200The CODA file.

Response headers Content-Disposition

text/plain

401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/coda-files/31/download" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/coda-files/31/download', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/coda-files/31/download", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/coda-files/31/download",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/payments/open-itemsSupplier items to pay read

Open supplier lines; payable is false when the IBAN of the supplier is missing.

Integration tokens need the read ability.

Operation id companies.payments.open-items

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • itemsobject[]
    Properties
    • line_idinteger
    • entry_idinteger
    • referencestring
      e.g. ACH 2026/000412
    • journal_codestring
      e.g. ACH
    • entry_datestring <date>
    • due_datestring <date> | null
    • overdueboolean
    • labelstring
    • external_referencestring | null
      e.g. F-2026-0412
    • structured_communicationstring | null
    • third_party_idinteger
    • third_partystring
      e.g. Brasserie Dubuisson SA
    • ibanstring | null
    • bicstring | null
    • amountstring <decimal>
      e.g. 655.82
    • payableboolean
  • totalstring <decimal>
    e.g. 655.82
  • payable_countinteger
    e.g. 1
Example
{
    "items": [
        {
            "line_id": 3391,
            "entry_id": 1284,
            "reference": "ACH 2026/000412",
            "journal_code": "ACH",
            "entry_date": "2026-03-15",
            "due_date": "2026-03-15",
            "overdue": true,
            "label": "Facture Brasserie Dubuisson",
            "external_reference": "F-2026-0412",
            "structured_communication": "000000000101",
            "third_party_id": 18,
            "third_party": "Brasserie Dubuisson SA",
            "iban": "BE68539007547034",
            "bic": "GEBABEBB",
            "amount": "655.82",
            "payable": true
        }
    ],
    "total": "655.82",
    "payable_count": 1
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/payments/open-items" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/payments/open-items', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/payments/open-items", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/payments/open-items",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/payments/sepaGenerate a SEPA credit transfer file write Not in demo 20 / 1 min

pain.001 XML for the chosen open items, debited from the bank of a financial journal. The file is to be uploaded to the bank: NovaFisko never initiates a payment.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 20 requests per minute (429 beyond, see Retry-After).

Operation id companies.payments.sepa

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • journal_idintegerrequired
    Financial journal with an IBAN.
  • line_idsinteger[]required
  • execution_datestring <date>required
    Today or later.
Example
{
    "journal_id": 7,
    "line_ids": [
        3394,
        3410
    ],
    "execution_date": "2026-04-02"
}

Responses

200SEPA pain.001 file. Headers X-Sepa-Count and X-Sepa-Total give the number of transfers and their total.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/payments/sepa" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "journal_id": 7,
    "line_ids": [
        3394,
        3410
    ],
    "execution_date": "2026-04-02"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/payments/sepa', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'journal_id' => 7,
        'line_ids' => [
            3394,
            3410,
        ],
        'execution_date' => '2026-04-02',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/payments/sepa", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "journal_id": 7,
      "line_ids": [
          3394,
          3410
      ],
      "execution_date": "2026-04-02"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/payments/sepa",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "journal_id": 7,
        "line_ids": [
            3394,
            3410
        ],
        "execution_date": "2026-04-02"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

VAT

VAT codes, periodic declarations, Intervat XML, customer and intra-community listings.

GET/v1/companies/{company}/vat-codesVAT codes read

Codes of the country pack with their rate, nature and declaration grids.

Integration tokens need the read ability.

Operation id companies.vat-codes.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
allbooleanInclude the inactive codes.

Common headers: Accept-Language

Responses

200OK

application/json

Schema VatCode[]

Array of VatCode

Example
[
    {
        "id": 4,
        "company_id": 7,
        "code": "V21",
        "label": "Ventes 21 %",
        "direction": "sale",
        "rate": "21.00",
        "nature": "standard",
        "deductible_pct": "100.00",
        "base_grid": "03",
        "vat_grid": "54",
        "due_vat_grid": "string",
        "credit_base_grid": "49",
        "credit_vat_grid": "64",
        "vat_account": "451100",
        "due_vat_account": "string",
        "description": "Description",
        "is_active": true,
        "sort_order": 13,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-codes" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-codes', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-codes", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-codes",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/vat-codes/{vatCode}Activate or describe a VAT code write

Rates and grids are part of the country pack and cannot be edited.

Integration tokens need the write ability.

Operation id companies.vat-codes.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
vatCode requiredintegerId of the VAT code.
e.g. 4

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • is_activeboolean
  • descriptionstring | null
Example
{
    "is_active": false
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema VatCode

Example
{
    "id": 4,
    "company_id": 7,
    "code": "V21",
    "label": "Ventes 21 %",
    "direction": "sale",
    "rate": "21.00",
    "nature": "standard",
    "deductible_pct": "100.00",
    "base_grid": "03",
    "vat_grid": "54",
    "due_vat_grid": "string",
    "credit_base_grid": "49",
    "credit_vat_grid": "64",
    "vat_account": "451100",
    "due_vat_account": "string",
    "description": "Description",
    "is_active": true,
    "sort_order": 13,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-codes/4" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "is_active": false
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-codes/4', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'is_active' => false,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-codes/4", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "is_active": false
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-codes/4",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "is_active": False
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/vat-declarationsVAT periods of a year read

Every period of the year with its declaration, or a computed preview when none exists yet.

Integration tokens need the read ability.

Operation id companies.vat.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
yearintegerCurrent year by default.
e.g. 2026

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • yearinteger
    e.g. 2026
  • period_typestring
    monthly quarterly
  • periodsobject[]
    Properties
    • periodinteger
      e.g. 1
    • labelstring
      e.g. 1T 2026
    • starts_onstring <date>
    • ends_onstring <date>
    • declarationVatDeclaration | null
    • previewVatComputation | null
Example
{
    "year": 2026,
    "period_type": "monthly",
    "periods": [
        {
            "period": 1,
            "label": "1T 2026",
            "starts_on": "2026-03-15",
            "ends_on": "2026-03-15",
            "declaration": {
                "id": 14,
                "company_id": 7,
                "period_type": "monthly",
                "year": 2026,
                "period": 1,
                "starts_on": "2026-03-15T09:41:00+00:00",
                "ends_on": "2026-03-15T09:41:00+00:00",
                "grids": {
                    "00": "0.00",
                    "01": "0.00",
                    "02": "0.00",
                    "03": "1000.00",
                    "54": "210.00",
                    "59": "52.50",
                    "71": "157.50",
                    "72": "0.00",
                    "81": "0.00",
                    "82": "250.00",
                    "83": "0.00"
                },
                "amount_due": "157.50",
                "amount_refund": "0.00",
                "status": "draft",
                "validated_at": "2026-03-15T09:41:00+00:00",
                "validated_by": 1,
                "submitted_at": "2026-03-15T09:41:00+00:00",
                "submission_reference": "string",
                "journal_entry_id": 1284,
                "warnings": [
                    "string"
                ],
                "created_at": "2026-03-15T09:41:00+00:00",
                "updated_at": "2026-03-15T09:41:00+00:00",
                "lock_version": 3,
                "version": 3,
                "journal_entry": {}
            },
            "preview": {
                "grids": {
                    "00": "0.00",
                    "01": "0.00",
                    "02": "0.00",
                    "03": "1000.00",
                    "54": "210.00",
                    "59": "52.50",
                    "71": "157.50",
                    "72": "0.00",
                    "81": "0.00",
                    "82": "250.00",
                    "83": "0.00"
                },
                "amount_due": "157.50",
                "amount_refund": "0.00",
                "warnings": [
                    "string"
                ],
                "entries": 38
            }
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/vat-declarationsCreate or refresh a draft declaration write

Computes the grids of the period and stores them as a draft. Calling it again recomputes the draft.

Integration tokens need the write ability.

Operation id companies.vat.store

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • yearintegerrequired
    2000 to 2100.
    e.g. 2026
  • periodintegerrequired
    Month (1-12) or quarter (1-4) according to the VAT regime of the file.
    e.g. 1
Example
{
    "year": 2026,
    "period": 1
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema VatDeclaration

Example
{
    "id": 14,
    "company_id": 7,
    "period_type": "monthly",
    "year": 2026,
    "period": 1,
    "starts_on": "2026-03-15T09:41:00+00:00",
    "ends_on": "2026-03-15T09:41:00+00:00",
    "grids": {
        "00": "0.00",
        "01": "0.00",
        "02": "0.00",
        "03": "1000.00",
        "54": "210.00",
        "59": "52.50",
        "71": "157.50",
        "72": "0.00",
        "81": "0.00",
        "82": "250.00",
        "83": "0.00"
    },
    "amount_due": "157.50",
    "amount_refund": "0.00",
    "status": "draft",
    "validated_at": "2026-03-15T09:41:00+00:00",
    "validated_by": 1,
    "submitted_at": "2026-03-15T09:41:00+00:00",
    "submission_reference": "string",
    "journal_entry_id": 1284,
    "warnings": [
        "string"
    ],
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal_entry": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "year": 2026,
    "period": 1
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'year' => 2026,
        'period' => 1,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "year": 2026,
      "period": 1
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "year": 2026,
        "period": 1
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/vat-declarations/previewCompute a VAT period read

Grids computed from the entries of the period, without saving anything.

Integration tokens need the read ability.

Operation id companies.vat.preview

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
year requiredinteger2000 to 2100.
e.g. 2026
period requiredintegerMonth (1-12) or quarter (1-4) according to the VAT regime of the file.
e.g. 1

Common headers: Accept-Language

Responses

200OK

application/json

Schema object & VatComputation
  • starts_onstring <date>
  • ends_onstring <date>

Includes VatComputation

Example
{
    "starts_on": "2026-03-15",
    "ends_on": "2026-03-15",
    "grids": {
        "00": "0.00",
        "01": "0.00",
        "02": "0.00",
        "03": "1000.00",
        "54": "210.00",
        "59": "52.50",
        "71": "157.50",
        "72": "0.00",
        "81": "0.00",
        "82": "250.00",
        "83": "0.00"
    },
    "amount_due": "157.50",
    "amount_refund": "0.00",
    "warnings": [
        "string"
    ],
    "entries": 38
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/preview?year=2026&period=1" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/preview', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'query' => [
        'year' => '2026',
        'period' => '1',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/preview?year=2026&period=1", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/preview",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    params={
        "year": "2026",
        "period": "1"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/vat-declarations/intracom-listingIntra-community listing read

Intra-EU supplies of goods and services per customer for the period. format=xml downloads the Intervat file.

Integration tokens need the read ability.

Operation id companies.vat.intracom-listing

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
year requiredinteger2000 to 2100.
e.g. 2026
period requiredintegerMonth (1-12) or quarter (1-4) according to the VAT regime of the file.
e.g. 1
formatstring
xml

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • yearinteger
  • periodinteger
  • period_typestring
  • fromstring <date>
  • tostring <date>
  • clientsobject[]
    Properties
    • vat_numberstring
      e.g. NL853746333B01
    • countrystring
      e.g. NL
    • namestring
    • codestring
      L goods, S services, T triangular.
      e.g. S
    • amountstring <decimal>
  • totalstring <decimal>
  • total_goodsstring <decimal>
  • total_servicesstring <decimal>
Example
{
    "year": 2026,
    "period": 3,
    "period_type": "string",
    "from": "2026-03-15",
    "to": "2026-03-15",
    "clients": [
        {
            "vat_number": "NL853746333B01",
            "country": "NL",
            "name": "Le Comptoir Montois SRL",
            "code": "S",
            "amount": "1210.00"
        }
    ],
    "total": "1210.00",
    "total_goods": "1210.00",
    "total_services": "1210.00"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/intracom-listing?year=2026&period=1" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/intracom-listing', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'query' => [
        'year' => '2026',
        'period' => '1',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/intracom-listing?year=2026&period=1", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/intracom-listing",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    params={
        "year": "2026",
        "period": "1"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/vat-declarations/client-listing/{year}Annual customer listing read

Belgian VAT-liable customers of the year with turnover and VAT; declare is true above the legal threshold of 250 EUR. format=xml downloads the Intervat file.

Integration tokens need the read ability.

Operation id companies.vat.client-listing

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
year requiredintegerCalendar year.
e.g. 2026

Query parameters

NameTypeDescription
formatstring
xml

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • yearinteger
    e.g. 2026
  • clientsobject[]
    Properties
    • vat_numberstring
      e.g. BE0403170701
    • namestring
      e.g. ACME SA
    • turnovernumber
      e.g. 18250
    • vatnumber
      e.g. 3832.5
    • declareboolean
  • total_turnovernumber
  • total_vatnumber
Example
{
    "year": 2026,
    "clients": [
        {
            "vat_number": "BE0403170701",
            "name": "ACME SA",
            "turnover": 18250,
            "vat": 3832.5,
            "declare": true
        }
    ],
    "total_turnover": 12.5,
    "total_vat": 12.5
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/client-listing/2026" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/client-listing/2026', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/client-listing/2026", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/client-listing/2026",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/vat-declarations/{vatDeclaration}VAT declaration read

With its settlement entry once validated.

Integration tokens need the read ability.

Operation id companies.vat.show

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
vatDeclaration requiredintegerId of the VAT declaration.
e.g. 14

Common headers: Accept-Language

Responses

200OK

application/json

Schema VatDeclaration

Example
{
    "id": 14,
    "company_id": 7,
    "period_type": "monthly",
    "year": 2026,
    "period": 1,
    "starts_on": "2026-03-15T09:41:00+00:00",
    "ends_on": "2026-03-15T09:41:00+00:00",
    "grids": {
        "00": "0.00",
        "01": "0.00",
        "02": "0.00",
        "03": "1000.00",
        "54": "210.00",
        "59": "52.50",
        "71": "157.50",
        "72": "0.00",
        "81": "0.00",
        "82": "250.00",
        "83": "0.00"
    },
    "amount_due": "157.50",
    "amount_refund": "0.00",
    "status": "draft",
    "validated_at": "2026-03-15T09:41:00+00:00",
    "validated_by": 1,
    "submitted_at": "2026-03-15T09:41:00+00:00",
    "submission_reference": "string",
    "journal_entry_id": 1284,
    "warnings": [
        "string"
    ],
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal_entry": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/vat-declarations/{vatDeclaration}/validateValidate a declaration write

Freezes the grids and posts the VAT settlement entry (accounts of settings.auto_entries.vat). Emits the webhook vat.declaration_validated.

Integration tokens need the write ability.

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.vat.validate

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
vatDeclaration requiredintegerId of the VAT declaration.
e.g. 14

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema VatDeclaration

Example
{
    "id": 14,
    "company_id": 7,
    "period_type": "monthly",
    "year": 2026,
    "period": 1,
    "starts_on": "2026-03-15T09:41:00+00:00",
    "ends_on": "2026-03-15T09:41:00+00:00",
    "grids": {
        "00": "0.00",
        "01": "0.00",
        "02": "0.00",
        "03": "1000.00",
        "54": "210.00",
        "59": "52.50",
        "71": "157.50",
        "72": "0.00",
        "81": "0.00",
        "82": "250.00",
        "83": "0.00"
    },
    "amount_due": "157.50",
    "amount_refund": "0.00",
    "status": "draft",
    "validated_at": "2026-03-15T09:41:00+00:00",
    "validated_by": 1,
    "submitted_at": "2026-03-15T09:41:00+00:00",
    "submission_reference": "string",
    "journal_entry_id": 1284,
    "warnings": [
        "string"
    ],
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal_entry": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14/validate" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14/validate', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14/validate", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14/validate",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/vat-declarations/{vatDeclaration}/submitMark a declaration as submitted write

Records the Intervat reference. NovaFisko does not file the declaration itself: download the XML and upload it on Intervat.

Integration tokens need the write ability.

Operation id companies.vat.submit

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
vatDeclaration requiredintegerId of the VAT declaration.
e.g. 14

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • referencestring | null
    Intervat receipt reference.
Example
{
    "reference": "INTERVAT-2026-04-0098123"
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema VatDeclaration

Example
{
    "id": 14,
    "company_id": 7,
    "period_type": "monthly",
    "year": 2026,
    "period": 1,
    "starts_on": "2026-03-15T09:41:00+00:00",
    "ends_on": "2026-03-15T09:41:00+00:00",
    "grids": {
        "00": "0.00",
        "01": "0.00",
        "02": "0.00",
        "03": "1000.00",
        "54": "210.00",
        "59": "52.50",
        "71": "157.50",
        "72": "0.00",
        "81": "0.00",
        "82": "250.00",
        "83": "0.00"
    },
    "amount_due": "157.50",
    "amount_refund": "0.00",
    "status": "draft",
    "validated_at": "2026-03-15T09:41:00+00:00",
    "validated_by": 1,
    "submitted_at": "2026-03-15T09:41:00+00:00",
    "submission_reference": "string",
    "journal_entry_id": 1284,
    "warnings": [
        "string"
    ],
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal_entry": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14/submit" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "reference": "INTERVAT-2026-04-0098123"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14/submit', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'reference' => 'INTERVAT-2026-04-0098123',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14/submit", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "reference": "INTERVAT-2026-04-0098123"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14/submit",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "reference": "INTERVAT-2026-04-0098123"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/vat-declarations/{vatDeclaration}/xmlIntervat XML of a declaration read

File ready to upload on Intervat (VATConsignment).

Integration tokens need the read ability.

Operation id companies.vat.xml

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
vatDeclaration requiredintegerId of the VAT declaration.
e.g. 14

Common headers: Accept-Language

Responses

200Intervat XML file.

Response headers Content-Disposition

application/xml

401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14/xml" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14/xml', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14/xml", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/14/xml",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Fixed assets

Fixed asset register, depreciation plans, bookings, disposals.

GET/v1/companies/{company}/fixed-assetsFixed asset register read

With the depreciation plan of each asset.

Integration tokens need the read ability.

Operation id companies.fixed-assets.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema FixedAsset[]

Array of FixedAsset

Example
[
    {
        "id": 9,
        "company_id": 7,
        "source": "manual",
        "external_id": "string",
        "reference": "IMM-2026-003",
        "name": "Four mixte Rational",
        "category": "it_equipment",
        "asset_group": "string",
        "asset_account_id": 42,
        "depreciation_account_id": 42,
        "expense_account_id": 42,
        "imported_document_id": 42,
        "acquisition_date": "2026-02-01T00:00:00.000000Z",
        "acquisition_cost": "12400.00",
        "residual_value": "0.00",
        "useful_life_years": 5,
        "method": "linear",
        "prorata_temporis": true,
        "start_date": "2026-03-15T09:41:00+00:00",
        "status": "active",
        "notes": "string",
        "disposed_on": "2026-03-15T09:41:00+00:00",
        "disposal_price": "1210.00",
        "disposal_entry_id": 42,
        "investment_deduction_pct": "1210.00",
        "investment_deduction_spread": true,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1,
        "lines": [
            {
                "id": 42,
                "fixed_asset_id": 9,
                "year": 2026,
                "period_start": "2026-03-15T09:41:00+00:00",
                "period_end": "2026-03-15T09:41:00+00:00",
                "amount": "2269.37",
                "cumulative_amount": "2269.37",
                "remaining_value": "10130.63",
                "status": "planned",
                "journal_entry_id": 1284,
                "booked_amount": "0.00"
            }
        ],
        "asset_account": {
            "id": 580,
            "number": "702000",
            "label": "Prestations de services"
        },
        "depreciation_account": {
            "id": 580,
            "number": "702000",
            "label": "Prestations de services"
        },
        "expense_account": {
            "id": 580,
            "number": "702000",
            "label": "Prestations de services"
        }
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/fixed-assetsCreate a fixed asset write

Builds the depreciation plan (linear or declining, pro rata temporis) and resolves the asset, depreciation and expense accounts.

Integration tokens need the write ability.

Operation id companies.fixed-assets.store

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • namestringrequired
  • referencestring | null
  • categorystringrequired
    it_equipment vehicle furniture machinery building software other
  • asset_groupstring | null
  • investment_deduction_pctnumber | null
    0 to 100.
  • investment_deduction_spreadboolean
  • asset_account_idinteger | null
    Class 2 account; resolved from the category when absent.
  • acquisition_datestring <date>required
  • acquisition_coststringrequired
    Decimal, excl. VAT.
  • residual_valuestring | null
    Decimal.
  • useful_life_yearsintegerrequired
    1 to 50.
  • methodstring
    linear declining
  • prorata_temporisboolean
    True by default.
  • start_datestring <date> | null
    Start of the depreciation; the acquisition date by default.
  • notesstring | null
Example
{
    "name": "Four mixte Rational",
    "category": "machinery",
    "acquisition_date": "2026-02-01",
    "acquisition_cost": "12400.00",
    "useful_life_years": 5
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema FixedAsset

Example
{
    "id": 9,
    "company_id": 7,
    "source": "manual",
    "external_id": "string",
    "reference": "IMM-2026-003",
    "name": "Four mixte Rational",
    "category": "it_equipment",
    "asset_group": "string",
    "asset_account_id": 42,
    "depreciation_account_id": 42,
    "expense_account_id": 42,
    "imported_document_id": 42,
    "acquisition_date": "2026-02-01T00:00:00.000000Z",
    "acquisition_cost": "12400.00",
    "residual_value": "0.00",
    "useful_life_years": 5,
    "method": "linear",
    "prorata_temporis": true,
    "start_date": "2026-03-15T09:41:00+00:00",
    "status": "active",
    "notes": "string",
    "disposed_on": "2026-03-15T09:41:00+00:00",
    "disposal_price": "1210.00",
    "disposal_entry_id": 42,
    "investment_deduction_pct": "1210.00",
    "investment_deduction_spread": true,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "lines": [
        {
            "id": 42,
            "fixed_asset_id": 9,
            "year": 2026,
            "period_start": "2026-03-15T09:41:00+00:00",
            "period_end": "2026-03-15T09:41:00+00:00",
            "amount": "2269.37",
            "cumulative_amount": "2269.37",
            "remaining_value": "10130.63",
            "status": "planned",
            "journal_entry_id": 1284,
            "booked_amount": "0.00"
        }
    ],
    "asset_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "depreciation_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "expense_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "name": "Four mixte Rational",
    "category": "machinery",
    "acquisition_date": "2026-02-01",
    "acquisition_cost": "12400.00",
    "useful_life_years": 5
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'name' => 'Four mixte Rational',
        'category' => 'machinery',
        'acquisition_date' => '2026-02-01',
        'acquisition_cost' => '12400.00',
        'useful_life_years' => 5,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "name": "Four mixte Rational",
      "category": "machinery",
      "acquisition_date": "2026-02-01",
      "acquisition_cost": "12400.00",
      "useful_life_years": 5
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "name": "Four mixte Rational",
        "category": "machinery",
        "acquisition_date": "2026-02-01",
        "acquisition_cost": "12400.00",
        "useful_life_years": 5
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/fixed-assets/groups/{fiscalYear}Depreciation table per group read

Acquisition cost, accumulated depreciation, depreciation of the year and net book value per group, for a fiscal year.

Integration tokens need the read ability.

Operation id companies.fixed-assets.groups

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • fiscal_yearstring
    e.g. 2026
  • groupsobject[]
    Properties
    • groupstring
      e.g. machinery
    • countinteger
      e.g. 1
    • acquisition_coststring <decimal>
      e.g. 12400.00
    • accumulatedstring <decimal>
      e.g. 2269.37
    • net_book_valuestring <decimal>
      e.g. 10130.63
    • year_depreciationstring <decimal>
      e.g. 2269.37
    • investment_deductionstring <decimal>
      e.g. 0.00
    • assetsobject[]
  • totalsobject
    Properties
    • acquisition_coststring <decimal>
    • accumulatedstring <decimal>
    • net_book_valuestring <decimal>
    • year_depreciationstring <decimal>
    • investment_deductionstring <decimal>
Example
{
    "fiscal_year": "2026",
    "groups": [
        {
            "group": "machinery",
            "count": 1,
            "acquisition_cost": "12400.00",
            "accumulated": "2269.37",
            "net_book_value": "10130.63",
            "year_depreciation": "2269.37",
            "investment_deduction": "0.00",
            "assets": [
                {}
            ]
        }
    ],
    "totals": {
        "acquisition_cost": "1210.00",
        "accumulated": "1210.00",
        "net_book_value": "1210.00",
        "year_depreciation": "1210.00",
        "investment_deduction": "1210.00"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/groups/2" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/groups/2', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/groups/2", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/groups/2",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/fixed-assets/{fixedAsset}Fixed asset read

Integration tokens need the read ability.

Operation id companies.fixed-assets.show

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fixedAsset requiredintegerId of the fixed asset.
e.g. 9

Common headers: Accept-Language

Responses

200OK

application/json

Schema FixedAsset

Example
{
    "id": 9,
    "company_id": 7,
    "source": "manual",
    "external_id": "string",
    "reference": "IMM-2026-003",
    "name": "Four mixte Rational",
    "category": "it_equipment",
    "asset_group": "string",
    "asset_account_id": 42,
    "depreciation_account_id": 42,
    "expense_account_id": 42,
    "imported_document_id": 42,
    "acquisition_date": "2026-02-01T00:00:00.000000Z",
    "acquisition_cost": "12400.00",
    "residual_value": "0.00",
    "useful_life_years": 5,
    "method": "linear",
    "prorata_temporis": true,
    "start_date": "2026-03-15T09:41:00+00:00",
    "status": "active",
    "notes": "string",
    "disposed_on": "2026-03-15T09:41:00+00:00",
    "disposal_price": "1210.00",
    "disposal_entry_id": 42,
    "investment_deduction_pct": "1210.00",
    "investment_deduction_spread": true,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "lines": [
        {
            "id": 42,
            "fixed_asset_id": 9,
            "year": 2026,
            "period_start": "2026-03-15T09:41:00+00:00",
            "period_end": "2026-03-15T09:41:00+00:00",
            "amount": "2269.37",
            "cumulative_amount": "2269.37",
            "remaining_value": "10130.63",
            "status": "planned",
            "journal_entry_id": 1284,
            "booked_amount": "0.00"
        }
    ],
    "asset_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "depreciation_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "expense_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/fixed-assets/{fixedAsset}Update a fixed asset write

The plan is rebuilt for the years not booked yet.

Integration tokens need the write ability.

Operation id companies.fixed-assets.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fixedAsset requiredintegerId of the fixed asset.
e.g. 9

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • namestring
  • categorystring
    it_equipment vehicle furniture machinery building software other
  • asset_groupstring | null
  • investment_deduction_pctnumber | null
  • investment_deduction_spreadboolean
  • asset_account_idinteger | null
  • residual_valuestring
  • useful_life_yearsinteger
  • methodstring
    linear declining
  • prorata_temporisboolean
  • statusstring
    active fully_depreciated disposed
  • notesstring | null
Example
{
    "useful_life_years": 7
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema FixedAsset

Example
{
    "id": 9,
    "company_id": 7,
    "source": "manual",
    "external_id": "string",
    "reference": "IMM-2026-003",
    "name": "Four mixte Rational",
    "category": "it_equipment",
    "asset_group": "string",
    "asset_account_id": 42,
    "depreciation_account_id": 42,
    "expense_account_id": 42,
    "imported_document_id": 42,
    "acquisition_date": "2026-02-01T00:00:00.000000Z",
    "acquisition_cost": "12400.00",
    "residual_value": "0.00",
    "useful_life_years": 5,
    "method": "linear",
    "prorata_temporis": true,
    "start_date": "2026-03-15T09:41:00+00:00",
    "status": "active",
    "notes": "string",
    "disposed_on": "2026-03-15T09:41:00+00:00",
    "disposal_price": "1210.00",
    "disposal_entry_id": 42,
    "investment_deduction_pct": "1210.00",
    "investment_deduction_spread": true,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "lines": [
        {
            "id": 42,
            "fixed_asset_id": 9,
            "year": 2026,
            "period_start": "2026-03-15T09:41:00+00:00",
            "period_end": "2026-03-15T09:41:00+00:00",
            "amount": "2269.37",
            "cumulative_amount": "2269.37",
            "remaining_value": "10130.63",
            "status": "planned",
            "journal_entry_id": 1284,
            "booked_amount": "0.00"
        }
    ],
    "asset_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "depreciation_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "expense_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "useful_life_years": 7
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'useful_life_years' => 7,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "useful_life_years": 7
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "useful_life_years": 7
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/fixed-assets/book-period/{fiscalYear}Book the depreciation of a period write

One miscellaneous entry for every asset, for a month of the fiscal year. 200 with entry: null when there is nothing to book.

Integration tokens need the write ability.

Operation id companies.fixed-assets.book-period

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • period_numberintegerrequired
    1 to 12.
Example
{
    "period_number": 3
}

Responses

200Nothing to book

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
Example
{
    "entry": {
        "id": 1284,
        "company_id": 7,
        "fiscal_year_id": 2,
        "period_id": 16,
        "journal_id": 3,
        "number": 412,
        "entry_date": "2026-03-15T00:00:00.000000Z",
        "due_date": "2026-03-15T09:41:00+00:00",
        "label": "Facture Brasserie Dubuisson SA",
        "reference": "F-2026-0412",
        "structured_communication": "000000000101",
        "third_party_id": 18,
        "status": "posted",
        "origin": "manual",
        "created_by": 1,
        "posted_at": "2026-03-15T09:41:00+00:00",
        "reversed_entry_id": 42,
        "reversed_by_entry_id": 42,
        "recurring_entry_id": 42,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal": {
            "id": 3,
            "code": "VEN",
            "type": "sale"
        },
        "third_party": {
            "id": 18,
            "name": "Brasserie Dubuisson SA"
        },
        "lines": [
            {
                "id": 3391,
                "journal_entry_id": 1284,
                "position": 1,
                "account_id": 580,
                "third_party_id": 18,
                "label": "Brasserie Dubuisson SA",
                "debit": "0.00",
                "credit": "1000.00",
                "vat_code_id": 4,
                "vat_base": "1000.00",
                "reconciliation_code": "AB",
                "cost_center_id": 42,
                "project_id": 42,
                "reminder_level": 0,
                "reminder_sent_at": "2026-03-15T09:41:00+00:00",
                "account": {
                    "id": 580,
                    "number": "702000",
                    "label": "Prestations de services"
                },
                "vat_code": {}
            }
        ]
    },
    "period": "Mars 2026"
}
201Depreciation booked

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
Example
{
    "entry": {
        "id": 1284,
        "company_id": 7,
        "fiscal_year_id": 2,
        "period_id": 16,
        "journal_id": 3,
        "number": 412,
        "entry_date": "2026-03-15T00:00:00.000000Z",
        "due_date": "2026-03-15T09:41:00+00:00",
        "label": "Facture Brasserie Dubuisson SA",
        "reference": "F-2026-0412",
        "structured_communication": "000000000101",
        "third_party_id": 18,
        "status": "posted",
        "origin": "manual",
        "created_by": 1,
        "posted_at": "2026-03-15T09:41:00+00:00",
        "reversed_entry_id": 42,
        "reversed_by_entry_id": 42,
        "recurring_entry_id": 42,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal": {
            "id": 3,
            "code": "VEN",
            "type": "sale"
        },
        "third_party": {
            "id": 18,
            "name": "Brasserie Dubuisson SA"
        },
        "lines": [
            {
                "id": 3391,
                "journal_entry_id": 1284,
                "position": 1,
                "account_id": 580,
                "third_party_id": 18,
                "label": "Brasserie Dubuisson SA",
                "debit": "0.00",
                "credit": "1000.00",
                "vat_code_id": 4,
                "vat_base": "1000.00",
                "reconciliation_code": "AB",
                "cost_center_id": 42,
                "project_id": 42,
                "reminder_level": 0,
                "reminder_sent_at": "2026-03-15T09:41:00+00:00",
                "account": {
                    "id": 580,
                    "number": "702000",
                    "label": "Prestations de services"
                },
                "vat_code": {}
            }
        ]
    },
    "period": "Mars 2026"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/book-period/2" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "period_number": 3
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/book-period/2', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'period_number' => 3,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/book-period/2", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "period_number": 3
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/book-period/2",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "period_number": 3
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/fixed-assets/{fixedAsset}/book/{fiscalYear}Book the yearly depreciation of an asset write

Miscellaneous entry 6302 / 2x09 for the fiscal year.

Integration tokens need the write ability.

Error codes (code):

  • period_locked: the period is locked or the fiscal year is closed; reason tells which (period_locked or fiscal_year_closed)

Operation id companies.fixed-assets.book

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fixedAsset requiredintegerId of the fixed asset.
e.g. 9
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema FixedAsset

Example
{
    "id": 9,
    "company_id": 7,
    "source": "manual",
    "external_id": "string",
    "reference": "IMM-2026-003",
    "name": "Four mixte Rational",
    "category": "it_equipment",
    "asset_group": "string",
    "asset_account_id": 42,
    "depreciation_account_id": 42,
    "expense_account_id": 42,
    "imported_document_id": 42,
    "acquisition_date": "2026-02-01T00:00:00.000000Z",
    "acquisition_cost": "12400.00",
    "residual_value": "0.00",
    "useful_life_years": 5,
    "method": "linear",
    "prorata_temporis": true,
    "start_date": "2026-03-15T09:41:00+00:00",
    "status": "active",
    "notes": "string",
    "disposed_on": "2026-03-15T09:41:00+00:00",
    "disposal_price": "1210.00",
    "disposal_entry_id": 42,
    "investment_deduction_pct": "1210.00",
    "investment_deduction_spread": true,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "lines": [
        {
            "id": 42,
            "fixed_asset_id": 9,
            "year": 2026,
            "period_start": "2026-03-15T09:41:00+00:00",
            "period_end": "2026-03-15T09:41:00+00:00",
            "amount": "2269.37",
            "cumulative_amount": "2269.37",
            "remaining_value": "10130.63",
            "status": "planned",
            "journal_entry_id": 1284,
            "booked_amount": "0.00"
        }
    ],
    "asset_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "depreciation_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "expense_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed, or the write was refused because its period is locked or its fiscal year is closed (code: period_locked, with reason). PeriodLockedError

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9/book/2" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9/book/2', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9/book/2", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9/book/2",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/fixed-assets/{fixedAsset}/disposeDispose of an asset write

Sale (price above 0) or scrapping (price 0): posts the disposal entry with the gain or loss.

Integration tokens need the write ability.

Operation id companies.fixed-assets.dispose

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fixedAsset requiredintegerId of the fixed asset.
e.g. 9

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • datestring <date>required
  • sale_pricestring | null
    Decimal, excl. VAT.
  • labelstring | null
Example
{
    "date": "2026-09-30",
    "sale_price": "4500.00"
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
Example
{
    "asset": {
        "id": 9,
        "company_id": 7,
        "source": "manual",
        "external_id": "string",
        "reference": "IMM-2026-003",
        "name": "Four mixte Rational",
        "category": "it_equipment",
        "asset_group": "string",
        "asset_account_id": 42,
        "depreciation_account_id": 42,
        "expense_account_id": 42,
        "imported_document_id": 42,
        "acquisition_date": "2026-02-01T00:00:00.000000Z",
        "acquisition_cost": "12400.00",
        "residual_value": "0.00",
        "useful_life_years": 5,
        "method": "linear",
        "prorata_temporis": true,
        "start_date": "2026-03-15T09:41:00+00:00",
        "status": "active",
        "notes": "string",
        "disposed_on": "2026-03-15T09:41:00+00:00",
        "disposal_price": "1210.00",
        "disposal_entry_id": 42,
        "investment_deduction_pct": "1210.00",
        "investment_deduction_spread": true,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1,
        "lines": [
            {
                "id": 42,
                "fixed_asset_id": 9,
                "year": 2026,
                "period_start": "2026-03-15T09:41:00+00:00",
                "period_end": "2026-03-15T09:41:00+00:00",
                "amount": "2269.37",
                "cumulative_amount": "2269.37",
                "remaining_value": "10130.63",
                "status": "planned",
                "journal_entry_id": 1284,
                "booked_amount": "0.00"
            }
        ],
        "asset_account": {
            "id": 580,
            "number": "702000",
            "label": "Prestations de services"
        },
        "depreciation_account": {
            "id": 580,
            "number": "702000",
            "label": "Prestations de services"
        },
        "expense_account": {
            "id": 580,
            "number": "702000",
            "label": "Prestations de services"
        }
    },
    "entry": {
        "id": 1284,
        "company_id": 7,
        "fiscal_year_id": 2,
        "period_id": 16,
        "journal_id": 3,
        "number": 412,
        "entry_date": "2026-03-15T00:00:00.000000Z",
        "due_date": "2026-03-15T09:41:00+00:00",
        "label": "Facture Brasserie Dubuisson SA",
        "reference": "F-2026-0412",
        "structured_communication": "000000000101",
        "third_party_id": 18,
        "status": "posted",
        "origin": "manual",
        "created_by": 1,
        "posted_at": "2026-03-15T09:41:00+00:00",
        "reversed_entry_id": 42,
        "reversed_by_entry_id": 42,
        "recurring_entry_id": 42,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal": {
            "id": 3,
            "code": "VEN",
            "type": "sale"
        },
        "third_party": {
            "id": 18,
            "name": "Brasserie Dubuisson SA"
        },
        "lines": [
            {
                "id": 3391,
                "journal_entry_id": 1284,
                "position": 1,
                "account_id": 580,
                "third_party_id": 18,
                "label": "Brasserie Dubuisson SA",
                "debit": "0.00",
                "credit": "1000.00",
                "vat_code_id": 4,
                "vat_base": "1000.00",
                "reconciliation_code": "AB",
                "cost_center_id": 42,
                "project_id": 42,
                "reminder_level": 0,
                "reminder_sent_at": "2026-03-15T09:41:00+00:00",
                "account": {
                    "id": 580,
                    "number": "702000",
                    "label": "Prestations de services"
                },
                "vat_code": {}
            }
        ]
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9/dispose" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "date": "2026-09-30",
    "sale_price": "4500.00"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9/dispose', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'date' => '2026-09-30',
        'sale_price' => '4500.00',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9/dispose", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "date": "2026-09-30",
      "sale_price": "4500.00"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/9/dispose",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "date": "2026-09-30",
        "sale_price": "4500.00"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Reports

Trial balance, general ledger, balance sheet and income statement, third party and aged balances.

GET/v1/companies/{company}/journals/{journal}/entriesEntries of a journal read

Full entries of the journal over a date range, in number order (journal book).

Integration tokens need the read ability.

Operation id companies.reports.journal

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
journal requiredintegerId of the journal.
e.g. 3

Query parameters

NameTypeDescription
fromstring <date>
tostring <date>

Common headers: Accept-Language

Responses

200OK

application/json

Schema JournalEntry[]

Array of JournalEntry

Example
[
    {
        "id": 1284,
        "company_id": 7,
        "fiscal_year_id": 2,
        "period_id": 16,
        "journal_id": 3,
        "number": 412,
        "entry_date": "2026-03-15T00:00:00.000000Z",
        "due_date": "2026-03-15T09:41:00+00:00",
        "label": "Facture Brasserie Dubuisson SA",
        "reference": "F-2026-0412",
        "structured_communication": "000000000101",
        "third_party_id": 18,
        "status": "posted",
        "origin": "manual",
        "created_by": 1,
        "posted_at": "2026-03-15T09:41:00+00:00",
        "reversed_entry_id": 42,
        "reversed_by_entry_id": 42,
        "recurring_entry_id": 42,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal": {
            "id": 3,
            "code": "VEN",
            "type": "sale"
        },
        "third_party": {
            "id": 18,
            "name": "Brasserie Dubuisson SA"
        },
        "lines": [
            {
                "id": 3391,
                "journal_entry_id": 1284,
                "position": 1,
                "account_id": 580,
                "third_party_id": 18,
                "label": "Brasserie Dubuisson SA",
                "debit": "0.00",
                "credit": "1000.00",
                "vat_code_id": 4,
                "vat_base": "1000.00",
                "reconciliation_code": "AB",
                "cost_center_id": 42,
                "project_id": 42,
                "reminder_level": 0,
                "reminder_sent_at": "2026-03-15T09:41:00+00:00",
                "account": {
                    "id": 580,
                    "number": "702000",
                    "label": "Prestations de services"
                },
                "vat_code": {}
            }
        ]
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/3/entries" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/3/entries', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/3/entries", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/3/entries",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/fiscal-years/{fiscalYear}/trial-balanceTrial balance read

Integration tokens need the read ability.

Operation id companies.reports.trial-balance

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Query parameters

NameTypeDescription
fromstring <date>
tostring <date>
include_emptybooleanInclude the accounts without movement.

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • fiscal_yearstring
    e.g. 2026
  • fromstring <date>
  • tostring <date>
  • linesobject[]
    Properties
    • account_idinteger
      e.g. 223
    • numberstring
      e.g. 400000
    • labelstring
      e.g. Clients
    • typestring
      e.g. asset
    • debitstring <decimal>
      e.g. 1210.00
    • creditstring <decimal>
      e.g. 0.00
    • debit_balancestring <decimal>
      e.g. 1210.00
    • credit_balancestring <decimal>
      e.g. 0.00
    • balancestring <decimal>
      e.g. 1210.00
  • totalsobject
    Properties
    • debitstring <decimal>
      e.g. 1512.50
    • creditstring <decimal>
      e.g. 1512.50
    • is_balancedboolean
    • resultstring <decimal>
      Result of the period.
      e.g. 750.00
Example
{
    "fiscal_year": "2026",
    "from": "2026-03-15",
    "to": "2026-03-15",
    "lines": [
        {
            "account_id": 223,
            "number": "400000",
            "label": "Clients",
            "type": "asset",
            "debit": "1210.00",
            "credit": "0.00",
            "debit_balance": "1210.00",
            "credit_balance": "0.00",
            "balance": "1210.00"
        }
    ],
    "totals": {
        "debit": "1512.50",
        "credit": "1512.50",
        "is_balanced": true,
        "result": "750.00"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/trial-balance" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/trial-balance', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/trial-balance", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/trial-balance",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/fiscal-years/{fiscalYear}/balance-by-periodBalance by period read

One column per period of the fiscal year.

Integration tokens need the read ability.

Operation id companies.reports.balance-by-period

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • fiscal_yearstring
    e.g. 2026
  • periodsobject[]
    Properties
    • idinteger
    • numberinteger
    • labelstring
      e.g. Janvier 2026
    • is_lockedboolean
  • accountsobject[]
    Properties
    • account_idinteger
      e.g. 223
    • numberstring
      e.g. 400000
    • labelstring
      e.g. Clients
    • typestring
      e.g. asset
    • periodsstring <decimal>[]
    • totalstring <decimal>
Example
{
    "fiscal_year": "2026",
    "periods": [
        {
            "id": 42,
            "number": 412,
            "label": "Janvier 2026",
            "is_locked": false
        }
    ],
    "accounts": [
        {
            "account_id": 223,
            "number": "400000",
            "label": "Clients",
            "type": "asset",
            "periods": [
                "1210.00"
            ],
            "total": "1210.00"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/balance-by-period" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/balance-by-period', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/balance-by-period", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/balance-by-period",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/fiscal-years/{fiscalYear}/financial-statementsBalance sheet and income statement read

Belgian legal scheme (BNB / NBB headings), in real time.

Integration tokens need the read ability.

Operation id companies.reports.financial-statements

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Query parameters

NameTypeDescription
tostring <date>Situation at this date.

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • fiscal_yearstring
    e.g. 2026
  • tostring <date>
  • schemestring
    e.g. BE
  • balance_sheetobject[]
    Properties
    • codestring
      e.g. 20/28
    • labelstring
      e.g. ACTIFS IMMOBILISÉS
    • sidestring
      asset liability
    • groupboolean
    • amountstring <decimal> | null
  • totalsobject
    Properties
    • assetsstring <decimal>
      e.g. 1262.50
    • liabilitiesstring <decimal>
      e.g. 1262.50
    • is_balancedboolean
  • income_statementobject[]
    Properties
    • codestring
      e.g. 70
    • labelstring
      e.g. Chiffre d'affaires
    • sidestring
      income expense
    • detailboolean
    • amountstring <decimal>
      e.g. 1000.00
  • resultstring <decimal>
    e.g. 750.00
Example
{
    "fiscal_year": "2026",
    "to": "2026-03-15",
    "scheme": "BE",
    "balance_sheet": [
        {
            "code": "20/28",
            "label": "ACTIFS IMMOBILISÉS",
            "side": "asset",
            "group": true,
            "amount": "1210.00"
        }
    ],
    "totals": {
        "assets": "1262.50",
        "liabilities": "1262.50",
        "is_balanced": true
    },
    "income_statement": [
        {
            "code": "70",
            "label": "Chiffre d'affaires",
            "side": "income",
            "detail": true,
            "amount": "1000.00"
        }
    ],
    "result": "750.00"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/financial-statements" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/financial-statements', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/financial-statements", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/financial-statements",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/fiscal-years/{fiscalYear}/general-ledger/{account}General ledger of an account read

Movements of one account with the running balance.

Integration tokens need the read ability.

Operation id companies.reports.general-ledger

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2
account requiredintegerId of the account (not its number).
e.g. 223

Query parameters

NameTypeDescription
fromstring <date>
tostring <date>

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • account_idinteger
    e.g. 223
  • fromstring <date>
  • tostring <date>
  • opening_balancestring <decimal>
    e.g. 0.00
  • movementsobject[]
    Properties
    • line_idinteger
    • entry_idinteger
    • entry_datestring <date>
    • journalstring
      e.g. VEN
    • documentstring
      e.g. 2026/000412
    • labelstring | null
    • referencestring | null
    • third_partystring | null
    • debitstring <decimal>
    • creditstring <decimal>
    • balancestring <decimal>
    • reconciliation_codestring | null
  • totalsobject
    Properties
    • debitstring <decimal>
    • creditstring <decimal>
    • balancestring <decimal>
Example
{
    "account_id": 223,
    "from": "2026-03-15",
    "to": "2026-03-15",
    "opening_balance": "0.00",
    "movements": [
        {
            "line_id": 3391,
            "entry_id": 1284,
            "entry_date": "2026-03-15",
            "journal": "VEN",
            "document": "2026/000412",
            "label": "Facture Brasserie Dubuisson",
            "reference": "F-2026-0412",
            "third_party": "string",
            "debit": "1210.00",
            "credit": "0.00",
            "balance": "1210.00",
            "reconciliation_code": "string"
        }
    ],
    "totals": {
        "debit": "1210.00",
        "credit": "0.00",
        "balance": "1210.00"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/general-ledger/223" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/general-ledger/223', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/general-ledger/223", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/general-ledger/223",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/fiscal-years/{fiscalYear}/consistencyConsistency of the fiscal year read

Gaps in the numbering, entries whose period does not match their date, entries outside the fiscal year.

Integration tokens need the read ability.

Operation id companies.reports.consistency

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • fiscal_yearstring
    e.g. 2026
  • missing_numbersobject[]
  • period_mismatchesobject[]
  • entries_outside_fiscal_yearinteger
    e.g. 0
  • is_consistentboolean
Example
{
    "fiscal_year": "2026",
    "missing_numbers": [
        {}
    ],
    "period_mismatches": [
        {}
    ],
    "entries_outside_fiscal_year": 0,
    "is_consistent": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/consistency" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/consistency', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/consistency", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/consistency",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/third-party-balance/{type}Customer or supplier balance read

Integration tokens need the read ability.

Operation id companies.reports.third-party-balance

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
type requiredstringSide of the balance.
customer supplier

Query parameters

NameTypeDescription
tostring <date>

Common headers: Accept-Language

Responses

200OK

application/json

Schema object[]

Array of

  • third_party_idinteger
  • codestring
    e.g. ACME
  • namestring
    e.g. ACME SA
  • debitstring <decimal>
  • creditstring <decimal>
  • outstandingstring <decimal>
    e.g. 1210.00
  • open_itemsinteger
    e.g. 1
Example
[
    {
        "third_party_id": 18,
        "code": "ACME",
        "name": "ACME SA",
        "debit": "1210.00",
        "credit": "0.00",
        "outstanding": "1210.00",
        "open_items": 1
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-party-balance/customer" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-party-balance/customer', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-party-balance/customer", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-party-balance/customer",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/aged-balance/{type}Aged balance read

Open amounts per third party, split by age: not due, 1-30, 31-60, 61-90 and more than 90 days.

Integration tokens need the read ability.

Operation id companies.reports.aged-balance

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
type requiredstringSide of the balance.
customer supplier

Query parameters

NameTypeDescription
tostring <date>Today by default.

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • typestring
    e.g. customer
  • tostring <date>
  • rowsobject[]
    Properties
    • third_party_idinteger
    • codestring
    • namestring
    • totalstring <decimal>
    • currentstring <decimal>
    • d30string <decimal>
    • d60string <decimal>
    • d90string <decimal>
    • d90plusstring <decimal>
  • totalsobject
    Properties
    • currentstring <decimal>
    • d30string <decimal>
    • d60string <decimal>
    • d90string <decimal>
    • d90plusstring <decimal>
    • totalstring <decimal>
Example
{
    "type": "customer",
    "to": "2026-03-15",
    "rows": [
        {
            "third_party_id": 18,
            "code": "COMPTOIR",
            "name": "Le Comptoir Montois SRL",
            "total": "1210.00",
            "current": "1210.00",
            "d30": "1210.00",
            "d60": "1210.00",
            "d90": "1210.00",
            "d90plus": "1210.00"
        }
    ],
    "totals": {
        "current": "1210.00",
        "d30": "1210.00",
        "d60": "1210.00",
        "d90": "1210.00",
        "d90plus": "1210.00",
        "total": "1210.00"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/aged-balance/customer" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/aged-balance/customer', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/aged-balance/customer", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/aged-balance/customer",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Analytics & budgets

Analytic codes, analytic report, budgets.

GET/v1/companies/{company}/analytic-codesAnalytic codes read

Integration tokens need the read ability.

Operation id companies.analytic-codes.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
axisstring
cost_center project

Common headers: Accept-Language

Responses

200OK

application/json

Schema AnalyticCode[]

Array of AnalyticCode

Example
[
    {
        "id": 2,
        "company_id": 7,
        "axis": "cost_center",
        "code": "SALLE",
        "label": "Salle",
        "is_active": true,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "deleted_by": 1
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/analytic-codesCreate an analytic code write

Integration tokens need the write ability.

Operation id companies.analytic-codes.store

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • axisstringrequired
    cost_center project
  • codestringrequired
    Unique per axis, 20 max.
  • labelstringrequired
  • is_activeboolean
Example
{
    "axis": "cost_center",
    "code": "SALLE",
    "label": "Salle"
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema AnalyticCode

Example
{
    "id": 2,
    "company_id": 7,
    "axis": "cost_center",
    "code": "SALLE",
    "label": "Salle",
    "is_active": true,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "axis": "cost_center",
    "code": "SALLE",
    "label": "Salle"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'axis' => 'cost_center',
        'code' => 'SALLE',
        'label' => 'Salle',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "axis": "cost_center",
      "code": "SALLE",
      "label": "Salle"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "axis": "cost_center",
        "code": "SALLE",
        "label": "Salle"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/analytic-codes/{analyticCode}Update an analytic code write

Integration tokens need the write ability.

Operation id companies.analytic-codes.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
analyticCode requiredintegerId of the analytic code.
e.g. 2

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • labelstring
  • is_activeboolean
Example
{
    "is_active": false
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema AnalyticCode

Example
{
    "id": 2,
    "company_id": 7,
    "axis": "cost_center",
    "code": "SALLE",
    "label": "Salle",
    "is_active": true,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes/2" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "is_active": false
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes/2', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'is_active' => false,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes/2", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "is_active": false
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes/2",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "is_active": False
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/fiscal-years/{fiscalYear}/analytic-reportAnalytic report read

Expenses, income and result per analytic code.

Integration tokens need the read ability.

Operation id companies.reports.analytic

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Query parameters

NameTypeDescription
axisstring
cost_center project
fromstring <date>
tostring <date>

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • axisstring
  • fiscal_yearstring
  • groupsobject[]
    Properties
    • codestring | null
      e.g. SALLE
    • labelstring | null
    • expensesstring <decimal>
    • incomestring <decimal>
    • resultstring <decimal>
    • accountsobject[]
      Properties
      • account_idinteger
        e.g. 223
      • numberstring
        e.g. 400000
      • labelstring
        e.g. Clients
      • typestring
        e.g. asset
      • amountstring <decimal>
Example
{
    "axis": "string",
    "fiscal_year": "string",
    "groups": [
        {
            "code": "SALLE",
            "label": "Facture Brasserie Dubuisson",
            "expenses": "1210.00",
            "income": "1210.00",
            "result": "1210.00",
            "accounts": [
                {
                    "account_id": 223,
                    "number": "400000",
                    "label": "Clients",
                    "type": "asset",
                    "amount": "1210.00"
                }
            ]
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/analytic-report" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/analytic-report', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/analytic-report", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/analytic-report",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/fiscal-years/{fiscalYear}/budgetsBudget cells read

Integration tokens need the read ability.

Operation id companies.budgets.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Query parameters

NameTypeDescription
scenariostringdefault when absent.

Common headers: Accept-Language

Responses

200OK

application/json

Schema Budget[]

Array of Budget

Example
[
    {
        "id": 42,
        "company_id": 7,
        "fiscal_year_id": 2,
        "scenario": "default",
        "account_id": 580,
        "cost_center_id": 42,
        "period_number": 3,
        "amount": "1500.00",
        "account": {
            "id": 580,
            "number": "702000",
            "label": "Prestations de services"
        }
    }
]
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/budgets" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/budgets', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/budgets", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/budgets",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PUT/v1/companies/{company}/fiscal-years/{fiscalYear}/budgetsSave budget cells write

Batch of cells (account × period, optionally × cost centre). An amount of 0 deletes the cell; spread_yearly spreads a yearly amount over twelve months.

Integration tokens need the write ability.

Operation id companies.budgets.save

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • scenariostring
  • cellsobject[]required
    Properties
    • account_idintegerrequired
    • cost_center_idinteger | null
    • period_numberintegerrequired
      1 to 12.
    • amountstringrequired
      Decimal.
  • spread_yearlyboolean
Example
{
    "cells": [
        {
            "account_id": 378,
            "period_number": 1,
            "amount": "18000.00"
        }
    ],
    "spread_yearly": true
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
  • savedinteger
    e.g. 1
Example
{
    "saved": 1
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PUT "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/budgets" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "cells": [
        {
            "account_id": 378,
            "period_number": 1,
            "amount": "18000.00"
        }
    ],
    "spread_yearly": true
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PUT', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/budgets', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'cells' => [
            [
                'account_id' => 378,
                'period_number' => 1,
                'amount' => '18000.00',
            ],
        ],
        'spread_yearly' => true,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/budgets", {
  method: "PUT",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "cells": [
          {
              "account_id": 378,
              "period_number": 1,
              "amount": "18000.00"
          }
      ],
      "spread_yearly": true
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.put(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/budgets",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "cells": [
            {
                "account_id": 378,
                "period_number": 1,
                "amount": "18000.00"
            }
        ],
        "spread_yearly": True
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/fiscal-years/{fiscalYear}/budget-reportBudget against actuals read

Integration tokens need the read ability.

Operation id companies.reports.budget

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Query parameters

NameTypeDescription
scenariostring
cost_center_idinteger
upto_periodinteger1 to 12.

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • scenariostring
  • fiscal_yearstring
  • upto_periodinteger
  • linesobject[]
    Properties
    • account_idinteger
      e.g. 223
    • numberstring
      e.g. 400000
    • labelstring
      e.g. Clients
    • typestring
      e.g. asset
    • budgetobject
      Period number => amount.
    • actualobject
      Period number => amount.
    • budget_ytdstring <decimal>
    • actual_ytdstring <decimal>
    • variancestring <decimal>
    • variance_pctnumber | null
    • budget_yearstring <decimal>
  • totalsobject
    Properties
    • expenses_minus_income_budgetstring <decimal>
    • expenses_minus_income_actualstring <decimal>
Example
{
    "scenario": "string",
    "fiscal_year": "string",
    "upto_period": 1,
    "lines": [
        {
            "account_id": 223,
            "number": "400000",
            "label": "Clients",
            "type": "asset",
            "budget": {},
            "actual": {},
            "budget_ytd": "1210.00",
            "actual_ytd": "1210.00",
            "variance": "1210.00",
            "variance_pct": 12.5,
            "budget_year": "1210.00"
        }
    ],
    "totals": {
        "expenses_minus_income_budget": "1210.00",
        "expenses_minus_income_actual": "1210.00"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/budget-report" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/budget-report', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/budget-report", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fiscal-years/2/budget-report",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Exports

Legal books, statements and data as PDF, XLSX or CSV; full dossier as ZIP.

GET/v1/companies/{company}/exportsCatalogue of exports read

Every export with its group, formats and parameters. types keeps the historical list of CSV codes.

Integration tokens need the read ability.

Operation id companies.exports.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
langstring
fr nl en de

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • typesstring[]
  • formatsstring[]
    pdf xlsx csv
  • default_formatstring
    e.g. csv
  • full_dossierstring
    e.g. zip
  • groupsobject[]
    Properties
    • codestring
      books statements vat third_parties assets data
    • labelstring
      e.g. Livres comptables
  • common_paramsstring[]
  • catalogobject[]
    Properties
    • codestring
      e.g. general-ledger
    • labelstring
      e.g. Grand livre
    • descriptionstring
    • groupstring
      e.g. books
    • group_labelstring
    • formatsstring[]
    • datedboolean
    • requires_fiscal_yearboolean
    • paramsobject[]
Example
{
    "types": [
        "string"
    ],
    "formats": [
        "pdf"
    ],
    "default_format": "csv",
    "full_dossier": "zip",
    "groups": [
        {
            "code": "books",
            "label": "Livres comptables"
        }
    ],
    "common_params": [
        "string"
    ],
    "catalog": [
        {
            "code": "general-ledger",
            "label": "Grand livre",
            "description": "Description",
            "group": "books",
            "group_label": "string",
            "formats": [
                "string"
            ],
            "dated": true,
            "requires_fiscal_year": true,
            "params": [
                {}
            ]
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/exports/full-dossier/{fiscalYear}Full dossier (ZIP) read 10 / 1 min

Every book, statement, VAT document, third party listing, fixed asset table and the source documents of the fiscal year, in numbered folders with a manifest of SHA-256 fingerprints.

Integration tokens need the read ability.

Rate limit: 10 requests per minute (429 beyond, see Retry-After).

Operation id companies.exports.full-dossier

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
fiscalYear requiredintegerId of the fiscal year.
e.g. 2

Query parameters

NameTypeDescription
langstring
fr nl en de

Common headers: Accept-Language

Responses

200ZIP archive.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/full-dossier/2" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/full-dossier/2', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/full-dossier/2", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/full-dossier/2",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/exports/{type}/preview-urlSigned preview URL of an export read 60 / 1 min

URL valid 15 minutes that serves the PDF inline (preview pane).

Integration tokens need the read ability.

Rate limit: 60 requests per minute (429 beyond, see Retry-After).

Operation id companies.exports.preview-url

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
type requiredstringExport code from the catalogue of GET exports (journals, general-ledger, trial-balance, vat-declaration, …).
e.g. trial-balance

Query parameters

NameTypeDescription
fiscal_year_idintegerThe current fiscal year when absent.
fromstring <date>
tostring <date>
langstring
fr nl en de
account_fromstringgeneral-ledger.
account_tostringgeneral-ledger.
schemestringannual-accounts.
abbreviated micro
general_meeting_datestring <date>annual-accounts.
declaration_idintegervat-declaration.
yearintegerintracom-listing.
periodintegerintracom-listing.
third_party_idintegerthird-party-ledger.
party_typestringthird-party-ledger.
customer supplier

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • urlstring <uri>
  • expires_ininteger
    Seconds.
    e.g. 900
  • formatstring
    e.g. pdf
Example
{
    "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "expires_in": 900,
    "format": "pdf"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/trial-balance/preview-url" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/trial-balance/preview-url', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/trial-balance/preview-url", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/trial-balance/preview-url",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/exports/{type}Download an export read 30 / 1 min

Codes: journals, purchases, sales, financial, miscellaneous, general-ledger, trial-balance, balance-by-period, financial-statements, annual-accounts, vat-summary, vat-declaration, customer-listing, intracom-listing, third-parties, customer-balance, supplier-balance, aged-customers, aged-suppliers, third-party-ledger, fixed-assets, accounts, documents, audit-trail. Generation is synchronous. PDFs of a period that is not locked carry a « provisional » mention.

Integration tokens need the read ability.

Rate limit: 30 requests per minute (429 beyond, see Retry-After).

Operation id companies.exports.download

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
type requiredstringExport code from the catalogue of GET exports (journals, general-ledger, trial-balance, vat-declaration, …).
e.g. trial-balance

Query parameters

NameTypeDescription
formatstringCSV by default.
pdf xlsx csv
fiscal_year_idintegerThe current fiscal year when absent.
fromstring <date>
tostring <date>
langstring
fr nl en de
account_fromstringgeneral-ledger.
account_tostringgeneral-ledger.
schemestringannual-accounts.
abbreviated micro
general_meeting_datestring <date>annual-accounts.
declaration_idintegervat-declaration.
yearintegerintracom-listing.
periodintegerintracom-listing.
third_party_idintegerthird-party-ledger.
party_typestringthird-party-ledger.
customer supplier

Common headers: Accept-Language

Responses

200The file.

Response headers Content-Disposition X-Export-Fingerprint X-RateLimit-Limit X-RateLimit-Remaining

application/pdf

application/vnd.openxmlformats-officedocument.spreadsheetml.sheet

text/csv

401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/trial-balance" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/trial-balance', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/trial-balance", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/trial-balance",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/exports/{type}/viewInline PDF of an export (signed) Signed URL 30 / 1 min

Target of the URL returned by preview-url.

Authorised by the signature of the URL (query parameters signature and expires), not by a bearer token. The URL is issued by another endpoint and expires.

Rate limit: 30 requests per minute (429 beyond, see Retry-After).

Operation id exports.view

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
type requiredstringExport code from the catalogue of GET exports (journals, general-ledger, trial-balance, vat-declaration, …).
e.g. trial-balance

Common headers: signature expires

Responses

200The PDF, inline.
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/trial-balance/view" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/trial-balance/view', [
    'headers' => [
        'Accept' => 'application/json',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/trial-balance/view", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/exports/trial-balance/view",
    headers={
        "Accept": "application/json",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Peppol

Registration of a company file on Peppol, transport options, network lookups.

GET/v1/companies/{company}/peppolPeppol state of the file read

Registration, transport options, SMP publication, supported documents and what blocks a registration.

Integration tokens need the read ability.

Operation id companies.peppol.show

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema PeppolState

Example
{
    "identity": {},
    "participant_id": "0208:0477472701",
    "status": "none",
    "account": {
        "id": "string",
        "name": "Le Comptoir Montois SRL",
        "archived": true
    },
    "transport": {},
    "smp": {
        "published": true,
        "checked_at": "2026-03-15T09:41:00+00:00"
    },
    "access_point": {
        "smp_host": "smp.b2brouter.net",
        "provider_name": "B2Brouter",
        "endpoint_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "technical_contact": "string"
    },
    "supported_documents": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "can_register": true,
    "blockers": [
        "string"
    ],
    "blocker_codes": [
        "string"
    ],
    "managed_by_novadesko": true,
    "registered_elsewhere": true,
    "external_provider": "string",
    "provider_configured": true,
    "environment": "production",
    "contact": {},
    "last_error": "string"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/peppolUnregister the file from Peppol write Not in demo

Archives the account at the access point and records the reason.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Operation id companies.peppol.destroy

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • reason_typestringrequired
    expensive accountant other
  • custom_reasonstring | null
    Required when the reason is other.
Example
{
    "reason_type": "accountant"
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-Trashed

application/json

Schema PeppolState

Example
{
    "identity": {},
    "participant_id": "0208:0477472701",
    "status": "none",
    "account": {
        "id": "string",
        "name": "Le Comptoir Montois SRL",
        "archived": true
    },
    "transport": {},
    "smp": {
        "published": true,
        "checked_at": "2026-03-15T09:41:00+00:00"
    },
    "access_point": {
        "smp_host": "smp.b2brouter.net",
        "provider_name": "B2Brouter",
        "endpoint_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "technical_contact": "string"
    },
    "supported_documents": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "can_register": true,
    "blockers": [
        "string"
    ],
    "blocker_codes": [
        "string"
    ],
    "managed_by_novadesko": true,
    "registered_elsewhere": true,
    "external_provider": "string",
    "provider_configured": true,
    "environment": "production",
    "contact": {},
    "last_error": "string"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Refused: missing data on the file, provider error or not registered. blocker_codes lists the machine reasons and state carries the current Peppol state.

application/json

Schema Error & object

Includes Error

Example
{
    "message": "Le numéro de TVA du dossier est requis pour l'inscription Peppol.",
    "errors": {
        "peppol": [
            "Le numéro de TVA du dossier est requis pour l'inscription Peppol."
        ]
    },
    "blockers": [
        "Numéro de TVA manquant"
    ],
    "blocker_codes": [
        "missing_vat_number"
    ]
}

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "reason_type": "accountant"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'reason_type' => 'accountant',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "reason_type": "accountant"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "reason_type": "accountant"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/peppol/registerRegister the file on Peppol write Not in demo 6 / 1 min

Creates the account at the access point (B2Brouter) and publishes the participant 0208:<enterprise number>. 201 for a new registration, 200 when it was already active. Emits the webhook peppol.status_changed.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 6 requests per minute (429 beyond, see Retry-After).

Operation id companies.peppol.register

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • emailstring <email> | null
    Contact of the registration.
  • phonestring | null
  • addressstring | null
  • postal_codestring | null
  • citystring | null
  • provincestring | null
  • optionsobject
    Properties
    • round_before_sumboolean | null
    • apply_taxes_per_lineboolean | null
    • registered_for_empl_taxboolean | null
Example
{
    "email": "gerant@comptoir-montois.example",
    "address": "Grand-Place 14",
    "postal_code": "7000",
    "city": "Mons"
}

Responses

200Already registered

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema PeppolState

Example
{
    "identity": {},
    "participant_id": "0208:0477472701",
    "status": "none",
    "account": {
        "id": "string",
        "name": "Le Comptoir Montois SRL",
        "archived": true
    },
    "transport": {},
    "smp": {
        "published": true,
        "checked_at": "2026-03-15T09:41:00+00:00"
    },
    "access_point": {
        "smp_host": "smp.b2brouter.net",
        "provider_name": "B2Brouter",
        "endpoint_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "technical_contact": "string"
    },
    "supported_documents": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "can_register": true,
    "blockers": [
        "string"
    ],
    "blocker_codes": [
        "string"
    ],
    "managed_by_novadesko": true,
    "registered_elsewhere": true,
    "external_provider": "string",
    "provider_configured": true,
    "environment": "production",
    "contact": {},
    "last_error": "string"
}
201Registered

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema PeppolState

Example
{
    "identity": {},
    "participant_id": "0208:0477472701",
    "status": "none",
    "account": {
        "id": "string",
        "name": "Le Comptoir Montois SRL",
        "archived": true
    },
    "transport": {},
    "smp": {
        "published": true,
        "checked_at": "2026-03-15T09:41:00+00:00"
    },
    "access_point": {
        "smp_host": "smp.b2brouter.net",
        "provider_name": "B2Brouter",
        "endpoint_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "technical_contact": "string"
    },
    "supported_documents": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "can_register": true,
    "blockers": [
        "string"
    ],
    "blocker_codes": [
        "string"
    ],
    "managed_by_novadesko": true,
    "registered_elsewhere": true,
    "external_provider": "string",
    "provider_configured": true,
    "environment": "production",
    "contact": {},
    "last_error": "string"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Refused: missing data on the file, provider error or not registered. blocker_codes lists the machine reasons and state carries the current Peppol state.

application/json

Schema Error & object

Includes Error

Example
{
    "message": "Le numéro de TVA du dossier est requis pour l'inscription Peppol.",
    "errors": {
        "peppol": [
            "Le numéro de TVA du dossier est requis pour l'inscription Peppol."
        ]
    },
    "blockers": [
        "Numéro de TVA manquant"
    ],
    "blocker_codes": [
        "missing_vat_number"
    ]
}
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/register" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "email": "gerant@comptoir-montois.example",
    "address": "Grand-Place 14",
    "postal_code": "7000",
    "city": "Mons"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/register', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'email' => 'gerant@comptoir-montois.example',
        'address' => 'Grand-Place 14',
        'postal_code' => '7000',
        'city' => 'Mons',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/register", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "email": "gerant@comptoir-montois.example",
      "address": "Grand-Place 14",
      "postal_code": "7000",
      "city": "Mons"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/register",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "email": "gerant@comptoir-montois.example",
        "address": "Grand-Place 14",
        "postal_code": "7000",
        "city": "Mons"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/peppol/refreshRefresh the Peppol state write Not in demo 12 / 1 min

Reads the account at the access point and the network (SML / SMP) again.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 12 requests per minute (429 beyond, see Retry-After).

Operation id companies.peppol.refresh

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema PeppolState

Example
{
    "identity": {},
    "participant_id": "0208:0477472701",
    "status": "none",
    "account": {
        "id": "string",
        "name": "Le Comptoir Montois SRL",
        "archived": true
    },
    "transport": {},
    "smp": {
        "published": true,
        "checked_at": "2026-03-15T09:41:00+00:00"
    },
    "access_point": {
        "smp_host": "smp.b2brouter.net",
        "provider_name": "B2Brouter",
        "endpoint_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "technical_contact": "string"
    },
    "supported_documents": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "can_register": true,
    "blockers": [
        "string"
    ],
    "blocker_codes": [
        "string"
    ],
    "managed_by_novadesko": true,
    "registered_elsewhere": true,
    "external_provider": "string",
    "provider_configured": true,
    "environment": "production",
    "contact": {},
    "last_error": "string"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Refused: missing data on the file, provider error or not registered. blocker_codes lists the machine reasons and state carries the current Peppol state.

application/json

Schema Error & object

Includes Error

Example
{
    "message": "Le numéro de TVA du dossier est requis pour l'inscription Peppol.",
    "errors": {
        "peppol": [
            "Le numéro de TVA du dossier est requis pour l'inscription Peppol."
        ]
    },
    "blockers": [
        "Numéro de TVA manquant"
    ],
    "blocker_codes": [
        "missing_vat_number"
    ]
}
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/refresh" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/refresh', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/refresh", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/refresh",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/peppol/transportUpdate the transport options write Not in demo

Reception and the document families received through Peppol.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Operation id companies.peppol.transport

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • enabledboolean | null
  • receptionboolean | null
  • standard_documentsboolean | null
  • invoiceboolean | null
  • credit_noteboolean | null
  • self_billingboolean | null
  • orderboolean | null
  • application_responseboolean | null
Example
{
    "reception": true,
    "credit_note": true
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema PeppolState

Example
{
    "identity": {},
    "participant_id": "0208:0477472701",
    "status": "none",
    "account": {
        "id": "string",
        "name": "Le Comptoir Montois SRL",
        "archived": true
    },
    "transport": {},
    "smp": {
        "published": true,
        "checked_at": "2026-03-15T09:41:00+00:00"
    },
    "access_point": {
        "smp_host": "smp.b2brouter.net",
        "provider_name": "B2Brouter",
        "endpoint_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "technical_contact": "string"
    },
    "supported_documents": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "can_register": true,
    "blockers": [
        "string"
    ],
    "blocker_codes": [
        "string"
    ],
    "managed_by_novadesko": true,
    "registered_elsewhere": true,
    "external_provider": "string",
    "provider_configured": true,
    "environment": "production",
    "contact": {},
    "last_error": "string"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Refused: missing data on the file, provider error or not registered. blocker_codes lists the machine reasons and state carries the current Peppol state.

application/json

Schema Error & object

Includes Error

Example
{
    "message": "Le numéro de TVA du dossier est requis pour l'inscription Peppol.",
    "errors": {
        "peppol": [
            "Le numéro de TVA du dossier est requis pour l'inscription Peppol."
        ]
    },
    "blockers": [
        "Numéro de TVA manquant"
    ],
    "blocker_codes": [
        "missing_vat_number"
    ]
}

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/transport" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "reception": true,
    "credit_note": true
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/transport', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'reception' => true,
        'credit_note' => true,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/transport", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "reception": true,
      "credit_note": true
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/transport",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "reception": True,
        "credit_note": True
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/peppol/lookupLook a participant up on the Peppol network read Not in demo 30 / 1 min

By identifier (0208:0402531376) or by VAT / enterprise number and country. Reads the SML and the SMP of the participant.

Integration tokens need the read ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 30 requests per minute (429 beyond, see Retry-After).

Operation id companies.peppol.lookup

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
identifierstring
e.g. 0208:0402531376
vatstring
e.g. BE0402531376
countrystring
e.g. BE
enterprise_numberstring

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema PeppolThirdPartyStatus

Example
{
    "identifier": "0208:0402531376",
    "registered": true,
    "access_point": {
        "smp_host": "smp.b2brouter.net",
        "provider_name": "B2Brouter",
        "endpoint_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "technical_contact": "string"
    },
    "document_types": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "checked_at": "2026-03-15T09:41:00+00:00",
    "stale": true,
    "error": "string",
    "source": "sml+smp"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/lookup" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/lookup', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/lookup", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/lookup",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/peppol/document-typesSupported Peppol document types read

Integration tokens need the read ability.

Operation id companies.peppol.document-types

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • document_typesPeppolDocumentType[]
  • familiesstring[]
  • identifier_schemesobject
    Country => ISO 6523 scheme (BE: 0208).
Example
{
    "document_types": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "families": [
        "string"
    ],
    "identifier_schemes": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/document-types" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/document-types', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/document-types", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/document-types",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/peppol/logsCalls to the access point read

Last calls made for the file, for support.

Integration tokens need the read ability.

Operation id companies.peppol.logs

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
limitinteger1 to 200, 50 by default.

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • logsobject[]
Example
{
    "logs": [
        {}
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/logs" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/logs', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/logs", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/peppol/logs",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/third-parties/peppol/check-allCheck the Peppol status of every third party write Not in demo 6 / 1 min

Up to 100 third parties per call.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 6 requests per minute (429 beyond, see Retry-After).

Operation id companies.third-parties.peppol.check-all

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • only_staleboolean | null
    Only the statuses older than 7 days.
Example
{
    "only_stale": true
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • checkedinteger
    e.g. 42
  • registeredinteger
    e.g. 17
  • errorsinteger
    e.g. 0
  • skippedinteger
    Third parties without a usable identifier.
    e.g. 1
Example
{
    "checked": 42,
    "registered": 17,
    "errors": 0,
    "skipped": 1
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/peppol/check-all" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "only_stale": true
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/peppol/check-all', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'only_stale' => true,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/peppol/check-all", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "only_stale": true
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/peppol/check-all",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "only_stale": True
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/third-parties/{thirdParty}/peppolPeppol status of a third party read 60 / 1 min

Cached 7 days; refresh=1 asks the network again.

Integration tokens need the read ability.

Rate limit: 60 requests per minute (429 beyond, see Retry-After).

Operation id companies.third-parties.peppol

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
thirdParty requiredintegerId of the third party.
e.g. 18

Query parameters

NameTypeDescription
refreshboolean

Common headers: Accept-Language

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema PeppolThirdPartyStatus

Example
{
    "identifier": "0208:0402531376",
    "registered": true,
    "access_point": {
        "smp_host": "smp.b2brouter.net",
        "provider_name": "B2Brouter",
        "endpoint_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "technical_contact": "string"
    },
    "document_types": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "checked_at": "2026-03-15T09:41:00+00:00",
    "stale": true,
    "error": "string",
    "source": "sml+smp"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/peppol" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/peppol', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/peppol", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/18/peppol",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Integrations

Catalogue of integrations, Novadesko synchronisation, file relays.

GET/v1/companies/{company}/integrationsCatalogue of integrations read

Every integration with its status, its configuration schema and the connection of the file.

Integration tokens need the read ability.

Operation id companies.integrations.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
langstring
fr nl en de

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
Example
{
    "integrations": [
        {
            "slug": "novadesko",
            "name": "Novadesko",
            "category": "accounting",
            "description": "Description",
            "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "status": "available",
            "capabilities": [
                "import_documents"
            ],
            "config_schema": [
                {
                    "key": "string",
                    "label": "Facture Brasserie Dubuisson",
                    "type": "text",
                    "required": true
                }
            ],
            "open_tab": "string",
            "has_driver": true,
            "is_enabled": true,
            "connection": {
                "is_active": true,
                "status": "connected",
                "config_masked": {},
                "last_sync_at": "2026-03-15T09:41:00+00:00",
                "last_error": "string"
            },
            "interested": true,
            "actions": [
                "string"
            ]
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/integrations/{integration}/activateActivate an integration write Not in demo

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Error codes (code):

  • integration_error: generic driver error
  • not_available: integration not available yet
  • not_connected: the integration is not active on the file
  • integration_inactive: the integration is switched off
  • no_driver: nothing to run for this integration
  • not_linked: the file is not linked to the external system
  • use_open_tab: managed from its own tab (Peppol)
  • file_required: a file is expected
  • file_too_large: file above the size limit
  • sync_failed: the run failed
  • novadesko_locked: locked on the Novadesko side

Operation id companies.integrations.activate

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
integration requiredstringSlug of the integration (novadesko, peppol, file_import, …).
e.g. novadesko

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • configobject | null
    Values of the configuration schema.
Example
{
    "config": []
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema Integration

Example
{
    "slug": "novadesko",
    "name": "Novadesko",
    "category": "accounting",
    "description": "Description",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "status": "available",
    "capabilities": [
        "import_documents"
    ],
    "config_schema": [
        {
            "key": "string",
            "label": "Facture Brasserie Dubuisson",
            "type": "text",
            "required": true
        }
    ],
    "open_tab": "string",
    "has_driver": true,
    "is_enabled": true,
    "connection": {
        "is_active": true,
        "status": "connected",
        "config_masked": {},
        "last_sync_at": "2026-03-15T09:41:00+00:00",
        "last_error": "string"
    },
    "interested": true,
    "actions": [
        "string"
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/activate" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "config": []
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/activate', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'config' => [],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/activate", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "config": []
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/activate",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "config": []
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/integrations/{integration}/deactivateDeactivate an integration write Not in demo

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Error codes (code):

  • integration_error: generic driver error
  • not_available: integration not available yet
  • not_connected: the integration is not active on the file
  • integration_inactive: the integration is switched off
  • no_driver: nothing to run for this integration
  • not_linked: the file is not linked to the external system
  • use_open_tab: managed from its own tab (Peppol)
  • file_required: a file is expected
  • file_too_large: file above the size limit
  • sync_failed: the run failed
  • novadesko_locked: locked on the Novadesko side

Operation id companies.integrations.deactivate

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
integration requiredstringSlug of the integration (novadesko, peppol, file_import, …).
e.g. novadesko

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema Integration

Example
{
    "slug": "novadesko",
    "name": "Novadesko",
    "category": "accounting",
    "description": "Description",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "status": "available",
    "capabilities": [
        "import_documents"
    ],
    "config_schema": [
        {
            "key": "string",
            "label": "Facture Brasserie Dubuisson",
            "type": "text",
            "required": true
        }
    ],
    "open_tab": "string",
    "has_driver": true,
    "is_enabled": true,
    "connection": {
        "is_active": true,
        "status": "connected",
        "config_masked": {},
        "last_sync_at": "2026-03-15T09:41:00+00:00",
        "last_error": "string"
    },
    "interested": true,
    "actions": [
        "string"
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/deactivate" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/deactivate', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/deactivate", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/deactivate",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/integrations/{integration}/configUpdate the configuration write Not in demo

Secrets are stored encrypted and returned masked.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Error codes (code):

  • integration_error: generic driver error
  • not_available: integration not available yet
  • not_connected: the integration is not active on the file
  • integration_inactive: the integration is switched off
  • no_driver: nothing to run for this integration
  • not_linked: the file is not linked to the external system
  • use_open_tab: managed from its own tab (Peppol)
  • file_required: a file is expected
  • file_too_large: file above the size limit
  • sync_failed: the run failed
  • novadesko_locked: locked on the Novadesko side

Operation id companies.integrations.config

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
integration requiredstringSlug of the integration (novadesko, peppol, file_import, …).
e.g. novadesko

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • configobjectrequired
Example
{
    "config": {}
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema Integration

Example
{
    "slug": "novadesko",
    "name": "Novadesko",
    "category": "accounting",
    "description": "Description",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "status": "available",
    "capabilities": [
        "import_documents"
    ],
    "config_schema": [
        {
            "key": "string",
            "label": "Facture Brasserie Dubuisson",
            "type": "text",
            "required": true
        }
    ],
    "open_tab": "string",
    "has_driver": true,
    "is_enabled": true,
    "connection": {
        "is_active": true,
        "status": "connected",
        "config_masked": {},
        "last_sync_at": "2026-03-15T09:41:00+00:00",
        "last_error": "string"
    },
    "interested": true,
    "actions": [
        "string"
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/config" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "config": {}
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/config', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'config' => [],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/config", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "config": {}
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/config",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "config": {}
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/integrations/{integration}/testTest the connection write Not in demo 12 / 1 min

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 12 requests per minute (429 beyond, see Retry-After).

Error codes (code):

  • integration_error: generic driver error
  • not_available: integration not available yet
  • not_connected: the integration is not active on the file
  • integration_inactive: the integration is switched off
  • no_driver: nothing to run for this integration
  • not_linked: the file is not linked to the external system
  • use_open_tab: managed from its own tab (Peppol)
  • file_required: a file is expected
  • file_too_large: file above the size limit
  • sync_failed: the run failed
  • novadesko_locked: locked on the Novadesko side

Operation id companies.integrations.test

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
integration requiredstringSlug of the integration (novadesko, peppol, file_import, …).
e.g. novadesko

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
Example
{
    "ok": true,
    "message": "OK",
    "integration": {
        "slug": "novadesko",
        "name": "Novadesko",
        "category": "accounting",
        "description": "Description",
        "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "status": "available",
        "capabilities": [
            "import_documents"
        ],
        "config_schema": [
            {
                "key": "string",
                "label": "Facture Brasserie Dubuisson",
                "type": "text",
                "required": true
            }
        ],
        "open_tab": "string",
        "has_driver": true,
        "is_enabled": true,
        "connection": {
            "is_active": true,
            "status": "connected",
            "config_masked": {},
            "last_sync_at": "2026-03-15T09:41:00+00:00",
            "last_error": "string"
        },
        "interested": true,
        "actions": [
            "string"
        ]
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/test" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/test', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/test", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/test",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/integrations/{integration}/syncRun a synchronisation write Not in demo 12 / 1 min

Runs the driver synchronously. JSON options (full) or, for file_import, a multipart upload (file: CODA, CSV…). On failure the answer is 422 with the last run.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 12 requests per minute (429 beyond, see Retry-After).

Error codes (code):

  • integration_error: generic driver error
  • not_available: integration not available yet
  • not_connected: the integration is not active on the file
  • integration_inactive: the integration is switched off
  • no_driver: nothing to run for this integration
  • not_linked: the file is not linked to the external system
  • use_open_tab: managed from its own tab (Peppol)
  • file_required: a file is expected
  • file_too_large: file above the size limit
  • sync_failed: the run failed
  • novadesko_locked: locked on the Novadesko side

Operation id companies.integrations.sync

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
integration requiredstringSlug of the integration (novadesko, peppol, file_import, …).
e.g. novadesko

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • fullboolean
    Full resynchronisation instead of incremental.
Example
{
    "full": false
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
Example
{
    "run": {
        "id": 77,
        "status": "running",
        "started_at": "2026-03-15T09:41:00+00:00",
        "finished_at": "2026-03-15T09:41:00+00:00",
        "duration_ms": 1840,
        "summary": {},
        "message": "OK"
    },
    "result": {},
    "integration": {
        "slug": "novadesko",
        "name": "Novadesko",
        "category": "accounting",
        "description": "Description",
        "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "status": "available",
        "capabilities": [
            "import_documents"
        ],
        "config_schema": [
            {
                "key": "string",
                "label": "Facture Brasserie Dubuisson",
                "type": "text",
                "required": true
            }
        ],
        "open_tab": "string",
        "has_driver": true,
        "is_enabled": true,
        "connection": {
            "is_active": true,
            "status": "connected",
            "config_masked": {},
            "last_sync_at": "2026-03-15T09:41:00+00:00",
            "last_error": "string"
        },
        "interested": true,
        "actions": [
            "string"
        ]
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/sync" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "full": false
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/sync', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'full' => false,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/sync", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "full": false
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/sync",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "full": False
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/integrations/{integration}/runsSynchronisation runs read

Integration tokens need the read ability.

Operation id companies.integrations.runs

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
integration requiredstringSlug of the integration (novadesko, peppol, file_import, …).
e.g. novadesko

Query parameters

NameTypeDescription
limitinteger1 to 100, 20 by default.

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
Example
{
    "runs": [
        {
            "id": 77,
            "status": "running",
            "started_at": "2026-03-15T09:41:00+00:00",
            "finished_at": "2026-03-15T09:41:00+00:00",
            "duration_ms": 1840,
            "summary": {},
            "message": "OK"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/runs" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/runs', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/runs", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/runs",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/integrations/{integration}/interestRegister an interest write Not in demo

For an integration that is not available yet (coming_soon).

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Operation id companies.integrations.interest

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
integration requiredstringSlug of the integration (novadesko, peppol, file_import, …).
e.g. novadesko

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
  • registeredboolean
  • registered_atstring <date-time>
  • slugstring
    e.g. codabox
Example
{
    "registered": true,
    "registered_at": "2026-03-15T09:41:00+00:00",
    "slug": "codabox"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/interest" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/interest', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/interest", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/integrations/novadesko/interest",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/sync/novadeskoSynchronise the file from Novadesko write Not in demo 10 / 1 min

Reads documents, bank statements (CODA) and fixed assets of the linked shop. Read-only on the Novadesko side. 422 when the file is not linked or the integration is inactive.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 10 requests per minute (429 beyond, see Retry-After).

Operation id companies.sync.novadesko

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • fullboolean
    Reload everything instead of the changes since the last run.
Example
{
    "full": false
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • documentsinteger
    Documents created or updated.
    e.g. 12
  • bank_transactionsinteger
    e.g. 34
  • coda_filesinteger
    e.g. 2
  • fixed_assetsinteger
    e.g. 0
  • errorstring | null
  • synced_atstring <date-time>
Example
{
    "documents": 12,
    "bank_transactions": 34,
    "coda_files": 2,
    "fixed_assets": 0,
    "error": "string",
    "synced_at": "2026-03-15T09:41:00+00:00"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/novadesko" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "full": false
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/novadesko', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'full' => false,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/novadesko", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "full": false
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/novadesko",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "full": False
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/files/preview-urlSigned URL of a Novadesko file read

Novadesko files cannot be framed directly; this returns a signed relay URL valid 20 minutes. Only whitelisted hosts and paths are relayed.

Integration tokens need the read ability.

Operation id companies.files.preview-url

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
url requiredstring <uri>File on web.novadesko.com.

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • urlstring <uri>
  • expires_ininteger
    e.g. 1200
Example
{
    "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "expires_in": 1200
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/files/preview-url?url=https%3A%2F%2Fapi.novafisko.com%2Fv1%2Fcompanies%2FXBVD5O1L29HC" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/files/preview-url', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'query' => [
        'url' => 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/files/preview-url?url=https%3A%2F%2Fapi.novafisko.com%2Fv1%2Fcompanies%2FXBVD5O1L29HC", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/files/preview-url",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    params={
        "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/files/viewSigned relay of a Novadesko file Signed URL 120 / 1 min

Target of files/preview-url: serves the PDF or image inline with frame-ancestors allowing the app.

Authorised by the signature of the URL (query parameters signature and expires), not by a bearer token. The URL is issued by another endpoint and expires.

Rate limit: 120 requests per minute (429 beyond, see Retry-After).

Operation id files.view

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
url requiredstring <uri>

Common headers: signature expires

Responses

200The file, inline.

Response headers Content-Disposition X-RateLimit-Limit X-RateLimit-Remaining

application/pdf

image/png

image/jpeg

403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/files/view?url=https%3A%2F%2Fapi.novafisko.com%2Fv1%2Fcompanies%2FXBVD5O1L29HC" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/files/view', [
    'headers' => [
        'Accept' => 'application/json',
    ],
    'query' => [
        'url' => 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/files/view?url=https%3A%2F%2Fapi.novafisko.com%2Fv1%2Fcompanies%2FXBVD5O1L29HC", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/files/view",
    headers={
        "Accept": "application/json",
    },
    params={
        "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

History & recycle bin

Version history, revert, recycle bin, activity feed.

GET/v1/companies/{company}/historyVersion history read

Who changed what, from which device, newest first.

Integration tokens need the read ability.

Operation id companies.history.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
subject_typestringthird_parties, accounts, journals, entries, documents, bank_transactions, fixed_assets…
subject_idinteger
user_idinteger
actionstring
created updated deleted restored reverted synced
originstring
online offline_sync system bridge
operation_idstring <uuid>
device_idstring
fromstring <date>
tostring <date>
qstringRecord label, user or device.
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 2301,
            "action": "created",
            "effect": "updated",
            "action_label": "Modification · Tiers",
            "subject_type": "third_parties",
            "subject_type_label": "Tiers",
            "subject_id": 18,
            "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
            "user": null,
            "actor_name": "Claire Dumont",
            "changes": [
                {
                    "field": "payment_terms_days",
                    "label": "Délai de paiement",
                    "old": null,
                    "new": null
                }
            ],
            "version": 4,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "origin": "online",
            "device_id": "mac-7F3A21",
            "device_name": "MacBook de Claire",
            "reason": "string",
            "reverts_revision_id": 42,
            "reverted_at": "2026-03-15T09:41:00+00:00",
            "reverted_by_revision_id": 42,
            "occurred_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "can_revert": true,
            "revert_blocked_reason": "string",
            "revert_blocked_message": "string",
            "revert_effect": "string",
            "snapshot_before": {},
            "snapshot_after": {},
            "ip": "string"
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/history/usersFilters of the history read

People and devices that changed something, subject types and actions.

Integration tokens need the read ability.

Operation id companies.history.users

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • dataobject[]
    Properties
    • idinteger
    • namestring
      e.g. Claire Dumont
    • revisionsinteger
      e.g. 214
    • last_atstring <date-time> | null
    • rolestring
      e.g. firm_admin
  • devicesobject[]
    Properties
    • idstring
    • namestring | null
    • revisionsinteger
  • subject_typesobject[]
    Properties
    • keystring
      e.g. third_parties
    • labelstring
      e.g. Tiers
  • actionsobject[]
    Properties
    • keystring
      e.g. created
    • labelstring
      e.g. Création
Example
{
    "data": [
        {
            "id": 42,
            "name": "Claire Dumont",
            "revisions": 214,
            "last_at": "2026-03-15T09:41:00+00:00",
            "role": "firm_admin"
        }
    ],
    "devices": [
        {
            "id": "string",
            "name": "Le Comptoir Montois SRL",
            "revisions": 1
        }
    ],
    "subject_types": [
        {
            "key": "third_parties",
            "label": "Tiers"
        }
    ],
    "actions": [
        {
            "key": "created",
            "label": "Création"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/users" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/users', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/users", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/users",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/history/exportExport the history (CSV) read 30 / 1 min

Same filters as the list. UTF-8 with BOM, semicolon separated.

Integration tokens need the read ability.

Rate limit: 30 requests per minute (429 beyond, see Retry-After).

Operation id companies.history.export

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
subject_typestringthird_parties, accounts, journals, entries, documents, bank_transactions, fixed_assets…
subject_idinteger
user_idinteger
actionstring
created updated deleted restored reverted synced
originstring
online offline_sync system bridge
operation_idstring <uuid>
device_idstring
fromstring <date>
tostring <date>
qstringRecord label, user or device.

Common headers: Accept-Language

Responses

200CSV file.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/export" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/export', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/export", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/export",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/history/settingsRetention settings read

Integration tokens need the read ability.

Operation id companies.history.settings

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • trash_retention_daysinteger
    e.g. 90
  • default_trash_retention_daysinteger
    e.g. 90
  • min_trash_retention_daysinteger
    e.g. 7
  • max_trash_retention_daysinteger
    e.g. 3650
  • sync_retention_daysinteger
    e.g. 90
  • can_editboolean
Example
{
    "trash_retention_days": 90,
    "default_trash_retention_days": 90,
    "min_trash_retention_days": 7,
    "max_trash_retention_days": 3650,
    "sync_retention_days": 90,
    "can_edit": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/settings" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/settings', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/settings", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/settings",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/companies/{company}/history/settingsUpdate the retention of the recycle bin write

Managers only.

Integration tokens need the write ability.

Error codes (code):

  • settings_forbidden: only a manager can change this setting

Operation id companies.history.settings.update

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Request body

application/json

Schema object
  • trash_retention_daysintegerrequired
    7 to 3650.
Example
{
    "trash_retention_days": 180
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
  • trash_retention_daysinteger
    e.g. 180
  • default_trash_retention_daysinteger
    e.g. 90
  • min_trash_retention_daysinteger
    e.g. 7
  • max_trash_retention_daysinteger
    e.g. 3650
  • sync_retention_daysinteger
    e.g. 90
  • can_editboolean
Example
{
    "trash_retention_days": 180,
    "default_trash_retention_days": 90,
    "min_trash_retention_days": 7,
    "max_trash_retention_days": 3650,
    "sync_retention_days": 90,
    "can_edit": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/settings" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "trash_retention_days": 180
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/settings', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'trash_retention_days' => 180,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/settings", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "trash_retention_days": 180
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/settings",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "trash_retention_days": 180
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/history/operations/{operation}/revertUndo a whole operation write

Reverts every change recorded under one X-Operation-Id, newest first, in one transaction: all or nothing.

Integration tokens need the write ability.

Error codes (code):

  • conflict: the record changed since then (forceable by a manager with force: true)
  • period_locked: locked period or closed fiscal year
  • vat_locked: VAT return validated or submitted
  • already_reverted: already reverted
  • not_revertible: this kind of change cannot be reverted
  • entry_immutable: a posted entry is reversed, not modified
  • in_use: the record is in use
  • booked: the record is booked
  • code_taken: the code is used by another record
  • force_forbidden: only a manager can force
  • read_only: read-only access to the file
  • operation_not_found: unknown operation
  • operation_not_revertible: one change of the batch cannot be reverted
  • nothing_to_revert: nothing to revert

Operation id companies.history.operations.revert

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
operation requiredstring <uuid>Operation id (X-Operation-Id) grouping the changes of one action.
e.g. bf413a19-2136-4504-bc42-b314637eb5c7

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • reasonstring | null
  • forceboolean
    Overwrite newer values (managers).
Example
{
    "reason": "Erreur de saisie"
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
  • revertedboolean
  • operation_idstring <uuid>
  • countinteger
    e.g. 3
  • revisionsRevision[]
  • skippedobject[]
Example
{
    "reverted": true,
    "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "count": 3,
    "revisions": [
        {
            "id": 2301,
            "action": "created",
            "effect": "updated",
            "action_label": "Modification · Tiers",
            "subject_type": "third_parties",
            "subject_type_label": "Tiers",
            "subject_id": 18,
            "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
            "user": null,
            "actor_name": "Claire Dumont",
            "changes": [
                {
                    "field": "payment_terms_days",
                    "label": "Délai de paiement",
                    "old": null,
                    "new": null
                }
            ],
            "version": 4,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "origin": "online",
            "device_id": "mac-7F3A21",
            "device_name": "MacBook de Claire",
            "reason": "string",
            "reverts_revision_id": 42,
            "reverted_at": "2026-03-15T09:41:00+00:00",
            "reverted_by_revision_id": 42,
            "occurred_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "can_revert": true,
            "revert_blocked_reason": "string",
            "revert_blocked_message": "string",
            "revert_effect": "string",
            "snapshot_before": {},
            "snapshot_after": {},
            "ip": "string"
        }
    ],
    "skipped": [
        {}
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/operations/bf413a19-2136-4504-bc42-b314637eb5c7/revert" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "reason": "Erreur de saisie"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/operations/bf413a19-2136-4504-bc42-b314637eb5c7/revert', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'reason' => 'Erreur de saisie',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/operations/bf413a19-2136-4504-bc42-b314637eb5c7/revert", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "reason": "Erreur de saisie"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/operations/bf413a19-2136-4504-bc42-b314637eb5c7/revert",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "reason": "Erreur de saisie"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/history/{revision}Revision read

With the snapshots before and after.

Integration tokens need the read ability.

Operation id companies.history.show

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
revision requiredintegerId of the revision (history line).
e.g. 2301

Common headers: Accept-Language

Responses

200OK

application/json

Schema Revision

Example
{
    "id": 2301,
    "action": "created",
    "effect": "updated",
    "action_label": "Modification · Tiers",
    "subject_type": "third_parties",
    "subject_type_label": "Tiers",
    "subject_id": 18,
    "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
    "user": {
        "id": 12,
        "name": "Claire Dumont"
    },
    "actor_name": "Claire Dumont",
    "changes": [
        {
            "field": "payment_terms_days",
            "label": "Délai de paiement",
            "old": null,
            "new": null
        }
    ],
    "version": 4,
    "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    "origin": "online",
    "device_id": "mac-7F3A21",
    "device_name": "MacBook de Claire",
    "reason": "string",
    "reverts_revision_id": 42,
    "reverted_at": "2026-03-15T09:41:00+00:00",
    "reverted_by_revision_id": 42,
    "occurred_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "can_revert": true,
    "revert_blocked_reason": "string",
    "revert_blocked_message": "string",
    "revert_effect": "string",
    "snapshot_before": {},
    "snapshot_after": {},
    "ip": "string"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/2301" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/2301', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/2301", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/2301",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/history/{revision}/revertRevert a change write

Puts back the state before the change: an update restores the previous values, a deletion restores the record, a creation sends it to the recycle bin, a posted entry is reversed. The revert is itself recorded and revertible.

Integration tokens need the write ability.

Error codes (code):

  • conflict: the record changed since then (forceable by a manager with force: true)
  • period_locked: locked period or closed fiscal year
  • vat_locked: VAT return validated or submitted
  • already_reverted: already reverted
  • not_revertible: this kind of change cannot be reverted
  • entry_immutable: a posted entry is reversed, not modified
  • in_use: the record is in use
  • booked: the record is booked
  • code_taken: the code is used by another record
  • force_forbidden: only a manager can force
  • read_only: read-only access to the file
  • operation_not_found: unknown operation
  • operation_not_revertible: one change of the batch cannot be reverted
  • nothing_to_revert: nothing to revert

Operation id companies.history.revert

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
revision requiredintegerId of the revision (history line).
e.g. 2301

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • reasonstring | null
  • forceboolean
Example
{
    "reason": "Mauvais tiers"
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
  • revertedboolean
  • effectstring
    updated trashed restored recreated reversed
  • revision_idsinteger[]
  • subject_typestring
  • subject_idinteger
  • reversal_entry_idinteger | null
  • revisionRevision
  • revisionsRevision[]
Example
{
    "reverted": true,
    "effect": "updated",
    "revision_ids": [
        1
    ],
    "subject_type": "string",
    "subject_id": 42,
    "reversal_entry_id": 42,
    "revision": {
        "id": 2301,
        "action": "created",
        "effect": "updated",
        "action_label": "Modification · Tiers",
        "subject_type": "third_parties",
        "subject_type_label": "Tiers",
        "subject_id": 18,
        "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
        "user": {
            "id": 12,
            "name": "Claire Dumont"
        },
        "actor_name": "Claire Dumont",
        "changes": [
            {
                "field": "payment_terms_days",
                "label": "Délai de paiement",
                "old": null,
                "new": null
            }
        ],
        "version": 4,
        "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
        "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
        "origin": "online",
        "device_id": "mac-7F3A21",
        "device_name": "MacBook de Claire",
        "reason": "string",
        "reverts_revision_id": 42,
        "reverted_at": "2026-03-15T09:41:00+00:00",
        "reverted_by_revision_id": 42,
        "occurred_at": "2026-03-15T09:41:00+00:00",
        "created_at": "2026-03-15T09:41:00+00:00",
        "can_revert": true,
        "revert_blocked_reason": "string",
        "revert_blocked_message": "string",
        "revert_effect": "string",
        "snapshot_before": {},
        "snapshot_after": {},
        "ip": "string"
    },
    "revisions": [
        {
            "id": 2301,
            "action": "created",
            "effect": "updated",
            "action_label": "Modification · Tiers",
            "subject_type": "third_parties",
            "subject_type_label": "Tiers",
            "subject_id": 18,
            "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
            "user": null,
            "actor_name": "Claire Dumont",
            "changes": [
                {
                    "field": "payment_terms_days",
                    "label": "Délai de paiement",
                    "old": null,
                    "new": null
                }
            ],
            "version": 4,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "origin": "online",
            "device_id": "mac-7F3A21",
            "device_name": "MacBook de Claire",
            "reason": "string",
            "reverts_revision_id": 42,
            "reverted_at": "2026-03-15T09:41:00+00:00",
            "reverted_by_revision_id": 42,
            "occurred_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "can_revert": true,
            "revert_blocked_reason": "string",
            "revert_blocked_message": "string",
            "revert_effect": "string",
            "snapshot_before": {},
            "snapshot_after": {},
            "ip": "string"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/2301/revert" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "reason": "Mauvais tiers"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/2301/revert', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'reason' => 'Mauvais tiers',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/2301/revert", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "reason": "Mauvais tiers"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/history/2301/revert",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "reason": "Mauvais tiers"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/activityActivity of the file read

Audit trail (sign-ins, exports, bookings…) and history merged, newest first. No total: use has_more.

Integration tokens need the read ability.

Operation id companies.activity

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
user_idinteger
fromstring <date>
tostring <date>
typestring
sourcestring
audit revision
qstring
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200OK

application/json

Schema ActivityFeed

Example
{
    "data": [
        {
            "source": "audit",
            "at": "2026-03-15T09:41:00+00:00",
            "recorded_at": "2026-03-15T09:41:00+00:00",
            "user": null,
            "action": "entry.posted",
            "action_label": "Écriture validée",
            "subject_type": "string",
            "subject_id": 42,
            "subject_label": "string",
            "origin": "string",
            "device_name": "MacBook de Claire",
            "revision_id": 42,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "company_id": 7,
            "changed_fields": [
                "string"
            ],
            "company": {
                "token": "XBVD5O1L29HC",
                "name": "Le Comptoir Montois SRL"
            }
        }
    ],
    "current_page": 1,
    "per_page": 50,
    "has_more": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/activity" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/activity', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/activity", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/activity",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/trashRecycle bin read

Integration tokens need the read ability.

Operation id companies.trash.index

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
typestringRecycle bin type.
qstring
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • dataTrashItem[]
  • countsobject
    Type => count.
  • typesobject[]
    Properties
    • keystring
    • labelstring
    • countinteger
  • totalinteger
  • current_pageinteger
  • per_pageinteger
  • last_pageinteger
  • retention_daysinteger
    e.g. 90
  • can_purgeboolean
Example
{
    "data": [
        {
            "type": "third_parties",
            "id": 18,
            "label": "DUBUISSON · Brasserie Dubuisson SA",
            "deleted_at": "2026-03-15T09:41:00+00:00",
            "deleted_by": null,
            "purge_at": "2026-03-15T09:41:00+00:00",
            "restorable": true,
            "blocked_reason": "string",
            "blocked_message": "string",
            "version": 3
        }
    ],
    "counts": {},
    "types": [
        {
            "key": "string",
            "label": "Facture Brasserie Dubuisson",
            "count": 12
        }
    ],
    "total": 1,
    "current_page": 1,
    "per_page": 50,
    "last_page": 1,
    "retention_days": 90,
    "can_purge": true
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/trash/restore-allRestore everything write

Optionally one type only.

Integration tokens need the write ability.

Operation id companies.trash.restore-all

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body optional

application/json

Schema object
  • typestring | null
Example
{
    "type": "third_parties"
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
  • restoredinteger
    e.g. 4
  • skippedobject[]
    Properties
    • typestring
    • idinteger
    • labelstring
    • blocked_reasonstring
      e.g. code_taken
Example
{
    "restored": 4,
    "skipped": [
        {
            "type": "string",
            "id": 42,
            "label": "Facture Brasserie Dubuisson",
            "blocked_reason": "code_taken"
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash/restore-all" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "type": "third_parties"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash/restore-all', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'type' => 'third_parties',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash/restore-all", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "type": "third_parties"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash/restore-all",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "type": "third_parties"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/trash/{type}/{id}/restoreRestore a record write

A third party whose code was taken comes back with a suffixed code; an account, journal or analytic code is refused (code_taken).

Integration tokens need the write ability.

Error codes (code):

  • code_taken: the code is used by another record
  • parent_missing: the linked record no longer exists
  • not_in_trash: the record is not in the recycle bin
  • restore_failed: the restore failed

Operation id companies.trash.restore

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
type requiredstringRecycle bin type: third_parties, accounts, journals, journal_rules, bank_rules, recurring_entries, analytic_codes, fixed_assets, documents, document_imports, integrations.
e.g. third_parties
id requiredintegerId of the record.
e.g. 42

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
  • restoredboolean
  • typestring
  • idinteger
  • labelstring
  • versioninteger
  • dataobject
Example
{
    "restored": true,
    "type": "string",
    "id": 42,
    "label": "Facture Brasserie Dubuisson",
    "version": 3,
    "data": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash/third_parties/42/restore" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash/third_parties/42/restore', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash/third_parties/42/restore", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash/third_parties/42/restore",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/trash/{type}/{id}Delete definitively write

Managers only; recorded in the audit trail. Cannot be undone.

Integration tokens need the write ability.

Error codes (code):

  • purge_forbidden: only a manager can purge

Operation id companies.trash.purge

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
type requiredstringRecycle bin type: third_parties, accounts, journals, journal_rules, bank_rules, recurring_entries, analytic_codes, fixed_assets, documents, document_imports, integrations.
e.g. third_parties
id requiredintegerId of the record.
e.g. 42

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

204Done, no body.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash/third_parties/42" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash/third_parties/42', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash/third_parties/42", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/trash/third_parties/42",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/third-parties/{id}/historyHistory of one record (third parties) read

Same items as the version history, limited to one record.

Integration tokens need the read ability.

Operation id companies.history.subject.third-parties

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Query parameters

NameTypeDescription
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 2301,
            "action": "created",
            "effect": "updated",
            "action_label": "Modification · Tiers",
            "subject_type": "third_parties",
            "subject_type_label": "Tiers",
            "subject_id": 18,
            "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
            "user": null,
            "actor_name": "Claire Dumont",
            "changes": [
                {
                    "field": "payment_terms_days",
                    "label": "Délai de paiement",
                    "old": null,
                    "new": null
                }
            ],
            "version": 4,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "origin": "online",
            "device_id": "mac-7F3A21",
            "device_name": "MacBook de Claire",
            "reason": "string",
            "reverts_revision_id": 42,
            "reverted_at": "2026-03-15T09:41:00+00:00",
            "reverted_by_revision_id": 42,
            "occurred_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "can_revert": true,
            "revert_blocked_reason": "string",
            "revert_blocked_message": "string",
            "revert_effect": "string",
            "snapshot_before": {},
            "snapshot_after": {},
            "ip": "string"
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/42/history" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/42/history', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/42/history", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/third-parties/42/history",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/entries/{id}/historyHistory of one record (entries) read

Same items as the version history, limited to one record.

Integration tokens need the read ability.

Operation id companies.history.subject.entries

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Query parameters

NameTypeDescription
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 2301,
            "action": "created",
            "effect": "updated",
            "action_label": "Modification · Tiers",
            "subject_type": "third_parties",
            "subject_type_label": "Tiers",
            "subject_id": 18,
            "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
            "user": null,
            "actor_name": "Claire Dumont",
            "changes": [
                {
                    "field": "payment_terms_days",
                    "label": "Délai de paiement",
                    "old": null,
                    "new": null
                }
            ],
            "version": 4,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "origin": "online",
            "device_id": "mac-7F3A21",
            "device_name": "MacBook de Claire",
            "reason": "string",
            "reverts_revision_id": 42,
            "reverted_at": "2026-03-15T09:41:00+00:00",
            "reverted_by_revision_id": 42,
            "occurred_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "can_revert": true,
            "revert_blocked_reason": "string",
            "revert_blocked_message": "string",
            "revert_effect": "string",
            "snapshot_before": {},
            "snapshot_after": {},
            "ip": "string"
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/42/history" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/42/history', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/42/history", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/entries/42/history",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/documents/{id}/historyHistory of one record (documents) read

Same items as the version history, limited to one record.

Integration tokens need the read ability.

Operation id companies.history.subject.documents

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Query parameters

NameTypeDescription
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 2301,
            "action": "created",
            "effect": "updated",
            "action_label": "Modification · Tiers",
            "subject_type": "third_parties",
            "subject_type_label": "Tiers",
            "subject_id": 18,
            "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
            "user": null,
            "actor_name": "Claire Dumont",
            "changes": [
                {
                    "field": "payment_terms_days",
                    "label": "Délai de paiement",
                    "old": null,
                    "new": null
                }
            ],
            "version": 4,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "origin": "online",
            "device_id": "mac-7F3A21",
            "device_name": "MacBook de Claire",
            "reason": "string",
            "reverts_revision_id": 42,
            "reverted_at": "2026-03-15T09:41:00+00:00",
            "reverted_by_revision_id": 42,
            "occurred_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "can_revert": true,
            "revert_blocked_reason": "string",
            "revert_blocked_message": "string",
            "revert_effect": "string",
            "snapshot_before": {},
            "snapshot_after": {},
            "ip": "string"
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/42/history" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/42/history', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/42/history", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/42/history",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/accounts/{id}/historyHistory of one record (accounts) read

Same items as the version history, limited to one record.

Integration tokens need the read ability.

Operation id companies.history.subject.accounts

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Query parameters

NameTypeDescription
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 2301,
            "action": "created",
            "effect": "updated",
            "action_label": "Modification · Tiers",
            "subject_type": "third_parties",
            "subject_type_label": "Tiers",
            "subject_id": 18,
            "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
            "user": null,
            "actor_name": "Claire Dumont",
            "changes": [
                {
                    "field": "payment_terms_days",
                    "label": "Délai de paiement",
                    "old": null,
                    "new": null
                }
            ],
            "version": 4,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "origin": "online",
            "device_id": "mac-7F3A21",
            "device_name": "MacBook de Claire",
            "reason": "string",
            "reverts_revision_id": 42,
            "reverted_at": "2026-03-15T09:41:00+00:00",
            "reverted_by_revision_id": 42,
            "occurred_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "can_revert": true,
            "revert_blocked_reason": "string",
            "revert_blocked_message": "string",
            "revert_effect": "string",
            "snapshot_before": {},
            "snapshot_after": {},
            "ip": "string"
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts/42/history" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts/42/history', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts/42/history", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts/42/history",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/bank-transactions/{id}/historyHistory of one record (bank transactions) read

Same items as the version history, limited to one record.

Integration tokens need the read ability.

Operation id companies.history.subject.bank-transactions

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Query parameters

NameTypeDescription
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 2301,
            "action": "created",
            "effect": "updated",
            "action_label": "Modification · Tiers",
            "subject_type": "third_parties",
            "subject_type_label": "Tiers",
            "subject_id": 18,
            "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
            "user": null,
            "actor_name": "Claire Dumont",
            "changes": [
                {
                    "field": "payment_terms_days",
                    "label": "Délai de paiement",
                    "old": null,
                    "new": null
                }
            ],
            "version": 4,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "origin": "online",
            "device_id": "mac-7F3A21",
            "device_name": "MacBook de Claire",
            "reason": "string",
            "reverts_revision_id": 42,
            "reverted_at": "2026-03-15T09:41:00+00:00",
            "reverted_by_revision_id": 42,
            "occurred_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "can_revert": true,
            "revert_blocked_reason": "string",
            "revert_blocked_message": "string",
            "revert_effect": "string",
            "snapshot_before": {},
            "snapshot_after": {},
            "ip": "string"
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/42/history" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/42/history', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/42/history", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/bank-transactions/42/history",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/fixed-assets/{id}/historyHistory of one record (fixed assets) read

Same items as the version history, limited to one record.

Integration tokens need the read ability.

Operation id companies.history.subject.fixed-assets

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Query parameters

NameTypeDescription
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 2301,
            "action": "created",
            "effect": "updated",
            "action_label": "Modification · Tiers",
            "subject_type": "third_parties",
            "subject_type_label": "Tiers",
            "subject_id": 18,
            "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
            "user": null,
            "actor_name": "Claire Dumont",
            "changes": [
                {
                    "field": "payment_terms_days",
                    "label": "Délai de paiement",
                    "old": null,
                    "new": null
                }
            ],
            "version": 4,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "origin": "online",
            "device_id": "mac-7F3A21",
            "device_name": "MacBook de Claire",
            "reason": "string",
            "reverts_revision_id": 42,
            "reverted_at": "2026-03-15T09:41:00+00:00",
            "reverted_by_revision_id": 42,
            "occurred_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "can_revert": true,
            "revert_blocked_reason": "string",
            "revert_blocked_message": "string",
            "revert_effect": "string",
            "snapshot_before": {},
            "snapshot_after": {},
            "ip": "string"
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/42/history" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/42/history', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/42/history", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/42/history",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/journals/{id}/historyHistory of one record (journals) read

Same items as the version history, limited to one record.

Integration tokens need the read ability.

Operation id companies.history.subject.journals

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Query parameters

NameTypeDescription
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 2301,
            "action": "created",
            "effect": "updated",
            "action_label": "Modification · Tiers",
            "subject_type": "third_parties",
            "subject_type_label": "Tiers",
            "subject_id": 18,
            "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
            "user": null,
            "actor_name": "Claire Dumont",
            "changes": [
                {
                    "field": "payment_terms_days",
                    "label": "Délai de paiement",
                    "old": null,
                    "new": null
                }
            ],
            "version": 4,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "origin": "online",
            "device_id": "mac-7F3A21",
            "device_name": "MacBook de Claire",
            "reason": "string",
            "reverts_revision_id": 42,
            "reverted_at": "2026-03-15T09:41:00+00:00",
            "reverted_by_revision_id": 42,
            "occurred_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "can_revert": true,
            "revert_blocked_reason": "string",
            "revert_blocked_message": "string",
            "revert_effect": "string",
            "snapshot_before": {},
            "snapshot_after": {},
            "ip": "string"
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/42/history" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/42/history', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/42/history", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/journals/42/history",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/recurring-entries/{id}/historyHistory of one record (recurring entries) read

Same items as the version history, limited to one record.

Integration tokens need the read ability.

Operation id companies.history.subject.recurring-entries

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Query parameters

NameTypeDescription
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 2301,
            "action": "created",
            "effect": "updated",
            "action_label": "Modification · Tiers",
            "subject_type": "third_parties",
            "subject_type_label": "Tiers",
            "subject_id": 18,
            "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
            "user": null,
            "actor_name": "Claire Dumont",
            "changes": [
                {
                    "field": "payment_terms_days",
                    "label": "Délai de paiement",
                    "old": null,
                    "new": null
                }
            ],
            "version": 4,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "origin": "online",
            "device_id": "mac-7F3A21",
            "device_name": "MacBook de Claire",
            "reason": "string",
            "reverts_revision_id": 42,
            "reverted_at": "2026-03-15T09:41:00+00:00",
            "reverted_by_revision_id": 42,
            "occurred_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "can_revert": true,
            "revert_blocked_reason": "string",
            "revert_blocked_message": "string",
            "revert_effect": "string",
            "snapshot_before": {},
            "snapshot_after": {},
            "ip": "string"
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/42/history" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/42/history', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/42/history", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/recurring-entries/42/history",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/vat-declarations/{id}/historyHistory of one record (vat declarations) read

Same items as the version history, limited to one record.

Integration tokens need the read ability.

Operation id companies.history.subject.vat-declarations

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Query parameters

NameTypeDescription
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

Example
{
    "current_page": 1,
    "data": [
        {
            "id": 2301,
            "action": "created",
            "effect": "updated",
            "action_label": "Modification · Tiers",
            "subject_type": "third_parties",
            "subject_type_label": "Tiers",
            "subject_id": 18,
            "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
            "user": null,
            "actor_name": "Claire Dumont",
            "changes": [
                {
                    "field": "payment_terms_days",
                    "label": "Délai de paiement",
                    "old": null,
                    "new": null
                }
            ],
            "version": 4,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "origin": "online",
            "device_id": "mac-7F3A21",
            "device_name": "MacBook de Claire",
            "reason": "string",
            "reverts_revision_id": 42,
            "reverted_at": "2026-03-15T09:41:00+00:00",
            "reverted_by_revision_id": 42,
            "occurred_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "can_revert": true,
            "revert_blocked_reason": "string",
            "revert_blocked_message": "string",
            "revert_effect": "string",
            "snapshot_before": {},
            "snapshot_after": {},
            "ip": "string"
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/42/history" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/42/history', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/42/history", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/vat-declarations/42/history",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/accounts/{id}Move to the recycle bin (accounts) write

Refused with 422 when the record is used or booked.

Integration tokens need the write ability.

Error codes (code):

  • in_use: the record is used by entries or documents
  • booked: the record is booked: reverse the entry first

Operation id companies.trash.destroy.accounts

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

204Done, no body.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts/42" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts/42', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts/42", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/accounts/42",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/analytic-codes/{id}Move to the recycle bin (analytic codes) write

Refused with 422 when the record is used or booked.

Integration tokens need the write ability.

Error codes (code):

  • in_use: the record is used by entries or documents
  • booked: the record is booked: reverse the entry first

Operation id companies.trash.destroy.analytic-codes

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

204Done, no body.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes/42" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes/42', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes/42", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/analytic-codes/42",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/fixed-assets/{id}Move to the recycle bin (fixed assets) write

Refused with 422 when the record is used or booked.

Integration tokens need the write ability.

Error codes (code):

  • in_use: the record is used by entries or documents
  • booked: the record is booked: reverse the entry first

Operation id companies.trash.destroy.fixed-assets

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

204Done, no body.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/42" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/42', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/42", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/fixed-assets/42",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/companies/{company}/documents/{id}Move to the recycle bin (documents) write

Refused with 422 when the record is used or booked.

Integration tokens need the write ability.

Error codes (code):

  • in_use: the record is used by entries or documents
  • booked: the record is booked: reverse the entry first

Operation id companies.trash.destroy.documents

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
id requiredintegerId of the record.
e.g. 42

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin X-Base-Version

Responses

204Done, no body.
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
409Optimistic lock: the record changed on the server since the version sent in X-Base-Version. Nothing was modified. VersionConflict
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X DELETE "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/42" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/42', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/42", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/documents/42",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Synchronisation

Continuous and offline synchronisation: bootstrap, pull, push, conflicts. Requires the sync ability for integration tokens.

GET/v1/companies/{company}/sync/bootstrapFirst load sync

Starting point of a local copy: the cursor, the list of resources with their REST endpoint, the company, its settings and the rights of the user. Load each resource through its endpoint, then keep cursor for sync/pull.

Integration tokens need the sync ability.

Operation id companies.sync.bootstrap

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • cursorinteger
    e.g. 1042
  • server_timestring <date-time>
  • full_resyncboolean
    e.g. false
  • retention_daysinteger
    e.g. 90
  • resourcesobject[]
    Properties
    • namestring
      e.g. third_parties
    • countinteger
      e.g. 187
    • endpointstring
      e.g. companies/XBVD5O1L29HC/third-parties
    • paginatedboolean
      e.g. false
  • companyCompany
  • company_settingsCompanySettings
  • userobject
    Properties
    • idinteger
    • namestring
      e.g. Claire Dumont
    • rolestring
      e.g. firm_admin
    • role_rankinteger
    • can_writeboolean
    • can_forceboolean
  • pushobject
    Properties
    • resourcesstring[]
    • max_mutationsinteger
      e.g. 200
    • temp_id_prefixstring
      e.g. tmp-
Example
{
    "cursor": 1042,
    "server_time": "2026-03-15T09:41:00+00:00",
    "full_resync": false,
    "retention_days": 90,
    "resources": [
        {
            "name": "third_parties",
            "count": 187,
            "endpoint": "companies/XBVD5O1L29HC/third-parties",
            "paginated": false
        }
    ],
    "company": {
        "id": 7,
        "public_token": "XBVD5O1L29HC",
        "firm_id": 3,
        "code": "COMPTOIR",
        "name": "Le Comptoir Montois SRL",
        "legal_form": "SRL",
        "legal_form_code": "610",
        "enterprise_number": "0477472701",
        "vat_number": "BE0477472701",
        "country_pack": "BE",
        "vat_regime": "monthly",
        "currency": "EUR",
        "locale": "fr",
        "address": "Grand-Place 14, 7000 Mons",
        "street": "Grand-Place",
        "house_number": "14",
        "box": "string",
        "postal_code": "7000",
        "city": "Mons",
        "country": "BE",
        "latitude": "50.4541000",
        "longitude": "3.9523000",
        "nace_codes": [
            {
                "code": "56111",
                "classification": "MAIN"
            }
        ],
        "main_nace_code": "56111",
        "company_sheet_at": "2026-03-15T09:41:00+00:00",
        "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "icon_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "fiscal_year_start": "2026-03-15",
        "fiscal_year_end": "2026-03-15",
        "settings": {
            "vat": {
                "administration_cell": "string",
                "structured_communication": "000000000101",
                "directorate_number": "string",
                "office_number": "string",
                "declarant": {
                    "applicable": false,
                    "company_name": "string",
                    "signatory_1": "string",
                    "signatory_1_title": "string",
                    "signatory_2": "string",
                    "signatory_2_title": "string",
                    "phone": "+32 65 31 42 18",
                    "fax": "string",
                    "email": "claire.dumont@fiduciaire-dumont.be",
                    "language": "fr"
                },
                "sender_281_50": {
                    "name": "Le Comptoir Montois SRL",
                    "enterprise_number": "0477472701",
                    "address": "Grand-Place 14",
                    "phone": "+32 65 31 42 18",
                    "email": "claire.dumont@fiduciaire-dumont.be"
                },
                "filer": {
                    "quality": "company",
                    "name": "Le Comptoir Montois SRL",
                    "enterprise_number": "0477472701",
                    "phone": "+32 65 31 42 18",
                    "email": "claire.dumont@fiduciaire-dumont.be"
                }
            },
            "legal": {
                "rpm_district": "Hainaut, division Mons"
            },
            "annual_accounts": {
                "scheme": "abbreviated",
                "general_meeting_date": "2026-03-15",
                "directors": "string",
                "valuation_rules": "string"
            },
            "auto_entries": {
                "vat": {
                    "payable_account": "451000",
                    "receivable_account": "411000",
                    "correction_payable_account": "string",
                    "correction_receivable_account": "string",
                    "journal_id": 3
                },
                "invoices_to_receive": {
                    "supplier_account": "444000",
                    "customer_account": "404000",
                    "journal_id": 3
                },
                "reconciliation_difference": {
                    "expense_account": "657000",
                    "income_account": "757000",
                    "max_amount": 1
                },
                "transfers": {
                    "transit_account": "580000",
                    "journal_id": 3
                }
            },
            "history": {
                "trash_retention_days": 90
            }
        },
        "is_active": true,
        "is_demo": false,
        "source": "manual",
        "external_id": "string",
        "synced_at": "2026-03-15T09:41:00+00:00",
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "deleted_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal_entries_count": 1284,
        "firm": {
            "id": 3,
            "public_token": "NDTQVQU4AUAV",
            "name": "Fiduciaire Dumont & Associés"
        },
        "fiscal_years": [
            {
                "id": 2,
                "company_id": 7,
                "code": "2026",
                "starts_on": "2026-01-01T00:00:00.000000Z",
                "ends_on": "2026-12-31T00:00:00.000000Z",
                "is_closed": false,
                "closed_at": "2026-03-15T09:41:00+00:00",
                "closed_by": 1,
                "created_at": "2026-03-15T09:41:00+00:00",
                "updated_at": "2026-03-15T09:41:00+00:00",
                "lock_version": 3,
                "version": 3,
                "periods": [
                    {}
                ]
            }
        ],
        "journals": [
            {
                "id": 3,
                "company_id": 7,
                "code": "VEN",
                "label": "Ventes",
                "type": "purchase",
                "control_account_id": 42,
                "iban": "BE68539007547034",
                "bic": "GEBABEBB",
                "last_number": 412,
                "is_active": true,
                "is_default": true,
                "description": "Description",
                "created_at": "2026-03-15T09:41:00+00:00",
                "updated_at": "2026-03-15T09:41:00+00:00",
                "lock_version": 3,
                "version": 3,
                "deleted_at": "2026-03-15T09:41:00+00:00",
                "deleted_by": 1,
                "entries_count": 412,
                "control_account": null,
                "rules": [
                    {}
                ]
            }
        ]
    },
    "company_settings": {
        "vat": {
            "administration_cell": "string",
            "structured_communication": "000000000101",
            "directorate_number": "string",
            "office_number": "string",
            "declarant": {
                "applicable": false,
                "company_name": "string",
                "signatory_1": "string",
                "signatory_1_title": "string",
                "signatory_2": "string",
                "signatory_2_title": "string",
                "phone": "+32 65 31 42 18",
                "fax": "string",
                "email": "claire.dumont@fiduciaire-dumont.be",
                "language": "fr"
            },
            "sender_281_50": {
                "name": "Le Comptoir Montois SRL",
                "enterprise_number": "0477472701",
                "address": "Grand-Place 14",
                "phone": "+32 65 31 42 18",
                "email": "claire.dumont@fiduciaire-dumont.be"
            },
            "filer": {
                "quality": "company",
                "name": "Le Comptoir Montois SRL",
                "enterprise_number": "0477472701",
                "phone": "+32 65 31 42 18",
                "email": "claire.dumont@fiduciaire-dumont.be"
            }
        },
        "legal": {
            "rpm_district": "Hainaut, division Mons"
        },
        "annual_accounts": {
            "scheme": "abbreviated",
            "general_meeting_date": "2026-03-15",
            "directors": "string",
            "valuation_rules": "string"
        },
        "auto_entries": {
            "vat": {
                "payable_account": "451000",
                "receivable_account": "411000",
                "correction_payable_account": "string",
                "correction_receivable_account": "string",
                "journal_id": 3
            },
            "invoices_to_receive": {
                "supplier_account": "444000",
                "customer_account": "404000",
                "journal_id": 3
            },
            "reconciliation_difference": {
                "expense_account": "657000",
                "income_account": "757000",
                "max_amount": 1
            },
            "transfers": {
                "transit_account": "580000",
                "journal_id": 3
            }
        },
        "history": {
            "trash_retention_days": 90
        }
    },
    "user": {
        "id": 42,
        "name": "Claire Dumont",
        "role": "firm_admin",
        "role_rank": 1,
        "can_write": true,
        "can_force": true
    },
    "push": {
        "resources": [
            "string"
        ],
        "max_mutations": 200,
        "temp_id_prefix": "tmp-"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/bootstrap" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/bootstrap', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/bootstrap", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/bootstrap",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/sync/pullIncremental pull sync

Changes since a cursor, one line per record (last state). delete is a tombstone (deleted or in the recycle bin). When since is absent, unknown or older than the 90-day journal, full_resync is true and no change is returned: reload everything, then restart from the returned cursor. A change becomes visible two seconds after it was written.

Integration tokens need the sync ability.

Operation id companies.sync.pull

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
sinceintegerCursor of the previous pull or bootstrap.
e.g. 1042
resourcesstringComma-separated resource names.
e.g. third_parties,entries
limitinteger500 by default, 1000 max.

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • cursorinteger
    e.g. 1057
  • has_moreboolean
    e.g. false
  • full_resyncboolean
    e.g. false
  • changesSyncChange[]
  • server_timestring <date-time>
Example
{
    "cursor": 1057,
    "has_more": false,
    "full_resync": false,
    "changes": [
        {
            "resource": "third_parties",
            "op": "upsert",
            "id": 18,
            "version": 4,
            "data": {},
            "changed_at": "2026-03-15T09:41:00+00:00",
            "seq": 1042
        }
    ],
    "server_time": "2026-03-15T09:41:00+00:00"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/pull" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/pull', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/pull", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/pull",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/sync/pushPush offline mutations sync

Up to 200 mutations, processed in order, each in its own transaction and replayed through the matching REST action. Idempotent on client_mutation_id. Conflicts are settled by the priority rules (posted or locked accounting data always wins; field-by-field merge; highest role, then most recent change).

Integration tokens need the sync ability.

Operation id companies.sync.push

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • deviceobject
    Properties
    • idstring
    • namestring
    • platformstring
      e.g. macos
  • mutationsSyncMutation[]required
Example
{
    "device": {
        "id": "erp-connector-01",
        "name": "ERP connector",
        "platform": "server"
    },
    "mutations": [
        {
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "occurred_at": "2026-10-05T08:00:00Z",
            "resource": "third_parties",
            "op": "create",
            "client_temp_id": "tmp-3c1f",
            "data": {
                "type": "supplier",
                "name": "Proximus SA",
                "vat_number": "BE0202239951"
            }
        }
    ]
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
Example
{
    "results": [
        {
            "client_mutation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "status": "applied",
            "original_status": "string",
            "code": "COMPTOIR",
            "message": "OK",
            "resource": "string",
            "op": "string",
            "action": "string",
            "id": 42,
            "client_temp_id": "string",
            "version": 3,
            "data": {},
            "errors": {},
            "conflict": {
                "server_version": 1,
                "server_data": {},
                "fields": [
                    {
                        "field": "string",
                        "client": null,
                        "server": null,
                        "winner": "client",
                        "rule": "string"
                    }
                ],
                "resolution": "string"
            },
            "duplicate_of": 1,
            "retryable": true
        }
    ],
    "cursor": 1,
    "server_time": "2026-03-15T09:41:00+00:00"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/push" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "device": {
        "id": "erp-connector-01",
        "name": "ERP connector",
        "platform": "server"
    },
    "mutations": [
        {
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "occurred_at": "2026-10-05T08:00:00Z",
            "resource": "third_parties",
            "op": "create",
            "client_temp_id": "tmp-3c1f",
            "data": {
                "type": "supplier",
                "name": "Proximus SA",
                "vat_number": "BE0202239951"
            }
        }
    ]
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/push', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'device' => [
            'id' => 'erp-connector-01',
            'name' => 'ERP connector',
            'platform' => 'server',
        ],
        'mutations' => [
            [
                'client_mutation_id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
                'occurred_at' => '2026-10-05T08:00:00Z',
                'resource' => 'third_parties',
                'op' => 'create',
                'client_temp_id' => 'tmp-3c1f',
                'data' => [
                    'type' => 'supplier',
                    'name' => 'Proximus SA',
                    'vat_number' => 'BE0202239951',
                ],
            ],
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/push", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "device": {
          "id": "erp-connector-01",
          "name": "ERP connector",
          "platform": "server"
      },
      "mutations": [
          {
              "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
              "occurred_at": "2026-10-05T08:00:00Z",
              "resource": "third_parties",
              "op": "create",
              "client_temp_id": "tmp-3c1f",
              "data": {
                  "type": "supplier",
                  "name": "Proximus SA",
                  "vat_number": "BE0202239951"
              }
          }
      ]
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/push",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "device": {
            "id": "erp-connector-01",
            "name": "ERP connector",
            "platform": "server"
        },
        "mutations": [
            {
                "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
                "occurred_at": "2026-10-05T08:00:00Z",
                "resource": "third_parties",
                "op": "create",
                "client_temp_id": "tmp-3c1f",
                "data": {
                    "type": "supplier",
                    "name": "Proximus SA",
                    "vat_number": "BE0202239951"
                }
            }
        ]
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/sync/statusSynchronisation status sync

Integration tokens need the sync ability.

Operation id companies.sync.status

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • cursorinteger
  • server_timestring <date-time>
  • pending_conflictsinteger
    e.g. 0
  • last_push_atstring <date-time> | null
  • devicesobject[]
    Properties
    • idstring
    • namestring | null
    • platformstring | null
    • userobject | null
    • last_seen_atstring <date-time> | null
    • last_push_atstring <date-time> | null
    • last_cursorinteger | null
Example
{
    "cursor": 1,
    "server_time": "2026-03-15T09:41:00+00:00",
    "pending_conflicts": 0,
    "last_push_at": "2026-03-15T09:41:00+00:00",
    "devices": [
        {
            "id": "string",
            "name": "Le Comptoir Montois SRL",
            "platform": "string",
            "user": {},
            "last_seen_at": "2026-03-15T09:41:00+00:00",
            "last_push_at": "2026-03-15T09:41:00+00:00",
            "last_cursor": 1
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/status" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/status', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/status", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/status",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/sync/conflictsSynchronisation conflicts sync

Integration tokens need the sync ability.

Operation id companies.sync.conflicts

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
statusstring
open resolved
resourcestring
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 50, maximum 200).
e.g. 50

Common headers: Accept-Language

Responses

200Paginated list

application/json

Schema Pagination & object

Includes Pagination

  • openinteger
    Number of open conflicts.
    e.g. 0
Example
{
    "current_page": 1,
    "data": [
        {
            "id": 8,
            "status": "open",
            "type": "field",
            "type_label": "string",
            "resource": "third_parties",
            "record_id": 42,
            "subject_id": 42,
            "subject_label": "string",
            "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
            "fields": [
                {
                    "field": "string",
                    "label": "Facture Brasserie Dubuisson",
                    "server": null,
                    "client": null,
                    "winner": "string",
                    "rule": "string"
                }
            ],
            "client_data": {},
            "server_data": {},
            "server_version": 1,
            "winner": "string",
            "loser": "string",
            "resolution": "string",
            "resolved_by": 1,
            "client_user": {},
            "server_user": {},
            "resolved_by_user": {},
            "device_id": "mac-7F3A21",
            "created_at": "2026-03-15T09:41:00+00:00",
            "resolved_at": "2026-03-15T09:41:00+00:00",
            "choices": [
                "server"
            ]
        }
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187,
    "open": 0
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/conflicts" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/conflicts', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/conflicts", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/conflicts",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/sync/conflicts/{conflict}/resolveResolve a conflict sync

client applies the values that were refused, merge applies data, server acknowledges.

Integration tokens need the sync ability.

Error codes (code):

  • conflict_already_resolved: already resolved
  • conflict_choice_unavailable: choice not available for this conflict

Operation id companies.sync.conflicts.resolve

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC
conflict requiredintegerId of the synchronisation conflict.
e.g. 8

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • choicestringrequired
    server client merge
  • dataobject | null
    Required for merge.
Example
{
    "choice": "client"
}

Responses

200OK

Response headers X-Operation-Id X-Idempotent-Replay

application/json

Schema object
Example
{
    "resolved": true,
    "conflict": {
        "id": 8,
        "status": "open",
        "type": "field",
        "type_label": "string",
        "resource": "third_parties",
        "record_id": 42,
        "subject_id": 42,
        "subject_label": "string",
        "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
        "fields": [
            {
                "field": "string",
                "label": "Facture Brasserie Dubuisson",
                "server": null,
                "client": null,
                "winner": "string",
                "rule": "string"
            }
        ],
        "client_data": {},
        "server_data": {},
        "server_version": 1,
        "winner": "string",
        "loser": "string",
        "resolution": "string",
        "resolved_by": 1,
        "client_user": {},
        "server_user": {},
        "resolved_by_user": {},
        "device_id": "mac-7F3A21",
        "created_at": "2026-03-15T09:41:00+00:00",
        "resolved_at": "2026-03-15T09:41:00+00:00",
        "choices": [
            "server"
        ]
    },
    "data": {}
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/conflicts/8/resolve" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "choice": "client"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/conflicts/8/resolve', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'choice' => 'client',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/conflicts/8/resolve", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "choice": "client"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/sync/conflicts/8/resolve",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "choice": "client"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Mail

Mails sent to clients in the name of the firm, shared files.

POST/v1/companies/{company}/mail/documentsSend documents or an export by e-mail write Not in demo 20 / 1 min

Sends documents of the file and / or an export to a client, in the name of the firm. Above 10 MB (or with as_link) the files are sent as a signed download link valid 7 days. Manager role at least.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 20 requests per minute (429 beyond, see Retry-After).

Operation id companies.mail.documents

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • tostring <email>[]required
  • ccstring <email>[]
  • subjectstring | null
  • messagestringrequired
    5000 characters max.
  • document_idsinteger[]
  • exportobject
    Properties
    • typestringrequired
      Export code or full-dossier.
    • formatstring
      pdf xlsx csv zip
    • fiscal_year_idinteger | null
    • fromstring <date> | null
    • tostring <date> | null
    • langstring
      fr nl en de
    • paramsobject | null
  • as_linkboolean
Example
{
    "to": [
        "gerant@comptoir-montois.example"
    ],
    "subject": "Balance au 30 septembre",
    "message": "Bonjour, vous trouverez ci-joint la balance arrêtée au 30 septembre.",
    "export": {
        "type": "trial-balance",
        "format": "pdf",
        "to": "2026-09-30"
    }
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • messagestring
  • sentinteger
    e.g. 1
  • modestring
    attachment link
  • recipientsstring <email>[]
  • attachmentsobject[]
    Properties
    • namestring
      e.g. balance-2026-09-30.pdf
    • sizeinteger
      e.g. 48211
  • link_expires_atstring <date-time> | null
Example
{
    "message": "OK",
    "sent": 1,
    "mode": "attachment",
    "recipients": [
        "claire.dumont@fiduciaire-dumont.be"
    ],
    "attachments": [
        {
            "name": "balance-2026-09-30.pdf",
            "size": 48211
        }
    ],
    "link_expires_at": "2026-03-15T09:41:00+00:00"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/mail/documents" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "to": [
        "gerant@comptoir-montois.example"
    ],
    "subject": "Balance au 30 septembre",
    "message": "Bonjour, vous trouverez ci-joint la balance arrêtée au 30 septembre.",
    "export": {
        "type": "trial-balance",
        "format": "pdf",
        "to": "2026-09-30"
    }
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/mail/documents', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'to' => [
            'gerant@comptoir-montois.example',
        ],
        'subject' => 'Balance au 30 septembre',
        'message' => 'Bonjour, vous trouverez ci-joint la balance arrêtée au 30 septembre.',
        'export' => [
            'type' => 'trial-balance',
            'format' => 'pdf',
            'to' => '2026-09-30',
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/mail/documents", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "to": [
          "gerant@comptoir-montois.example"
      ],
      "subject": "Balance au 30 septembre",
      "message": "Bonjour, vous trouverez ci-joint la balance arrêtée au 30 septembre.",
      "export": {
          "type": "trial-balance",
          "format": "pdf",
          "to": "2026-09-30"
      }
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/mail/documents",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "to": [
            "gerant@comptoir-montois.example"
        ],
        "subject": "Balance au 30 septembre",
        "message": "Bonjour, vous trouverez ci-joint la balance arrêtée au 30 septembre.",
        "export": {
            "type": "trial-balance",
            "format": "pdf",
            "to": "2026-09-30"
        }
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/companies/{company}/mail/document-requestAsk a client for missing documents write Not in demo 20 / 1 min

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 20 requests per minute (429 beyond, see Retry-After).

Operation id companies.mail.document-request

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Common headers: Accept-Language X-Client-Mutation-Id X-Operation-Id X-Device-Id X-Device-Name X-Occurred-At X-Origin

Request body

application/json

Schema object
  • tostring <email>[]required
  • itemsstring[]required
  • messagestring | null
  • due_datestring <date> | null
Example
{
    "to": [
        "gerant@comptoir-montois.example"
    ],
    "items": [
        "Extrait bancaire de septembre",
        "Facture Engie d'août"
    ],
    "due_date": "2026-10-15"
}

Responses

201Created

Response headers X-Operation-Id X-Idempotent-Replay X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • sentinteger
    e.g. 1
  • messagestring
Example
{
    "sent": 1,
    "message": "OK"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/mail/document-request" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "X-Client-Mutation-Id: b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11" \
  -d '{
    "to": [
        "gerant@comptoir-montois.example"
    ],
    "items": [
        "Extrait bancaire de septembre",
        "Facture Engie d'\''août"
    ],
    "due_date": "2026-10-15"
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/mail/document-request', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
        'X-Client-Mutation-Id' => 'b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11',
    ],
    'json' => [
        'to' => [
            'gerant@comptoir-montois.example',
        ],
        'items' => [
            'Extrait bancaire de septembre',
            'Facture Engie d\'août',
        ],
        'due_date' => '2026-10-15',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/mail/document-request", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
    "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
  },
  body: JSON.stringify({
      "to": [
          "gerant@comptoir-montois.example"
      ],
      "items": [
          "Extrait bancaire de septembre",
          "Facture Engie d'août"
      ],
      "due_date": "2026-10-15"
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/mail/document-request",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
        "X-Client-Mutation-Id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    },
    json={
        "to": [
            "gerant@comptoir-montois.example"
        ],
        "items": [
            "Extrait bancaire de septembre",
            "Facture Engie d'août"
        ],
        "due_date": "2026-10-15"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/companies/{company}/mail/logsMails sent for the file read

Integration tokens need the read ability.

Operation id companies.mail.logs

Path parameters

NameTypeDescription
company requiredstringPublic token of the company file (public_token, 12 characters).
e.g. XBVD5O1L29HC

Query parameters

NameTypeDescription
templatestringTemplate key.
per_pageinteger25 by default, 100 max.
pageinteger

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • dataMailLog[]
  • metaobject
    Properties
    • current_pageinteger
      e.g. 1
    • last_pageinteger
      e.g. 1
    • totalinteger
      e.g. 12
Example
{
    "data": [
        {
            "id": 9012,
            "template_key": "documents.send",
            "to": "gerant@comptoir-montois.example",
            "subject": "Vos documents comptables",
            "status": "queued",
            "locale": "fr",
            "created_at": "2026-03-15T09:41:00+00:00",
            "sent_at": "2026-03-15T09:41:00+00:00",
            "opened_at": "2026-03-15T09:41:00+00:00",
            "attachments": [
                {
                    "name": "balance-2026.pdf",
                    "size": 48211
                }
            ]
        }
    ],
    "meta": {
        "current_page": 1,
        "last_page": 1,
        "total": 12
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/mail/logs" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/companies/XBVD5O1L29HC/mail/logs', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/companies/XBVD5O1L29HC/mail/logs", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/companies/XBVD5O1L29HC/mail/logs",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/mail/shares/{share}Download a shared file Signed URL 60 / 1 min

Signed link of a mail (7 days). An expired or purged share redirects to the « download expired » page of the app.

Authorised by the signature of the URL (query parameters signature and expires), not by a bearer token. The URL is issued by another endpoint and expires.

Rate limit: 60 requests per minute (429 beyond, see Retry-After).

Operation id mail.shares.download

Path parameters

NameTypeDescription
share requiredstringToken of the shared file.
e.g. q8ZrT2mVx4

Common headers: signature expires

Responses

200The file.

Response headers Content-Disposition X-RateLimit-Limit X-RateLimit-Remaining

application/octet-stream

302Expired share.
Response headerDescription
LocationTarget of the redirection.
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/mail/shares/q8ZrT2mVx4" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/mail/shares/q8ZrT2mVx4', [
    'headers' => [
        'Accept' => 'application/json',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/mail/shares/q8ZrT2mVx4", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/mail/shares/q8ZrT2mVx4",
    headers={
        "Accept": "application/json",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/mail/o/{token}.gifOpen pixel Public 240 / 1 min

Present in the mails only when tracking is switched on by the firm. Not meant to be called by integrations.

Public endpoint: no bearer token.

Rate limit: 240 requests per minute (429 beyond, see Retry-After).

Operation id mail.open

Path parameters

NameTypeDescription
token requiredstringOpaque token.
e.g. a1B2c3D4e5

Responses

200Transparent 1 × 1 GIF.

Response headers X-RateLimit-Limit X-RateLimit-Remaining

image/gif

404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/mail/o/a1B2c3D4e5.gif" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/mail/o/a1B2c3D4e5.gif', [
    'headers' => [
        'Accept' => 'application/json',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/mail/o/a1B2c3D4e5.gif", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/mail/o/a1B2c3D4e5.gif",
    headers={
        "Accept": "application/json",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/mail/c/{token}Click redirection Public 240 / 1 min

Followed only when the signature of the target matches (no open redirect). Not meant to be called by integrations.

Public endpoint: no bearer token.

Rate limit: 240 requests per minute (429 beyond, see Retry-After).

Operation id mail.click

Path parameters

NameTypeDescription
token requiredstringOpaque token.
e.g. a1B2c3D4e5

Query parameters

NameTypeDescription
u requiredstringEncoded target.
s requiredstringSignature.

Responses

302Redirection to the target.
Response headerDescription
LocationTarget of the redirection.
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/mail/c/a1B2c3D4e5?u=string&s=string" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/mail/c/a1B2c3D4e5', [
    'headers' => [
        'Accept' => 'application/json',
    ],
    'query' => [
        'u' => 'string',
        's' => 'string',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/mail/c/a1B2c3D4e5?u=string&s=string", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/mail/c/a1B2c3D4e5",
    headers={
        "Accept": "application/json",
    },
    params={
        "u": "string",
        "s": "string"
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Webhooks

Outgoing webhooks of a firm: endpoints, test event, delivery log.

GET/v1/webhooks/eventsCatalogue of webhook events read

Integration tokens need the read ability.

Operation id webhooks.events

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • dataobject[]
    Properties
    • eventstring
      e.g. entry.posted
    • descriptionstring
      e.g. An entry was posted.
Example
{
    "data": [
        {
            "event": "entry.posted",
            "description": "An entry was posted."
        }
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/webhooks/events" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/webhooks/events', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/webhooks/events", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/webhooks/events",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/firms/{firm}/webhooksList the webhook endpoints read

Admins and managers of the firm (403 for other members, 404 for non-members).

Integration tokens need the read ability.

Operation id firms.webhooks.index

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
Example
{
    "data": [
        {
            "id": 3,
            "url": "https://erp.example.com/hooks/novafisko",
            "description": "ERP connector",
            "events": [
                "entry.posted"
            ],
            "is_active": true,
            "secret_hint": "whsec_…ab12",
            "last_delivery_at": "2026-03-15T09:41:00+00:00",
            "last_status": "delivered",
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00"
        }
    ],
    "available_events": [
        "entry.posted"
    ]
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/firms/{firm}/webhooksCreate a webhook endpoint write Not in demo

The signing secret (whsec_…) is returned once. Events are queued and sent by a dispatcher that runs every minute.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Error codes (code):

  • webhook_limit_reached: 20 endpoints per firm at most
  • webhook_url_refused: the URL is not HTTPS or targets a private / loopback address (production)

Operation id firms.webhooks.store

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV

Common headers: Accept-Language

Request body

application/json

Schema object
  • urlstring <uri>required
    HTTPS endpoint that receives the events (500 characters max).
  • descriptionstring | null
  • eventsstring[]required
  • is_activeboolean
Example
{
    "url": "https://erp.example.com/hooks/novafisko",
    "description": "ERP connector",
    "events": [
        "entry.posted",
        "document.booked",
        "vat.declaration_validated"
    ]
}

Responses

201Created

application/json

Schema object
  • secretstring
    Signing secret (whsec_ followed by 40 characters), shown once.
    e.g. whsec_4Qm9x2kL8vT4nR7sW1pZ5cY3hJ6dF0gA9bE2uI4o
Example
{
    "webhook": {
        "id": 3,
        "url": "https://erp.example.com/hooks/novafisko",
        "description": "ERP connector",
        "events": [
            "entry.posted"
        ],
        "is_active": true,
        "secret_hint": "whsec_…ab12",
        "last_delivery_at": "2026-03-15T09:41:00+00:00",
        "last_status": "delivered",
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00"
    },
    "data": {
        "id": 3,
        "url": "https://erp.example.com/hooks/novafisko",
        "description": "ERP connector",
        "events": [
            "entry.posted"
        ],
        "is_active": true,
        "secret_hint": "whsec_…ab12",
        "last_delivery_at": "2026-03-15T09:41:00+00:00",
        "last_status": "delivered",
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00"
    },
    "secret": "whsec_4Qm9x2kL8vT4nR7sW1pZ5cY3hJ6dF0gA9bE2uI4o"
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://erp.example.com/hooks/novafisko",
    "description": "ERP connector",
    "events": [
        "entry.posted",
        "document.booked",
        "vat.declaration_validated"
    ]
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'url' => 'https://erp.example.com/hooks/novafisko',
        'description' => 'ERP connector',
        'events' => [
            'entry.posted',
            'document.booked',
            'vat.declaration_validated',
        ],
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "url": "https://erp.example.com/hooks/novafisko",
      "description": "ERP connector",
      "events": [
          "entry.posted",
          "document.booked",
          "vat.declaration_validated"
      ]
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "url": "https://erp.example.com/hooks/novafisko",
        "description": "ERP connector",
        "events": [
            "entry.posted",
            "document.booked",
            "vat.declaration_validated"
        ]
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
PATCH/v1/firms/{firm}/webhooks/{webhook}Update a webhook endpoint write Not in demo

A paused endpoint keeps its pending deliveries; they are sent once it is active again.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Error codes (code):

  • webhook_url_refused: the URL is not HTTPS or targets a private / loopback address (production)

Operation id firms.webhooks.update

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV
webhook requiredintegerId of the webhook endpoint.
e.g. 3

Common headers: Accept-Language

Request body

application/json

Schema object
  • urlstring <uri>
  • descriptionstring | null
  • eventsstring[]
  • is_activeboolean
Example
{
    "is_active": false
}

Responses

200OK

application/json

Schema object
Example
{
    "webhook": {
        "id": 3,
        "url": "https://erp.example.com/hooks/novafisko",
        "description": "ERP connector",
        "events": [
            "entry.posted"
        ],
        "is_active": true,
        "secret_hint": "whsec_…ab12",
        "last_delivery_at": "2026-03-15T09:41:00+00:00",
        "last_status": "delivered",
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00"
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
422Validation failed or business rule refused the request. errors maps each field to its messages; code is present when the refusal has a machine reason. Error

Request sample

curl -X PATCH "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "is_active": false
}'
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
    'json' => [
        'is_active' => false,
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3", {
  method: "PATCH",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
      "is_active": false
  }),
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.patch(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    json={
        "is_active": False
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
DELETE/v1/firms/{firm}/webhooks/{webhook}Delete a webhook endpoint write Not in demo

Pending deliveries of the endpoint are dropped.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Operation id firms.webhooks.destroy

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV
webhook requiredintegerId of the webhook endpoint.
e.g. 3

Common headers: Accept-Language

Responses

204Done, no body.

No body.

401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X DELETE "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('DELETE', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.delete(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
POST/v1/firms/{firm}/webhooks/{webhook}/testSend a test event write Not in demo 12 / 1 min

Sends a webhook.test event immediately, signed like a real one. It is never retried: the returned delivery is delivered or failed.

Integration tokens need the write ability.

Not available in demo mode: answers 403 demo_mode.

Rate limit: 12 requests per minute (429 beyond, see Retry-After).

Operation id firms.webhooks.test

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV
webhook requiredintegerId of the webhook endpoint.
e.g. 3

Common headers: Accept-Language

Responses

202Test event sent.

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
Example
{
    "delivery": {
        "id": 1871,
        "event_id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
        "event": "entry.posted",
        "status": "pending",
        "attempts": 1,
        "next_attempt_at": "2026-03-15T09:41:00+00:00",
        "response_status": 200,
        "response_excerpt": "string",
        "duration_ms": 184,
        "delivered_at": "2026-03-15T09:41:00+00:00",
        "created_at": "2026-03-15T09:41:00+00:00",
        "payload": {
            "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
            "event": "entry.posted",
            "api_version": "v1",
            "created_at": "2026-03-15T09:41:00+00:00",
            "firm": {
                "public_token": "NDTQVQU4AUAV",
                "name": "Fiduciaire Dumont & Associés"
            },
            "company": {
                "public_token": "XBVD5O1L29HC",
                "name": "Le Comptoir Montois SRL"
            },
            "data": {}
        },
        "attempt": 1,
        "http_status": 200
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X POST "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3/test" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3/test', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3/test", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.post(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3/test",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/firms/{firm}/webhooks/{webhook}/deliveriesDeliveries of a webhook endpoint read

Newest first, with the status, the number of attempts and an excerpt of the answer (2000 characters max). Deliveries that are no longer pending are pruned after 30 days.

Integration tokens need the read ability.

Operation id firms.webhooks.deliveries

Path parameters

NameTypeDescription
firm requiredstringPublic token of the firm (public_token, 12 characters).
e.g. NDTQVQU4AUAV
webhook requiredintegerId of the webhook endpoint.
e.g. 3

Query parameters

NameTypeDescription
statusstring
pending delivered failed
eventstring
e.g. entry.posted
pageintegerPage number, starting at 1.
e.g. 1
per_pageintegerItems per page (default 25, maximum 100).
e.g. 25

Common headers: Accept-Language

Responses

200OK

application/json

Schema object
  • metaobject
    Properties
    • current_pageinteger
      e.g. 1
    • last_pageinteger
      e.g. 3
    • per_pageinteger
      e.g. 25
    • totalinteger
      e.g. 61
Example
{
    "data": [
        {
            "id": 1871,
            "event_id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
            "event": "entry.posted",
            "status": "pending",
            "attempts": 1,
            "next_attempt_at": "2026-03-15T09:41:00+00:00",
            "response_status": 200,
            "response_excerpt": "string",
            "duration_ms": 184,
            "delivered_at": "2026-03-15T09:41:00+00:00",
            "created_at": "2026-03-15T09:41:00+00:00",
            "payload": {
                "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
                "event": "entry.posted",
                "api_version": "v1",
                "created_at": "2026-03-15T09:41:00+00:00",
                "firm": {
                    "public_token": "NDTQVQU4AUAV",
                    "name": "Fiduciaire Dumont & Associés"
                },
                "company": {
                    "public_token": "XBVD5O1L29HC",
                    "name": "Le Comptoir Montois SRL"
                },
                "data": {}
            },
            "attempt": 1,
            "http_status": 200
        }
    ],
    "meta": {
        "current_page": 1,
        "last_page": 3,
        "per_page": 25,
        "total": 61
    }
}
401Missing, invalid, revoked or expired bearer token. Error
403Authenticated but not allowed: role too low, missing token ability (token_ability_missing, session_token_required), demo restriction (demo_mode) or invalid URL signature. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error

Request sample

curl -X GET "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3/deliveries" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer $NOVAFISKO_TOKEN"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3/deliveries', [
    'headers' => [
        'Accept' => 'application/json',
        'Authorization' => 'Bearer '.getenv('NOVAFISKO_TOKEN'),
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3/deliveries", {
  method: "GET",
  headers: {
    "Accept": "application/json",
    "Authorization": `Bearer ${process.env.NOVAFISKO_TOKEN}`,
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/firms/NDTQVQU4AUAV/webhooks/3/deliveries",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {os.environ['NOVAFISKO_TOKEN']}",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Novadesko bridge

Endpoints reserved to the Novadesko platform (shared secret).

GET/v1/bridge/pingPing of the Novadesko bridge Public 30 / 1 min

Used by Novadesko to check the shared secret. Reserved to the Novadesko platform.

Public endpoint: no bearer token.

Rate limit: 30 requests per minute (429 beyond, see Retry-After).

Operation id bridge.ping

Headers

NameTypeDescription
X-Novafisko-Secret requiredstringShared secret of the bridge.

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • okboolean
  • appstring
    e.g. NovaFisko
  • timestring <date-time>
  • linked_firmsinteger
  • linked_companiesinteger
Example
{
    "ok": true,
    "app": "NovaFisko",
    "time": "2026-03-15T09:41:00+00:00",
    "linked_firms": 1,
    "linked_companies": 1
}
401Missing, invalid, revoked or expired bearer token. Error
429Rate limit reached. Error
503Temporarily unavailable (maintenance, external provider down). A 503 always carries a code. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/bridge/ping" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/bridge/ping', [
    'headers' => [
        'Accept' => 'application/json',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/bridge/ping", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/bridge/ping",
    headers={
        "Accept": "application/json",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None
GET/v1/bridge/shops/{token}/statusSynchronisation status of a Novadesko shop Public 60 / 1 min

Shown on the integration page of Novadesko. Reserved to the Novadesko platform (shared secret).

Public endpoint: no bearer token.

Rate limit: 60 requests per minute (429 beyond, see Retry-After).

Operation id bridge.shop-status

Path parameters

NameTypeDescription
token requiredstringToken of the Novadesko shop.
e.g. shp_8fK2mQ

Headers

NameTypeDescription
X-Novafisko-Secret requiredstringShared secret of the bridge.

Responses

200OK

Response headers X-RateLimit-Limit X-RateLimit-Remaining

application/json

Schema object
  • okboolean
  • linkedboolean
  • companyobject
  • firmobject
  • synced_atstring <date-time> | null
  • documentsobject
    Properties
    • totalinteger
    • pendinginteger
    • bookedinteger
    • ignoredinteger
    • by_typeobject
  • bank_transactionsinteger
  • fixed_assetsinteger
  • journal_entriesinteger
  • correctionsobject
    Properties
    • totalinteger
    • recentobject[]
  • app_urlstring <uri>
Example
{
    "ok": true,
    "linked": true,
    "company": {},
    "firm": {},
    "synced_at": "2026-03-15T09:41:00+00:00",
    "documents": {
        "total": 1,
        "pending": 1,
        "booked": 1,
        "ignored": 1,
        "by_type": {}
    },
    "bank_transactions": 1,
    "fixed_assets": 1,
    "journal_entries": 1,
    "corrections": {
        "total": 1,
        "recent": [
            {}
        ]
    },
    "app_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC"
}
401Missing, invalid, revoked or expired bearer token. Error
404Unknown resource, or resource the user has no access to (a company file the user cannot see answers 404, never 403). Error
429Rate limit reached. Error

Request sample

curl -X GET "https://api.novafisko.com/v1/bridge/shops/shp_8fK2mQ/status" \
  -H "Accept: application/json"
<?php

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.novafisko.com/v1/bridge/shops/shp_8fK2mQ/status', [
    'headers' => [
        'Accept' => 'application/json',
    ],
]);

$data = json_decode((string) $response->getBody(), true);
const response = await fetch("https://api.novafisko.com/v1/bridge/shops/shp_8fK2mQ/status", {
  method: "GET",
  headers: {
    "Accept": "application/json",
  },
});

if (!response.ok) {
  const error = await response.json();
  throw new Error(error.code ?? error.message);
}
const data = response.status === 204 ? null : await response.json();
import os
import requests

response = requests.get(
    "https://api.novafisko.com/v1/bridge/shops/shp_8fK2mQ/status",
    headers={
        "Accept": "application/json",
    },
    timeout=30,
)
response.raise_for_status()
data = response.json() if response.content else None

Webhook events

Events POSTed to the webhook endpoints of the firm. Every delivery is signed (X-Novafisko-Signature header).

eventdocument.importedA document entered the company file (Novadesko synchronisation or document importer).

A document entered the company file (Novadesko synchronisation or document importer).

Headers

NameTypeDescription
X-Novafisko-Signature requiredstringt=<unix timestamp>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Compare in constant time and refuse timestamps older than five minutes.
e.g. t=1791189214,v1=5d2f0c9a7b6e4d1f8a3c2b1e0f9d8c7b6a5e4d3c2b1a0f9e8d7c6b5a4f3e2d1c
X-Novafisko-Event requiredstringEvent name.
e.g. document.imported
X-Novafisko-Delivery requiredstringId of the delivery (stable across retries).
e.g. 1871

Payload

Schema WebhookEvent

{
    "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "document.imported",
    "api_version": "v1",
    "created_at": "2026-10-05T08:21:48Z",
    "firm": {
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "company": {
        "public_token": "XBVD5O1L29HC",
        "name": "Le Comptoir Montois SRL"
    },
    "data": {
        "id": 87,
        "source": "novafisko",
        "origin": "novafisko",
        "type": "purchases",
        "direction": "purchase",
        "is_credit_note": false,
        "number": "F-2026-0412",
        "document_date": "2026-03-15",
        "due_date": "2026-04-14",
        "third_party_id": 18,
        "third_party_name": "Brasserie Dubuisson SA",
        "third_party_vat": "BE0402531376",
        "currency": "EUR",
        "amount_net": "542.00",
        "amount_vat": "113.82",
        "amount_gross": "655.82",
        "status": "pending",
        "journal_entry_id": null
    }
}

Any 2xx answer within 10 seconds acknowledges the delivery. Anything else is retried with an exponential backoff (1, 2, 4, 8, 16, 32 and 64 minutes): 8 attempts, then the delivery is failed.

eventdocument.bookedA document was booked to an entry.

A document was booked to an entry.

Headers

NameTypeDescription
X-Novafisko-Signature requiredstringt=<unix timestamp>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Compare in constant time and refuse timestamps older than five minutes.
e.g. t=1791189214,v1=5d2f0c9a7b6e4d1f8a3c2b1e0f9d8c7b6a5e4d3c2b1a0f9e8d7c6b5a4f3e2d1c
X-Novafisko-Event requiredstringEvent name.
e.g. document.booked
X-Novafisko-Delivery requiredstringId of the delivery (stable across retries).
e.g. 1871

Payload

Schema WebhookEvent

{
    "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "document.booked",
    "api_version": "v1",
    "created_at": "2026-10-05T08:21:48Z",
    "firm": {
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "company": {
        "public_token": "XBVD5O1L29HC",
        "name": "Le Comptoir Montois SRL"
    },
    "data": {
        "id": 87,
        "source": "novafisko",
        "origin": "novafisko",
        "type": "purchases",
        "direction": "purchase",
        "is_credit_note": false,
        "number": "F-2026-0412",
        "document_date": "2026-03-15",
        "due_date": "2026-04-14",
        "third_party_id": 18,
        "third_party_name": "Brasserie Dubuisson SA",
        "third_party_vat": "BE0402531376",
        "currency": "EUR",
        "amount_net": "542.00",
        "amount_vat": "113.82",
        "amount_gross": "655.82",
        "status": "booked",
        "journal_entry_id": 1284
    }
}

Any 2xx answer within 10 seconds acknowledges the delivery. Anything else is retried with an exponential backoff (1, 2, 4, 8, 16, 32 and 64 minutes): 8 attempts, then the delivery is failed.

evententry.postedAn entry was posted.

An entry was posted.

Headers

NameTypeDescription
X-Novafisko-Signature requiredstringt=<unix timestamp>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Compare in constant time and refuse timestamps older than five minutes.
e.g. t=1791189214,v1=5d2f0c9a7b6e4d1f8a3c2b1e0f9d8c7b6a5e4d3c2b1a0f9e8d7c6b5a4f3e2d1c
X-Novafisko-Event requiredstringEvent name.
e.g. entry.posted
X-Novafisko-Delivery requiredstringId of the delivery (stable across retries).
e.g. 1871

Payload

Schema WebhookEvent

{
    "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "entry.posted",
    "api_version": "v1",
    "created_at": "2026-10-05T08:21:48Z",
    "firm": {
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "company": {
        "public_token": "XBVD5O1L29HC",
        "name": "Le Comptoir Montois SRL"
    },
    "data": {
        "id": 1284,
        "reference": "ACH 2026/000412",
        "journal_code": "ACH",
        "fiscal_year_code": "2026",
        "number": 412,
        "entry_date": "2026-03-15",
        "due_date": "2026-04-14",
        "label": "Facture Brasserie Dubuisson SA",
        "document_reference": "F-2026-0412",
        "status": "posted",
        "origin": "manual",
        "third_party_id": 18,
        "total_debit": "655.82",
        "total_credit": "655.82",
        "lines_count": 4,
        "reversed_entry_id": null,
        "reversed_by_entry_id": null
    }
}

Any 2xx answer within 10 seconds acknowledges the delivery. Anything else is retried with an exponential backoff (1, 2, 4, 8, 16, 32 and 64 minutes): 8 attempts, then the delivery is failed.

evententry.reversedAn entry was reversed; `reversed_by_entry_id` is the reversal entry.

An entry was reversed; reversed_by_entry_id is the reversal entry.

Headers

NameTypeDescription
X-Novafisko-Signature requiredstringt=<unix timestamp>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Compare in constant time and refuse timestamps older than five minutes.
e.g. t=1791189214,v1=5d2f0c9a7b6e4d1f8a3c2b1e0f9d8c7b6a5e4d3c2b1a0f9e8d7c6b5a4f3e2d1c
X-Novafisko-Event requiredstringEvent name.
e.g. entry.reversed
X-Novafisko-Delivery requiredstringId of the delivery (stable across retries).
e.g. 1871

Payload

Schema WebhookEvent

{
    "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "entry.reversed",
    "api_version": "v1",
    "created_at": "2026-10-05T08:21:48Z",
    "firm": {
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "company": {
        "public_token": "XBVD5O1L29HC",
        "name": "Le Comptoir Montois SRL"
    },
    "data": {
        "id": 1284,
        "reference": "ACH 2026/000412",
        "journal_code": "ACH",
        "fiscal_year_code": "2026",
        "number": 412,
        "entry_date": "2026-03-15",
        "due_date": "2026-04-14",
        "label": "Facture Brasserie Dubuisson SA",
        "document_reference": "F-2026-0412",
        "status": "reversed",
        "origin": "manual",
        "third_party_id": 18,
        "total_debit": "655.82",
        "total_credit": "655.82",
        "lines_count": 4,
        "reversed_entry_id": null,
        "reversed_by_entry_id": 1301
    }
}

Any 2xx answer within 10 seconds acknowledges the delivery. Anything else is retried with an exponential backoff (1, 2, 4, 8, 16, 32 and 64 minutes): 8 attempts, then the delivery is failed.

eventbank.transaction_importedA bank transaction was imported (one event per transaction).

A bank transaction was imported (one event per transaction).

Headers

NameTypeDescription
X-Novafisko-Signature requiredstringt=<unix timestamp>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Compare in constant time and refuse timestamps older than five minutes.
e.g. t=1791189214,v1=5d2f0c9a7b6e4d1f8a3c2b1e0f9d8c7b6a5e4d3c2b1a0f9e8d7c6b5a4f3e2d1c
X-Novafisko-Event requiredstringEvent name.
e.g. bank.transaction_imported
X-Novafisko-Delivery requiredstringId of the delivery (stable across retries).
e.g. 1871

Payload

Schema WebhookEvent

{
    "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "bank.transaction_imported",
    "api_version": "v1",
    "created_at": "2026-10-05T08:21:48Z",
    "firm": {
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "company": {
        "public_token": "XBVD5O1L29HC",
        "name": "Le Comptoir Montois SRL"
    },
    "data": {
        "id": 951,
        "source": "novadesko",
        "account_iban": "BE68539007547034",
        "value_date": "2026-03-18",
        "amount": "-655.82",
        "currency": "EUR",
        "counterpart_name": "Brasserie Dubuisson SA",
        "counterpart_iban": "BE71096123456769",
        "communication": "F-2026-0412",
        "status": "pending"
    }
}

Any 2xx answer within 10 seconds acknowledges the delivery. Anything else is retried with an exponential backoff (1, 2, 4, 8, 16, 32 and 64 minutes): 8 attempts, then the delivery is failed.

eventvat.declaration_validatedA VAT declaration was validated and its settlement entry posted.

A VAT declaration was validated and its settlement entry posted.

Headers

NameTypeDescription
X-Novafisko-Signature requiredstringt=<unix timestamp>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Compare in constant time and refuse timestamps older than five minutes.
e.g. t=1791189214,v1=5d2f0c9a7b6e4d1f8a3c2b1e0f9d8c7b6a5e4d3c2b1a0f9e8d7c6b5a4f3e2d1c
X-Novafisko-Event requiredstringEvent name.
e.g. vat.declaration_validated
X-Novafisko-Delivery requiredstringId of the delivery (stable across retries).
e.g. 1871

Payload

Schema WebhookEvent

{
    "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "vat.declaration_validated",
    "api_version": "v1",
    "created_at": "2026-10-05T08:21:48Z",
    "firm": {
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "company": {
        "public_token": "XBVD5O1L29HC",
        "name": "Le Comptoir Montois SRL"
    },
    "data": {
        "id": 14,
        "period_type": "quarterly",
        "year": 2026,
        "period": 1,
        "label": "1T 2026",
        "starts_on": "2026-01-01",
        "ends_on": "2026-03-31",
        "amount_due": "157.50",
        "amount_refund": "0.00",
        "status": "validated",
        "validated_at": "2026-04-14T09:02:11Z",
        "journal_entry_id": 1420
    }
}

Any 2xx answer within 10 seconds acknowledges the delivery. Anything else is retried with an exponential backoff (1, 2, 4, 8, 16, 32 and 64 minutes): 8 attempts, then the delivery is failed.

eventfiscal_year.closedA fiscal year was closed.

A fiscal year was closed.

Headers

NameTypeDescription
X-Novafisko-Signature requiredstringt=<unix timestamp>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Compare in constant time and refuse timestamps older than five minutes.
e.g. t=1791189214,v1=5d2f0c9a7b6e4d1f8a3c2b1e0f9d8c7b6a5e4d3c2b1a0f9e8d7c6b5a4f3e2d1c
X-Novafisko-Event requiredstringEvent name.
e.g. fiscal_year.closed
X-Novafisko-Delivery requiredstringId of the delivery (stable across retries).
e.g. 1871

Payload

Schema WebhookEvent

{
    "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "fiscal_year.closed",
    "api_version": "v1",
    "created_at": "2026-10-05T08:21:48Z",
    "firm": {
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "company": {
        "public_token": "XBVD5O1L29HC",
        "name": "Le Comptoir Montois SRL"
    },
    "data": {
        "id": 2,
        "code": "2025",
        "starts_on": "2025-01-01",
        "ends_on": "2025-12-31",
        "closed_at": "2026-05-28T14:30:00Z"
    }
}

Any 2xx answer within 10 seconds acknowledges the delivery. Anything else is retried with an exponential backoff (1, 2, 4, 8, 16, 32 and 64 minutes): 8 attempts, then the delivery is failed.

eventpeppol.status_changedThe Peppol registration of a company file changed status.

The Peppol registration of a company file changed status.

Headers

NameTypeDescription
X-Novafisko-Signature requiredstringt=<unix timestamp>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Compare in constant time and refuse timestamps older than five minutes.
e.g. t=1791189214,v1=5d2f0c9a7b6e4d1f8a3c2b1e0f9d8c7b6a5e4d3c2b1a0f9e8d7c6b5a4f3e2d1c
X-Novafisko-Event requiredstringEvent name.
e.g. peppol.status_changed
X-Novafisko-Delivery requiredstringId of the delivery (stable across retries).
e.g. 1871

Payload

Schema WebhookEvent

{
    "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "peppol.status_changed",
    "api_version": "v1",
    "created_at": "2026-10-05T08:21:48Z",
    "firm": {
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "company": {
        "public_token": "XBVD5O1L29HC",
        "name": "Le Comptoir Montois SRL"
    },
    "data": {
        "id": 5,
        "participant_id": "0208:0477472701",
        "full_id": "iso6523-actorid-upis::0208:0477472701",
        "status": "active",
        "previous_status": "pending",
        "incoming_enabled": true,
        "activated_at": "2026-03-02T10:15:00Z"
    }
}

Any 2xx answer within 10 seconds acknowledges the delivery. Anything else is retried with an exponential backoff (1, 2, 4, 8, 16, 32 and 64 minutes): 8 attempts, then the delivery is failed.

eventthird_party.createdA customer or supplier was created.

A customer or supplier was created.

Headers

NameTypeDescription
X-Novafisko-Signature requiredstringt=<unix timestamp>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Compare in constant time and refuse timestamps older than five minutes.
e.g. t=1791189214,v1=5d2f0c9a7b6e4d1f8a3c2b1e0f9d8c7b6a5e4d3c2b1a0f9e8d7c6b5a4f3e2d1c
X-Novafisko-Event requiredstringEvent name.
e.g. third_party.created
X-Novafisko-Delivery requiredstringId of the delivery (stable across retries).
e.g. 1871

Payload

Schema WebhookEvent

{
    "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "third_party.created",
    "api_version": "v1",
    "created_at": "2026-10-05T08:21:48Z",
    "firm": {
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "company": {
        "public_token": "XBVD5O1L29HC",
        "name": "Le Comptoir Montois SRL"
    },
    "data": {
        "id": 18,
        "type": "supplier",
        "code": "DUBUISSON",
        "name": "Brasserie Dubuisson SA",
        "vat_number": "BE0402531376",
        "enterprise_number": "0402531376",
        "country": "BE",
        "email": "compta@dubuisson.example",
        "peppol_identifier": "0208:0402531376",
        "peppol_registered": true
    }
}

Any 2xx answer within 10 seconds acknowledges the delivery. Anything else is retried with an exponential backoff (1, 2, 4, 8, 16, 32 and 64 minutes): 8 attempts, then the delivery is failed.

eventthird_party.updatedA customer or supplier was updated; `changed` lists the columns.

A customer or supplier was updated; changed lists the columns.

Headers

NameTypeDescription
X-Novafisko-Signature requiredstringt=<unix timestamp>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Compare in constant time and refuse timestamps older than five minutes.
e.g. t=1791189214,v1=5d2f0c9a7b6e4d1f8a3c2b1e0f9d8c7b6a5e4d3c2b1a0f9e8d7c6b5a4f3e2d1c
X-Novafisko-Event requiredstringEvent name.
e.g. third_party.updated
X-Novafisko-Delivery requiredstringId of the delivery (stable across retries).
e.g. 1871

Payload

Schema WebhookEvent

{
    "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "third_party.updated",
    "api_version": "v1",
    "created_at": "2026-10-05T08:21:48Z",
    "firm": {
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "company": {
        "public_token": "XBVD5O1L29HC",
        "name": "Le Comptoir Montois SRL"
    },
    "data": {
        "id": 18,
        "type": "supplier",
        "code": "DUBUISSON",
        "name": "Brasserie Dubuisson SA",
        "vat_number": "BE0402531376",
        "enterprise_number": "0402531376",
        "country": "BE",
        "email": "facturation@dubuisson.example",
        "peppol_identifier": "0208:0402531376",
        "peppol_registered": true,
        "changed": [
            "email"
        ]
    }
}

Any 2xx answer within 10 seconds acknowledges the delivery. Anything else is retried with an exponential backoff (1, 2, 4, 8, 16, 32 and 64 minutes): 8 attempts, then the delivery is failed.

eventwebhook.testTest event sent by `POST /v1/firms/{firm}/webhooks/{webhook}/test`; `company` is null.

Test event sent by POST /v1/firms/{firm}/webhooks/{webhook}/test; company is null.

Headers

NameTypeDescription
X-Novafisko-Signature requiredstringt=<unix timestamp>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Compare in constant time and refuse timestamps older than five minutes.
e.g. t=1791189214,v1=5d2f0c9a7b6e4d1f8a3c2b1e0f9d8c7b6a5e4d3c2b1a0f9e8d7c6b5a4f3e2d1c
X-Novafisko-Event requiredstringEvent name.
e.g. webhook.test
X-Novafisko-Delivery requiredstringId of the delivery (stable across retries).
e.g. 1871

Payload

Schema WebhookEvent

{
    "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "webhook.test",
    "api_version": "v1",
    "created_at": "2026-10-05T08:21:48Z",
    "firm": {
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "company": null,
    "data": {
        "message": "Test event from NovaFisko.",
        "webhook_id": 3
    }
}

Any 2xx answer within 10 seconds acknowledges the delivery. Anything else is retried with an exponential backoff (1, 2, 4, 8, 16, 32 and 64 minutes): 8 attempts, then the delivery is failed.

Schemas

Data structures shared by the endpoints. Amounts are decimal strings, dates follow ISO 8601.

schemaAccount
  • idinteger
    e.g. 580
  • company_idinteger
    e.g. 7
  • numberstring
    PCMN account number (2 to 12 digits).
    e.g. 702000
  • labelstring
    e.g. Prestations de services
  • typestring
    asset liability expense income off_balance
  • is_postableboolean
    False for heading accounts.
  • is_reconcilableboolean
    Lettering allowed (customers, suppliers…).
  • purchase_gridinteger | null
    VAT grid of purchases: 81, 82 or 83.
    e.g. 82
  • default_vat_code_idinteger | null
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • deleted_atstring <date-time> | null
    Set while the record is in the recycle bin.
  • deleted_byinteger | null
  • default_vat_codeobject | null
Example
{
    "id": 580,
    "company_id": 7,
    "number": "702000",
    "label": "Prestations de services",
    "type": "asset",
    "is_postable": true,
    "is_reconcilable": true,
    "purchase_grid": 82,
    "default_vat_code_id": 42,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "default_vat_code": {}
}
schemaActivityFeed
  • current_pageinteger
    e.g. 1
  • per_pageinteger
    e.g. 50
  • has_moreboolean
Example
{
    "data": [
        {
            "source": "audit",
            "at": "2026-03-15T09:41:00+00:00",
            "recorded_at": "2026-03-15T09:41:00+00:00",
            "user": null,
            "action": "entry.posted",
            "action_label": "Écriture validée",
            "subject_type": "string",
            "subject_id": 42,
            "subject_label": "string",
            "origin": "string",
            "device_name": "MacBook de Claire",
            "revision_id": 42,
            "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
            "company_id": 7,
            "changed_fields": [
                "string"
            ],
            "company": {
                "token": "XBVD5O1L29HC",
                "name": "Le Comptoir Montois SRL"
            }
        }
    ],
    "current_page": 1,
    "per_page": 50,
    "has_more": true
}
schemaActivityRow
  • sourcestring
    audit revision
  • atstring <date-time>
  • recorded_atstring <date-time>
  • userobject | null
  • actionstring
    e.g. entry.posted
  • action_labelstring
    e.g. Écriture validée
  • subject_typestring | null
  • subject_idinteger | null
  • subject_labelstring | null
  • originstring | null
  • device_namestring | null
  • revision_idinteger | null
  • operation_idstring | null
  • company_idinteger | null
  • changed_fieldsstring[]
  • companyobject | null
    Firm feed only.
    Properties
    • tokenstring
    • namestring
Example
{
    "source": "audit",
    "at": "2026-03-15T09:41:00+00:00",
    "recorded_at": "2026-03-15T09:41:00+00:00",
    "user": {
        "id": 12,
        "name": "Claire Dumont"
    },
    "action": "entry.posted",
    "action_label": "Écriture validée",
    "subject_type": "string",
    "subject_id": 42,
    "subject_label": "string",
    "origin": "string",
    "device_name": "MacBook de Claire",
    "revision_id": 42,
    "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "company_id": 7,
    "changed_fields": [
        "string"
    ],
    "company": {
        "token": "XBVD5O1L29HC",
        "name": "Le Comptoir Montois SRL"
    }
}
schemaAnalyticCode
  • idinteger
    e.g. 2
  • company_idinteger
  • axisstring
    cost_center project
  • codestring
    e.g. SALLE
  • labelstring
    e.g. Salle
  • is_activeboolean
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • deleted_atstring <date-time> | null
    Set while the record is in the recycle bin.
  • deleted_byinteger | null
Example
{
    "id": 2,
    "company_id": 7,
    "axis": "cost_center",
    "code": "SALLE",
    "label": "Salle",
    "is_active": true,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1
}
schemaBankRule
  • idinteger
    e.g. 6
  • company_idinteger
  • namestring
    e.g. Frais bancaires
  • fieldstring
    counterpart_name counterpart_iban communication description any
  • operatorstring
    contains equals starts
  • patternstring
    e.g. frais de tenue
  • directionstring
    in out any
  • account_idinteger
    e.g. 517
  • third_party_idinteger | null
  • labelstring | null
  • priorityinteger
    e.g. 100
  • is_activeboolean
  • applied_countinteger
    e.g. 14
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • deleted_atstring <date-time> | null
    Set while the record is in the recycle bin.
  • deleted_byinteger | null
  • accountobject
    Properties
    • idinteger
      Id
      e.g. 580
    • numberstring
      Account number
      e.g. 702000
    • labelstring
      Label
      e.g. Prestations de services
  • third_partyobject | null
Example
{
    "id": 6,
    "company_id": 7,
    "name": "Frais bancaires",
    "field": "counterpart_name",
    "operator": "contains",
    "pattern": "frais de tenue",
    "direction": "in",
    "account_id": 517,
    "third_party_id": 18,
    "label": "Facture Brasserie Dubuisson",
    "priority": 100,
    "is_active": true,
    "applied_count": 14,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "third_party": {}
}
schemaBankTransaction
  • idinteger
    e.g. 951
  • company_idinteger
    e.g. 7
  • sourcestring
    e.g. novadesko
  • external_idstring | null
  • account_ibanstring
    e.g. BE68539007547034
  • account_bankstring | null
  • journal_idinteger | null
    e.g. 7
  • amountstring <decimal>
    Positive = money in, negative = money out.
    e.g. 1210.00
  • currencystring
    e.g. EUR
  • value_datestring <date-time>
    e.g. 2026-03-18T00:00:00.000000Z
  • execution_datestring <date-time> | null
  • counterpart_namestring | null
    e.g. ACME SA
  • counterpart_ibanstring | null
  • communicationstring | null
    e.g. +++000/0000/00101+++
  • descriptionstring | null
  • statusstring
    pending booked ignored
  • journal_entry_idinteger | null
  • matched_journal_entry_idinteger | null
    Invoice proposed by the matching.
  • match_confidencestring | null
    high, medium or low.
    e.g. high
  • match_reasonstring | null
    structured_communication, novadesko_link, amount_and_third_party, rule…
    e.g. structured_communication
  • matched_atstring <date-time> | null
  • booked_account_idinteger | null
  • matched_rule_idinteger | null
  • synced_atstring <date-time> | null
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • journalobject | null
  • linksobject[]
  • matched_entryobject | null
  • booked_accountobject | null
  • matched_ruleobject | null
  • journal_entryobject | null
Example
{
    "id": 951,
    "company_id": 7,
    "source": "novadesko",
    "external_id": "string",
    "account_iban": "BE68539007547034",
    "account_bank": "string",
    "journal_id": 7,
    "amount": "1210.00",
    "currency": "EUR",
    "value_date": "2026-03-18T00:00:00.000000Z",
    "execution_date": "2026-03-15T09:41:00+00:00",
    "counterpart_name": "ACME SA",
    "counterpart_iban": "string",
    "communication": "+++000/0000/00101+++",
    "description": "Description",
    "status": "pending",
    "journal_entry_id": 1284,
    "matched_journal_entry_id": 42,
    "match_confidence": "high",
    "match_reason": "structured_communication",
    "matched_at": "2026-03-15T09:41:00+00:00",
    "booked_account_id": 42,
    "matched_rule_id": 42,
    "synced_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal": {},
    "links": [
        {}
    ],
    "matched_entry": {},
    "booked_account": {},
    "matched_rule": {},
    "journal_entry": {}
}
schemaBudget
  • idinteger
  • company_idinteger
  • fiscal_year_idinteger
  • scenariostring
    e.g. default
  • account_idinteger
  • cost_center_idinteger | null
  • period_numberinteger
    e.g. 3
  • amountstring <decimal>
    e.g. 1500.00
  • accountobject
    Properties
    • idinteger
      Id
      e.g. 580
    • numberstring
      Account number
      e.g. 702000
    • labelstring
      Label
      e.g. Prestations de services
Example
{
    "id": 42,
    "company_id": 7,
    "fiscal_year_id": 2,
    "scenario": "default",
    "account_id": 580,
    "cost_center_id": 42,
    "period_number": 3,
    "amount": "1500.00",
    "account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    }
}
schemaCodaFile
  • idinteger
    e.g. 31
  • company_idinteger
  • sourcestring
    e.g. novadesko
  • external_idstring | null
  • filenamestring
    e.g. CODA_2026_031.cod
  • source_urlstring <uri> | null
  • account_ibanstring
    e.g. BE68539007547034
  • account_bankstring | null
  • journal_idinteger | null
  • statement_numberstring | null
    e.g. 031
  • sequencestring | null
  • opening_balancestring <decimal> | null
    e.g. 18420.11
  • closing_balancestring <decimal> | null
    e.g. 19630.11
  • period_fromstring <date-time> | null
  • period_tostring <date-time> | null
  • transactions_countinteger
    e.g. 12
  • statusstring
    e.g. imported
  • synced_atstring <date-time> | null
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • journalobject | null
Example
{
    "id": 31,
    "company_id": 7,
    "source": "novadesko",
    "external_id": "string",
    "filename": "CODA_2026_031.cod",
    "source_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "account_iban": "BE68539007547034",
    "account_bank": "string",
    "journal_id": 3,
    "statement_number": "031",
    "sequence": "string",
    "opening_balance": "18420.11",
    "closing_balance": "19630.11",
    "period_from": "2026-03-15T09:41:00+00:00",
    "period_to": "2026-03-15T09:41:00+00:00",
    "transactions_count": 12,
    "status": "imported",
    "synced_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "journal": {}
}
schemaCompanyCompany file (dossier). Addressed everywhere by its `public_token`.

Company file (dossier). Addressed everywhere by its public_token.

  • idinteger
    e.g. 7
  • public_tokenstring
    e.g. XBVD5O1L29HC
  • firm_idinteger | null
    e.g. 3
  • codestring | null
    e.g. COMPTOIR
  • namestring
    e.g. Le Comptoir Montois SRL
  • legal_formstring | null
    e.g. SRL
  • legal_form_codestring | null
    KBO / BCE legal form code.
    e.g. 610
  • enterprise_numberstring | null
    e.g. 0477472701
  • vat_numberstring | null
    e.g. BE0477472701
  • country_packstring
    BE FR LU
  • vat_regimestring
    monthly quarterly franchise exempt unit
  • currencystring
    e.g. EUR
  • localestring
    fr nl en de
  • addressstring | null
    e.g. Grand-Place 14, 7000 Mons
  • streetstring | null
    Street
    e.g. Grand-Place
  • house_numberstring | null
    Number
    e.g. 14
  • boxstring | null
    Box
  • postal_codestring | null
    Postal code
    e.g. 7000
  • citystring | null
    City
    e.g. Mons
  • countrystring | null
    ISO 3166-1 alpha-2
    e.g. BE
  • latitudestring | null
    e.g. 50.4541000
  • longitudestring | null
    e.g. 3.9523000
  • nace_codesobject[] | null
    Properties
    • codestring
      e.g. 56111
    • classificationstring
      MAIN SECO ANCI
  • main_nace_codestring | null
    e.g. 56111
  • company_sheet_atstring <date-time> | null
  • logo_urlstring <uri> | null
  • icon_urlstring <uri> | null
  • fiscal_year_startstring <date> | null
  • fiscal_year_endstring <date> | null
  • is_activeboolean
  • is_demoboolean
    True for the company files of the demo firm.
    e.g. false
  • sourcestring
    manual novadesko
  • external_idstring | null
  • synced_atstring <date-time> | null
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • deleted_atstring <date-time> | null
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • journal_entries_countinteger
    Present on list / show.
    e.g. 1284
  • firmobject
    Properties
    • idinteger
      e.g. 3
    • public_tokenstring
      e.g. NDTQVQU4AUAV
    • namestring
      e.g. Fiduciaire Dumont & Associés
  • fiscal_yearsFiscalYear[]
  • journalsJournal[]
Example
{
    "id": 7,
    "public_token": "XBVD5O1L29HC",
    "firm_id": 3,
    "code": "COMPTOIR",
    "name": "Le Comptoir Montois SRL",
    "legal_form": "SRL",
    "legal_form_code": "610",
    "enterprise_number": "0477472701",
    "vat_number": "BE0477472701",
    "country_pack": "BE",
    "vat_regime": "monthly",
    "currency": "EUR",
    "locale": "fr",
    "address": "Grand-Place 14, 7000 Mons",
    "street": "Grand-Place",
    "house_number": "14",
    "box": "string",
    "postal_code": "7000",
    "city": "Mons",
    "country": "BE",
    "latitude": "50.4541000",
    "longitude": "3.9523000",
    "nace_codes": [
        {
            "code": "56111",
            "classification": "MAIN"
        }
    ],
    "main_nace_code": "56111",
    "company_sheet_at": "2026-03-15T09:41:00+00:00",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "icon_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "fiscal_year_start": "2026-03-15",
    "fiscal_year_end": "2026-03-15",
    "settings": {
        "vat": {
            "administration_cell": "string",
            "structured_communication": "000000000101",
            "directorate_number": "string",
            "office_number": "string",
            "declarant": {
                "applicable": false,
                "company_name": "string",
                "signatory_1": "string",
                "signatory_1_title": "string",
                "signatory_2": "string",
                "signatory_2_title": "string",
                "phone": "+32 65 31 42 18",
                "fax": "string",
                "email": "claire.dumont@fiduciaire-dumont.be",
                "language": "fr"
            },
            "sender_281_50": {
                "name": "Le Comptoir Montois SRL",
                "enterprise_number": "0477472701",
                "address": "Grand-Place 14",
                "phone": "+32 65 31 42 18",
                "email": "claire.dumont@fiduciaire-dumont.be"
            },
            "filer": {
                "quality": "company",
                "name": "Le Comptoir Montois SRL",
                "enterprise_number": "0477472701",
                "phone": "+32 65 31 42 18",
                "email": "claire.dumont@fiduciaire-dumont.be"
            }
        },
        "legal": {
            "rpm_district": "Hainaut, division Mons"
        },
        "annual_accounts": {
            "scheme": "abbreviated",
            "general_meeting_date": "2026-03-15",
            "directors": "string",
            "valuation_rules": "string"
        },
        "auto_entries": {
            "vat": {
                "payable_account": "451000",
                "receivable_account": "411000",
                "correction_payable_account": "string",
                "correction_receivable_account": "string",
                "journal_id": 3
            },
            "invoices_to_receive": {
                "supplier_account": "444000",
                "customer_account": "404000",
                "journal_id": 3
            },
            "reconciliation_difference": {
                "expense_account": "657000",
                "income_account": "757000",
                "max_amount": 1
            },
            "transfers": {
                "transit_account": "580000",
                "journal_id": 3
            }
        },
        "history": {
            "trash_retention_days": 90
        }
    },
    "is_active": true,
    "is_demo": false,
    "source": "manual",
    "external_id": "string",
    "synced_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal_entries_count": 1284,
    "firm": {
        "id": 3,
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "fiscal_years": [
        {
            "id": 2,
            "company_id": 7,
            "code": "2026",
            "starts_on": "2026-01-01T00:00:00.000000Z",
            "ends_on": "2026-12-31T00:00:00.000000Z",
            "is_closed": false,
            "closed_at": "2026-03-15T09:41:00+00:00",
            "closed_by": 1,
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "periods": [
                {
                    "id": 16,
                    "fiscal_year_id": 2,
                    "number": 3,
                    "label": "Mars 2026",
                    "starts_on": "2026-03-15T09:41:00+00:00",
                    "ends_on": "2026-03-15T09:41:00+00:00",
                    "is_locked": false,
                    "locked_at": "2026-03-15T09:41:00+00:00",
                    "lock_version": 3,
                    "version": 3
                }
            ]
        }
    ],
    "journals": [
        {
            "id": 3,
            "company_id": 7,
            "code": "VEN",
            "label": "Ventes",
            "type": "purchase",
            "control_account_id": 42,
            "iban": "BE68539007547034",
            "bic": "GEBABEBB",
            "last_number": 412,
            "is_active": true,
            "is_default": true,
            "description": "Description",
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "deleted_at": "2026-03-15T09:41:00+00:00",
            "deleted_by": 1,
            "entries_count": 412,
            "control_account": null,
            "rules": [
                {
                    "id": 4,
                    "company_id": 7,
                    "journal_id": 3,
                    "direction": "sale",
                    "match_field": "payment_provider",
                    "match_value": "TK",
                    "priority": 100,
                    "is_active": true,
                    "created_at": "2026-03-15T09:41:00+00:00",
                    "updated_at": "2026-03-15T09:41:00+00:00",
                    "lock_version": 3,
                    "version": 3,
                    "deleted_at": "2026-03-15T09:41:00+00:00",
                    "deleted_by": 1,
                    "journal": {
                        "id": 3,
                        "code": "VEN",
                        "label": "Ventes",
                        "type": "sale"
                    }
                }
            ]
        }
    ]
}
schemaCompanySettingsResolved settings of the company file (country pack defaults merged with the saved values).

Resolved settings of the company file (country pack defaults merged with the saved values).

  • vatobject
    Properties
    • administration_cellstring | null
    • structured_communicationstring | null
    • directorate_numberstring | null
    • office_numberstring | null
    • declarantobject
      Properties
      • applicableboolean
        e.g. false
      • company_namestring | null
      • signatory_1string | null
      • signatory_1_titlestring | null
      • signatory_2string | null
      • signatory_2_titlestring | null
      • phonestring | null
      • faxstring | null
      • emailstring <email> | null
      • languagestring
        fr nl en de
    • sender_281_50object
      Properties
      • namestring | null
      • enterprise_numberstring | null
      • addressstring | null
      • phonestring | null
      • emailstring <email> | null
    • filerobject
      Properties
      • qualitystring
        company accountant
      • namestring | null
      • enterprise_numberstring | null
      • phonestring | null
      • emailstring <email> | null
  • legalobject
    Properties
    • rpm_districtstring | null
      RPM / RPR district printed on legal documents.
      e.g. Hainaut, division Mons
  • annual_accountsobject
    Properties
    • schemestring
      abbreviated micro
    • general_meeting_datestring <date> | null
    • directorsstring | null
    • valuation_rulesstring | null
  • auto_entriesobject
    Properties
    • vatobject
      Properties
      • payable_accountstring
        e.g. 451000
      • receivable_accountstring
        e.g. 411000
      • correction_payable_accountstring | null
      • correction_receivable_accountstring | null
      • journal_idinteger | null
    • invoices_to_receiveobject
      Properties
      • supplier_accountstring
        e.g. 444000
      • customer_accountstring
        e.g. 404000
      • journal_idinteger | null
    • reconciliation_differenceobject
      Properties
      • expense_accountstring
        e.g. 657000
      • income_accountstring
        e.g. 757000
      • max_amountnumber
        e.g. 1
    • transfersobject
      Properties
      • transit_accountstring
        e.g. 580000
      • journal_idinteger | null
  • historyobject
    Properties
    • trash_retention_daysinteger
      e.g. 90
Example
{
    "vat": {
        "administration_cell": "string",
        "structured_communication": "000000000101",
        "directorate_number": "string",
        "office_number": "string",
        "declarant": {
            "applicable": false,
            "company_name": "string",
            "signatory_1": "string",
            "signatory_1_title": "string",
            "signatory_2": "string",
            "signatory_2_title": "string",
            "phone": "+32 65 31 42 18",
            "fax": "string",
            "email": "claire.dumont@fiduciaire-dumont.be",
            "language": "fr"
        },
        "sender_281_50": {
            "name": "Le Comptoir Montois SRL",
            "enterprise_number": "0477472701",
            "address": "Grand-Place 14",
            "phone": "+32 65 31 42 18",
            "email": "claire.dumont@fiduciaire-dumont.be"
        },
        "filer": {
            "quality": "company",
            "name": "Le Comptoir Montois SRL",
            "enterprise_number": "0477472701",
            "phone": "+32 65 31 42 18",
            "email": "claire.dumont@fiduciaire-dumont.be"
        }
    },
    "legal": {
        "rpm_district": "Hainaut, division Mons"
    },
    "annual_accounts": {
        "scheme": "abbreviated",
        "general_meeting_date": "2026-03-15",
        "directors": "string",
        "valuation_rules": "string"
    },
    "auto_entries": {
        "vat": {
            "payable_account": "451000",
            "receivable_account": "411000",
            "correction_payable_account": "string",
            "correction_receivable_account": "string",
            "journal_id": 3
        },
        "invoices_to_receive": {
            "supplier_account": "444000",
            "customer_account": "404000",
            "journal_id": 3
        },
        "reconciliation_difference": {
            "expense_account": "657000",
            "income_account": "757000",
            "max_amount": 1
        },
        "transfers": {
            "transit_account": "580000",
            "journal_id": 3
        }
    },
    "history": {
        "trash_retention_days": 90
    }
}
schemaCompanySheetNormalised company sheet (CompanySearch for BE / FR, VIES elsewhere).

Normalised company sheet (CompanySearch for BE / FR, VIES elsewhere).

  • identifierstring
    e.g. 0477472701
  • enterprise_numberstring | null
  • vat_numberstring | null
    e.g. BE0477472701
  • namestring
    e.g. Le Comptoir Montois
  • legal_formstring | null
    e.g. SRL
  • legal_form_codestring | null
    e.g. 610
  • statusstring | null
    e.g. active
  • start_datestring <date> | null
  • addressobject
    Properties
    • streetstring | null
      Street
      e.g. Grand-Place
    • house_numberstring | null
      Number
      e.g. 14
    • boxstring | null
      Box
    • postal_codestring | null
      Postal code
      e.g. 7000
    • citystring | null
      City
      e.g. Mons
    • countrystring | null
      ISO 3166-1 alpha-2
      e.g. BE
  • address_linestring | null
  • latitudenumber | null
  • longitudenumber | null
  • nace_codesobject[]
    Properties
    • codestring
      e.g. 56111
    • classificationstring
      MAIN SECO ANCI
    • labelstring | null
  • main_nace_codestring | null
  • emailstring | null
  • phonestring | null
  • websitestring | null
  • sourcestring
    e.g. companysearch
  • fetched_atstring <date-time> | null
  • mapobject
    Properties
    • querystring
      Address used for the map
      e.g. Grand-Place 14, 7000 Mons, Belgique
    • apple_urlstring <uri>
    • google_urlstring <uri>
    • static_urlstring <uri> | null
    • latitudenumber | null
    • longitudenumber | null
Example
{
    "identifier": "0477472701",
    "enterprise_number": "0477472701",
    "vat_number": "BE0477472701",
    "name": "Le Comptoir Montois",
    "legal_form": "SRL",
    "legal_form_code": "610",
    "status": "active",
    "start_date": "2026-03-15",
    "address": {
        "street": "Grand-Place",
        "house_number": "14",
        "box": "string",
        "postal_code": "7000",
        "city": "Mons",
        "country": "BE"
    },
    "address_line": "string",
    "latitude": 12.5,
    "longitude": 12.5,
    "nace_codes": [
        {
            "code": "56111",
            "classification": "MAIN",
            "label": "Facture Brasserie Dubuisson"
        }
    ],
    "main_nace_code": "string",
    "email": "claire.dumont@fiduciaire-dumont.be",
    "phone": "+32 65 31 42 18",
    "website": "https://www.comptoir-montois.be",
    "source": "companysearch",
    "fetched_at": "2026-03-15T09:41:00+00:00",
    "map": {
        "query": "Grand-Place 14, 7000 Mons, Belgique",
        "apple_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "google_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "static_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "latitude": 12.5,
        "longitude": 12.5
    }
}
schemaDepreciationLine
  • idinteger
  • fixed_asset_idinteger
    e.g. 9
  • yearinteger
    e.g. 2026
  • period_startstring <date-time>
  • period_endstring <date-time>
  • amountstring <decimal>
    e.g. 2269.37
  • cumulative_amountstring <decimal>
    e.g. 2269.37
  • remaining_valuestring <decimal>
    e.g. 10130.63
  • statusstring
    planned booked
  • journal_entry_idinteger | null
  • booked_amountstring <decimal>
    e.g. 0.00
Example
{
    "id": 42,
    "fixed_asset_id": 9,
    "year": 2026,
    "period_start": "2026-03-15T09:41:00+00:00",
    "period_end": "2026-03-15T09:41:00+00:00",
    "amount": "2269.37",
    "cumulative_amount": "2269.37",
    "remaining_value": "10130.63",
    "status": "planned",
    "journal_entry_id": 1284,
    "booked_amount": "0.00"
}
schemaDocumentImportFile uploaded to the document importer and its analysis.

File uploaded to the document importer and its analysis.

  • idinteger
    e.g. 311
  • company_idinteger
    e.g. 7
  • uploaded_byinteger | null
  • batch_idstring <uuid>
    Groups the files of one upload.
  • parent_import_idinteger | null
    ZIP the file was extracted from.
  • original_namestring
    e.g. facture-dubuisson-0412.pdf
  • mimestring
    e.g. application/pdf
  • sizeinteger
    Bytes.
    e.g. 184320
  • file_hashstring
    SHA-256, used to detect duplicates.
  • kindstring
    pdf image xml zip other
  • statusstring
    queued analyzing ready needs_review validated error duplicate expanded
  • progressinteger
    0 to 100.
    e.g. 100
  • stepstring
    upload text ai lines match done
  • enginestring | null
    Engine that read the file.
    e.g. api
  • extractedExtractedDocument | null
  • raw_textstring | null
    Text layer (absent from lists).
  • warningsstring[] | null
  • errorstring | null
  • suggested_third_party_idinteger | null
  • suggested_directionstring | null
  • duplicate_of_import_idinteger | null
  • duplicate_of_document_idinteger | null
  • imported_document_idinteger | null
    Document created by the validation.
  • novadesko_document_idstring | null
  • novadesko_locked_atstring <date-time> | null
  • started_atstring <date-time> | null
  • finished_atstring <date-time> | null
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • deleted_atstring <date-time> | null
    Set while the record is in the recycle bin.
  • deleted_byinteger | null
  • suggested_third_partyobject | null
Example
{
    "id": 311,
    "company_id": 7,
    "uploaded_by": 1,
    "batch_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "parent_import_id": 42,
    "original_name": "facture-dubuisson-0412.pdf",
    "mime": "application/pdf",
    "size": 184320,
    "file_hash": "string",
    "kind": "pdf",
    "status": "queued",
    "progress": 100,
    "step": "upload",
    "engine": "api",
    "extracted": {
        "direction": "purchase",
        "is_credit_note": false,
        "number": "F-2026-0412",
        "document_date": "2026-03-15",
        "due_date": "2026-03-15",
        "currency": "EUR",
        "supplier": {
            "name": "Brasserie Dubuisson SA",
            "vat_number": "BE0402531376",
            "enterprise_number": "0477472701",
            "address": "Grand-Place 14",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE",
            "iban": "BE68539007547034",
            "email": "claire.dumont@fiduciaire-dumont.be"
        },
        "customer": {},
        "amount_net": "507.00",
        "amount_vat": "106.47",
        "amount_gross": "613.47",
        "structured_communication": "000000000101",
        "confidence": 0.93,
        "lines": [
            {
                "description": "Fûts Bush Caractère 20 L",
                "quantity": 6,
                "unit_price": 84.5,
                "tax_rate": 21,
                "amount_net": "507.00",
                "amount_vat": "106.47",
                "account_id": 580,
                "account_number": "604000",
                "vat_code_id": 4,
                "vat_code": "A21"
            }
        ]
    },
    "raw_text": "string",
    "warnings": [
        "string"
    ],
    "error": "string",
    "suggested_third_party_id": 42,
    "suggested_direction": "string",
    "duplicate_of_import_id": 42,
    "duplicate_of_document_id": 42,
    "imported_document_id": 42,
    "novadesko_document_id": "string",
    "novadesko_locked_at": "2026-03-15T09:41:00+00:00",
    "started_at": "2026-03-15T09:41:00+00:00",
    "finished_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "suggested_third_party": {}
}
schemaErrorError envelope. `message` is translated; `code` is a stable machine reason when the refusal has one; `errors`...

Error envelope. message is translated; code is a stable machine reason when the refusal has one; errors maps fields to messages (422).

  • messagestringrequired
    Human-readable message (translated).
    e.g. Le champ date de l'écriture est obligatoire.
  • codestring
    Machine reason (token_ability_missing, session_token_required, demo_mode, conflict, period_locked, company_limit_reached, service_unavailable…).
    e.g. period_locked
  • errorsobject
    Field => list of messages.
Example
{
    "message": "Le champ date de l'écriture est obligatoire.",
    "code": "period_locked",
    "errors": {
        "entry_date": [
            "La période Mars 2026 est verrouillée."
        ]
    }
}
schemaExtractedDocumentData read from an uploaded file (AI extraction or UBL / CII parsing), editable before validation.

Data read from an uploaded file (AI extraction or UBL / CII parsing), editable before validation.

  • directionstring
    purchase sale
  • is_credit_noteboolean
    e.g. false
  • numberstring | null
    e.g. F-2026-0412
  • document_datestring <date> | null
  • due_datestring <date> | null
  • currencystring
    e.g. EUR
  • supplierobject
    Properties
    • namestring | null
      e.g. Brasserie Dubuisson SA
    • vat_numberstring | null
      e.g. BE0402531376
    • enterprise_numberstring | null
    • addressstring | null
    • postal_codestring | null
    • citystring | null
    • countrystring | null
    • ibanstring | null
    • emailstring | null
  • customerobject | null
  • amount_netstring | null
    e.g. 507.00
  • amount_vatstring | null
    e.g. 106.47
  • amount_grossstring | null
    e.g. 613.47
  • structured_communicationstring | null
  • confidencenumber
    0 to 1; below 0.6 the import needs a review.
    e.g. 0.93
  • linesobject[]
    Properties
    • descriptionstring
      e.g. Fûts Bush Caractère 20 L
    • quantitynumber | null
      e.g. 6
    • unit_pricenumber | null
      e.g. 84.5
    • tax_ratenumber | null
      e.g. 21
    • amount_netstring
      e.g. 507.00
    • amount_vatstring | null
      e.g. 106.47
    • account_idinteger | null
      Suggested account.
    • account_numberstring | null
      e.g. 604000
    • vat_code_idinteger | null
    • vat_codestring | null
      e.g. A21
Example
{
    "direction": "purchase",
    "is_credit_note": false,
    "number": "F-2026-0412",
    "document_date": "2026-03-15",
    "due_date": "2026-03-15",
    "currency": "EUR",
    "supplier": {
        "name": "Brasserie Dubuisson SA",
        "vat_number": "BE0402531376",
        "enterprise_number": "0477472701",
        "address": "Grand-Place 14",
        "postal_code": "7000",
        "city": "Mons",
        "country": "BE",
        "iban": "BE68539007547034",
        "email": "claire.dumont@fiduciaire-dumont.be"
    },
    "customer": {},
    "amount_net": "507.00",
    "amount_vat": "106.47",
    "amount_gross": "613.47",
    "structured_communication": "000000000101",
    "confidence": 0.93,
    "lines": [
        {
            "description": "Fûts Bush Caractère 20 L",
            "quantity": 6,
            "unit_price": 84.5,
            "tax_rate": 21,
            "amount_net": "507.00",
            "amount_vat": "106.47",
            "account_id": 580,
            "account_number": "604000",
            "vat_code_id": 4,
            "vat_code": "A21"
        }
    ]
}
schemaFirmAccounting firm (fiduciary) with its team and company files.

Accounting firm (fiduciary) with its team and company files.

  • public_tokenstring
    e.g. NDTQVQU4AUAV
  • namestring
    e.g. Fiduciaire Dumont & Associés
  • enterprise_numberstring | null
    e.g. 0458662817
  • vat_numberstring | null
    e.g. BE0458662817
  • itaa_numberstring | null
    ITAA membership number.
    e.g. 50.123.456
  • itaa_statusstring | null
  • itaa_qualitystring | null
  • addressstring | null
    e.g. Rue de Nimy 52
  • postal_codestring | null
    e.g. 7000
  • citystring | null
    e.g. Mons
  • websitestring | null
  • logo_urlstring <uri> | null
  • is_partnerboolean
  • country_codestring
    e.g. BE
  • localestring
    fr nl en de
  • emailstring <email> | null
  • phonestring | null
  • sourcestring
    local novadesko
  • synced_atstring <date-time> | null
  • can_manageboolean
    True for admins and managers of the firm.
  • membersFirmMember[]
  • companiesobject[]
    Properties
    • public_tokenstring
    • namestring
    • codestring | null
    • icon_urlstring <uri> | null
    • logo_urlstring <uri> | null
    • membersobject[]
      Properties
      • idinteger
      • namestring
        e.g. Thomas Peeters
      • emailstring <email>
      • rolestring
        manager encoder reviewer
      • is_activeboolean
Example
{
    "public_token": "NDTQVQU4AUAV",
    "name": "Fiduciaire Dumont & Associés",
    "enterprise_number": "0458662817",
    "vat_number": "BE0458662817",
    "itaa_number": "50.123.456",
    "itaa_status": "string",
    "itaa_quality": "string",
    "address": "Rue de Nimy 52",
    "postal_code": "7000",
    "city": "Mons",
    "website": "https://www.comptoir-montois.be",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "is_partner": true,
    "country_code": "BE",
    "locale": "fr",
    "email": "claire.dumont@fiduciaire-dumont.be",
    "phone": "+32 65 31 42 18",
    "source": "local",
    "synced_at": "2026-03-15T09:41:00+00:00",
    "can_manage": true,
    "members": [
        {
            "id": 12,
            "name": "Thomas Peeters",
            "email": "thomas.peeters@fiduciaire-dumont.be",
            "auth_source": "local",
            "locale": "fr",
            "role": "admin",
            "is_active": true,
            "all_companies": true,
            "companies": [
                {
                    "public_token": "XBVD5O1L29HC",
                    "name": "Le Comptoir Montois SRL",
                    "code": "COMPTOIR",
                    "role": "manager",
                    "is_active": true
                }
            ]
        }
    ],
    "companies": [
        {
            "public_token": "XBVD5O1L29HC",
            "name": "Le Comptoir Montois SRL",
            "code": "COMPTOIR",
            "icon_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "members": [
                {
                    "id": 42,
                    "name": "Thomas Peeters",
                    "email": "claire.dumont@fiduciaire-dumont.be",
                    "role": "manager",
                    "is_active": true
                }
            ]
        }
    ]
}
schemaFirmMember
  • idinteger
    e.g. 12
  • namestring
    e.g. Thomas Peeters
  • emailstring <email>
    e.g. thomas.peeters@fiduciaire-dumont.be
  • auth_sourcestring
    local novadesko
  • localestring
    fr nl en de
  • rolestring
    admin manager encoder reviewer
  • is_activeboolean
  • all_companiesboolean
    Admins and managers see every company file of the firm.
  • companiesobject[]
    Properties
    • public_tokenstring
    • namestring
    • codestring | null
    • rolestring
      manager encoder reviewer
    • is_activeboolean
Example
{
    "id": 12,
    "name": "Thomas Peeters",
    "email": "thomas.peeters@fiduciaire-dumont.be",
    "auth_source": "local",
    "locale": "fr",
    "role": "admin",
    "is_active": true,
    "all_companies": true,
    "companies": [
        {
            "public_token": "XBVD5O1L29HC",
            "name": "Le Comptoir Montois SRL",
            "code": "COMPTOIR",
            "role": "manager",
            "is_active": true
        }
    ]
}
schemaFiscalYear
  • idinteger
    e.g. 2
  • company_idinteger
    e.g. 7
  • codestring
    e.g. 2026
  • starts_onstring <date-time>
    e.g. 2026-01-01T00:00:00.000000Z
  • ends_onstring <date-time>
    e.g. 2026-12-31T00:00:00.000000Z
  • is_closedboolean
    e.g. false
  • closed_atstring <date-time> | null
  • closed_byinteger | null
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • periodsPeriod[]
Example
{
    "id": 2,
    "company_id": 7,
    "code": "2026",
    "starts_on": "2026-01-01T00:00:00.000000Z",
    "ends_on": "2026-12-31T00:00:00.000000Z",
    "is_closed": false,
    "closed_at": "2026-03-15T09:41:00+00:00",
    "closed_by": 1,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "periods": [
        {
            "id": 16,
            "fiscal_year_id": 2,
            "number": 3,
            "label": "Mars 2026",
            "starts_on": "2026-03-15T09:41:00+00:00",
            "ends_on": "2026-03-15T09:41:00+00:00",
            "is_locked": false,
            "locked_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3
        }
    ]
}
schemaFixedAsset
  • idinteger
    e.g. 9
  • company_idinteger
  • sourcestring
    manual novadesko
  • external_idstring | null
  • referencestring | null
    e.g. IMM-2026-003
  • namestring
    e.g. Four mixte Rational
  • categorystring
    it_equipment vehicle furniture machinery building software other
  • asset_groupstring | null
  • asset_account_idinteger | null
  • depreciation_account_idinteger | null
  • expense_account_idinteger | null
  • imported_document_idinteger | null
  • acquisition_datestring <date-time>
    e.g. 2026-02-01T00:00:00.000000Z
  • acquisition_coststring <decimal>
    e.g. 12400.00
  • residual_valuestring <decimal>
    e.g. 0.00
  • useful_life_yearsinteger
    e.g. 5
  • methodstring
    linear declining
  • prorata_temporisboolean
  • start_datestring <date-time>
  • statusstring
    active fully_depreciated disposed
  • notesstring | null
  • disposed_onstring <date-time> | null
  • disposal_pricestring <decimal> | null
  • disposal_entry_idinteger | null
  • investment_deduction_pctstring <decimal> | null
  • investment_deduction_spreadboolean
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • deleted_atstring <date-time> | null
    Set while the record is in the recycle bin.
  • deleted_byinteger | null
  • asset_accountobject
    Properties
    • idinteger
      Id
      e.g. 580
    • numberstring
      Account number
      e.g. 702000
    • labelstring
      Label
      e.g. Prestations de services
  • depreciation_accountobject
    Properties
    • idinteger
      Id
      e.g. 580
    • numberstring
      Account number
      e.g. 702000
    • labelstring
      Label
      e.g. Prestations de services
  • expense_accountobject
    Properties
    • idinteger
      Id
      e.g. 580
    • numberstring
      Account number
      e.g. 702000
    • labelstring
      Label
      e.g. Prestations de services
Example
{
    "id": 9,
    "company_id": 7,
    "source": "manual",
    "external_id": "string",
    "reference": "IMM-2026-003",
    "name": "Four mixte Rational",
    "category": "it_equipment",
    "asset_group": "string",
    "asset_account_id": 42,
    "depreciation_account_id": 42,
    "expense_account_id": 42,
    "imported_document_id": 42,
    "acquisition_date": "2026-02-01T00:00:00.000000Z",
    "acquisition_cost": "12400.00",
    "residual_value": "0.00",
    "useful_life_years": 5,
    "method": "linear",
    "prorata_temporis": true,
    "start_date": "2026-03-15T09:41:00+00:00",
    "status": "active",
    "notes": "string",
    "disposed_on": "2026-03-15T09:41:00+00:00",
    "disposal_price": "1210.00",
    "disposal_entry_id": 42,
    "investment_deduction_pct": "1210.00",
    "investment_deduction_spread": true,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "lines": [
        {
            "id": 42,
            "fixed_asset_id": 9,
            "year": 2026,
            "period_start": "2026-03-15T09:41:00+00:00",
            "period_end": "2026-03-15T09:41:00+00:00",
            "amount": "2269.37",
            "cumulative_amount": "2269.37",
            "remaining_value": "10130.63",
            "status": "planned",
            "journal_entry_id": 1284,
            "booked_amount": "0.00"
        }
    ],
    "asset_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "depreciation_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "expense_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    }
}
schemaImportedDocumentInvoice, credit note or receipt of the company file: synchronised from Novadesko or created by the document im...

Invoice, credit note or receipt of the company file: synchronised from Novadesko or created by the document importer.

  • idinteger
    e.g. 87
  • company_idinteger
    e.g. 7
  • sourcestring
    e.g. novadesko
  • originstring | null
    novafisko when created by the importer.
  • external_idstring | null
  • typestring
    purchases, invoices, credit_notes, receipts…
    e.g. purchases
  • directionstring
    sale purchase
  • is_credit_noteboolean
    e.g. false
  • naturestring | null
  • numberstring | null
    e.g. F-2026-0412
  • payment_providerstring | null
  • number_seriesstring | null
  • document_datestring <date-time>
    e.g. 2026-03-15T00:00:00.000000Z
  • due_datestring <date-time> | null
  • subjectstring | null
  • communicationstring | null
  • currencystring
    e.g. EUR
  • amount_netstring <decimal>
    e.g. 507.00
  • amount_vatstring <decimal>
    e.g. 106.47
  • amount_grossstring <decimal>
    e.g. 613.47
  • is_paidboolean
  • third_party_idinteger | null
  • third_party_namestring | null
    e.g. Brasserie Dubuisson SA
  • third_party_vatstring | null
  • pdf_urlstring <uri> | null
  • xml_urlstring <uri> | null
  • statusstring
    pending booked ignored
  • journal_entry_idinteger | null
  • accountant_lockedboolean
    Locked for the shop: only the accountant can change it.
  • novadesko_push_statusstring | null
  • novadesko_pushed_atstring <date-time> | null
  • novadesko_push_errorstring | null
  • document_import_idinteger | null
  • synced_atstring <date-time> | null
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • deleted_atstring <date-time> | null
    Set while the record is in the recycle bin.
  • deleted_byinteger | null
  • third_partyobject | null
  • journal_entryJournalEntry | null
Example
{
    "id": 87,
    "company_id": 7,
    "source": "novadesko",
    "origin": "string",
    "external_id": "string",
    "type": "purchases",
    "direction": "sale",
    "is_credit_note": false,
    "nature": "string",
    "number": "F-2026-0412",
    "payment_provider": "string",
    "number_series": "TK",
    "document_date": "2026-03-15T00:00:00.000000Z",
    "due_date": "2026-03-15T09:41:00+00:00",
    "subject": "Vos documents comptables",
    "communication": "string",
    "currency": "EUR",
    "amount_net": "507.00",
    "amount_vat": "106.47",
    "amount_gross": "613.47",
    "is_paid": true,
    "third_party_id": 18,
    "third_party_name": "Brasserie Dubuisson SA",
    "third_party_vat": "string",
    "pdf_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "xml_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "status": "pending",
    "journal_entry_id": 1284,
    "accountant_locked": true,
    "novadesko_push_status": "string",
    "novadesko_pushed_at": "2026-03-15T09:41:00+00:00",
    "novadesko_push_error": "string",
    "document_import_id": 42,
    "synced_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "third_party": {},
    "lines": [
        {
            "id": 640,
            "imported_document_id": 87,
            "external_id": "string",
            "position": 1,
            "description": "Fûts Bush Caractère 20 L",
            "quantity": "6.000",
            "unit_price": "84.5000",
            "discount_pct": "1210.00",
            "tax_rate": "21.00",
            "amount_net": "507.00",
            "amount_vat": "106.47",
            "recorded_account_number": "604000",
            "recorded_account_id": 42,
            "actual_account_id": 42,
            "vat_code_id": 4,
            "purchase_category": "string",
            "corrected_at": "2026-03-15T09:41:00+00:00",
            "corrected_by": 1,
            "correction_pushed": true,
            "recorded_account": {},
            "actual_account": {},
            "vat_code": {}
        }
    ],
    "journal_entry": {
        "id": 1284,
        "company_id": 7,
        "fiscal_year_id": 2,
        "period_id": 16,
        "journal_id": 3,
        "number": 412,
        "entry_date": "2026-03-15T00:00:00.000000Z",
        "due_date": "2026-03-15T09:41:00+00:00",
        "label": "Facture Brasserie Dubuisson SA",
        "reference": "F-2026-0412",
        "structured_communication": "000000000101",
        "third_party_id": 18,
        "status": "posted",
        "origin": "manual",
        "created_by": 1,
        "posted_at": "2026-03-15T09:41:00+00:00",
        "reversed_entry_id": 42,
        "reversed_by_entry_id": 42,
        "recurring_entry_id": 42,
        "created_at": "2026-03-15T09:41:00+00:00",
        "updated_at": "2026-03-15T09:41:00+00:00",
        "lock_version": 3,
        "version": 3,
        "journal": {
            "id": 3,
            "code": "VEN",
            "type": "sale"
        },
        "third_party": {
            "id": 18,
            "name": "Brasserie Dubuisson SA"
        },
        "lines": [
            {
                "id": 3391,
                "journal_entry_id": 1284,
                "position": 1,
                "account_id": 580,
                "third_party_id": 18,
                "label": "Brasserie Dubuisson SA",
                "debit": "0.00",
                "credit": "1000.00",
                "vat_code_id": 4,
                "vat_base": "1000.00",
                "reconciliation_code": "AB",
                "cost_center_id": 42,
                "project_id": 42,
                "reminder_level": 0,
                "reminder_sent_at": "2026-03-15T09:41:00+00:00",
                "account": {
                    "id": 580,
                    "number": "702000",
                    "label": "Prestations de services"
                },
                "vat_code": {}
            }
        ]
    }
}
schemaImportedDocumentLine
  • idinteger
    e.g. 640
  • imported_document_idinteger
    e.g. 87
  • external_idstring | null
  • positioninteger
    e.g. 1
  • descriptionstring | null
    e.g. Fûts Bush Caractère 20 L
  • quantitystring | null
    e.g. 6.000
  • unit_pricestring | null
    e.g. 84.5000
  • discount_pctstring <decimal> | null
  • tax_ratestring <decimal> | null
    e.g. 21.00
  • amount_netstring <decimal>
    e.g. 507.00
  • amount_vatstring <decimal>
    e.g. 106.47
  • recorded_account_numberstring | null
    Account as encoded at the source (« recorded » layer).
    e.g. 604000
  • recorded_account_idinteger | null
  • actual_account_idinteger | null
    Account chosen by the accountant (« actual » layer).
  • vat_code_idinteger | null
  • purchase_categorystring | null
  • corrected_atstring <date-time> | null
  • corrected_byinteger | null
  • correction_pushedboolean
  • recorded_accountobject | null
  • actual_accountobject | null
  • vat_codeobject | null
Example
{
    "id": 640,
    "imported_document_id": 87,
    "external_id": "string",
    "position": 1,
    "description": "Fûts Bush Caractère 20 L",
    "quantity": "6.000",
    "unit_price": "84.5000",
    "discount_pct": "1210.00",
    "tax_rate": "21.00",
    "amount_net": "507.00",
    "amount_vat": "106.47",
    "recorded_account_number": "604000",
    "recorded_account_id": 42,
    "actual_account_id": 42,
    "vat_code_id": 4,
    "purchase_category": "string",
    "corrected_at": "2026-03-15T09:41:00+00:00",
    "corrected_by": 1,
    "correction_pushed": true,
    "recorded_account": {},
    "actual_account": {},
    "vat_code": {}
}
schemaIntegration
  • slugstring
    e.g. novadesko
  • namestring
    e.g. Novadesko
  • categorystring
    accounting banking e_invoicing documents payments api
  • descriptionstring
  • logo_urlstring <uri> | null
  • statusstring
    available beta coming_soon
  • capabilitiesstring[]
    import_documents import_bank import_assets export_entries e_invoicing
  • config_schemaobject[]
    Properties
    • keystring
    • labelstring
    • typestring
      text secret select bool
    • requiredboolean
  • open_tabstring | null
  • has_driverboolean
  • is_enabledboolean
  • connectionobject | null
    Properties
    • is_activeboolean
    • statusstring
      connected disconnected error
    • config_maskedobject
    • last_sync_atstring <date-time> | null
    • last_errorstring | null
  • interestedboolean
  • actionsstring[]
Example
{
    "slug": "novadesko",
    "name": "Novadesko",
    "category": "accounting",
    "description": "Description",
    "logo_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "status": "available",
    "capabilities": [
        "import_documents"
    ],
    "config_schema": [
        {
            "key": "string",
            "label": "Facture Brasserie Dubuisson",
            "type": "text",
            "required": true
        }
    ],
    "open_tab": "string",
    "has_driver": true,
    "is_enabled": true,
    "connection": {
        "is_active": true,
        "status": "connected",
        "config_masked": {},
        "last_sync_at": "2026-03-15T09:41:00+00:00",
        "last_error": "string"
    },
    "interested": true,
    "actions": [
        "string"
    ]
}
schemaIntegrationRun
  • idinteger
    e.g. 77
  • statusstring
    running success error
  • started_atstring <date-time> | null
  • finished_atstring <date-time> | null
  • duration_msinteger | null
    e.g. 1840
  • summaryobject | null
  • messagestring | null
Example
{
    "id": 77,
    "status": "running",
    "started_at": "2026-03-15T09:41:00+00:00",
    "finished_at": "2026-03-15T09:41:00+00:00",
    "duration_ms": 1840,
    "summary": {},
    "message": "OK"
}
schemaIntegrationTokenIntegration token (the secret is only returned once, by the creation).

Integration token (the secret is only returned once, by the creation).

  • idinteger
    e.g. 57
  • namestring
    e.g. ERP connector
  • abilitiesstring[]
    read write sync
  • created_atstring <date-time>
  • expires_atstring <date-time> | null
  • last_used_atstring <date-time> | null
Example
{
    "id": 57,
    "name": "ERP connector",
    "abilities": [
        "read"
    ],
    "created_at": "2026-03-15T09:41:00+00:00",
    "expires_at": "2026-03-15T09:41:00+00:00",
    "last_used_at": "2026-03-15T09:41:00+00:00"
}
schemaJournal
  • idinteger
    e.g. 3
  • company_idinteger
    e.g. 7
  • codestring
    e.g. VEN
  • labelstring
    e.g. Ventes
  • typestring
    purchase sale purchase_credit_note sale_credit_note financial miscellaneous
  • control_account_idinteger | null
  • ibanstring | null
  • bicstring | null
  • last_numberinteger
    e.g. 412
  • is_activeboolean
  • is_defaultboolean
  • descriptionstring | null
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • deleted_atstring <date-time> | null
    Set while the record is in the recycle bin.
  • deleted_byinteger | null
  • entries_countinteger
    e.g. 412
  • control_accountobject | null
Example
{
    "id": 3,
    "company_id": 7,
    "code": "VEN",
    "label": "Ventes",
    "type": "purchase",
    "control_account_id": 42,
    "iban": "BE68539007547034",
    "bic": "GEBABEBB",
    "last_number": 412,
    "is_active": true,
    "is_default": true,
    "description": "Description",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "entries_count": 412,
    "control_account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "rules": [
        {
            "id": 4,
            "company_id": 7,
            "journal_id": 3,
            "direction": "sale",
            "match_field": "payment_provider",
            "match_value": "TK",
            "priority": 100,
            "is_active": true,
            "created_at": "2026-03-15T09:41:00+00:00",
            "updated_at": "2026-03-15T09:41:00+00:00",
            "lock_version": 3,
            "version": 3,
            "deleted_at": "2026-03-15T09:41:00+00:00",
            "deleted_by": 1,
            "journal": {
                "id": 3,
                "code": "VEN",
                "label": "Ventes",
                "type": "sale"
            }
        }
    ]
}
schemaJournalEntryPosted accounting entry. A posted entry is never modified nor deleted: it is reversed.

Posted accounting entry. A posted entry is never modified nor deleted: it is reversed.

  • idinteger
    e.g. 1284
  • company_idinteger
    e.g. 7
  • fiscal_year_idinteger
    e.g. 2
  • period_idinteger
    e.g. 16
  • journal_idinteger
    e.g. 3
  • numberinteger
    Continuous number in the journal and fiscal year.
    e.g. 412
  • entry_datestring <date-time>
    e.g. 2026-03-15T00:00:00.000000Z
  • due_datestring <date-time> | null
  • labelstring
    e.g. Facture Brasserie Dubuisson SA
  • referencestring | null
    Document number.
    e.g. F-2026-0412
  • structured_communicationstring | null
    12 digits, without +++ and /.
    e.g. 000000000101
  • third_party_idinteger | null
    e.g. 18
  • statusstring
    posted reversed
  • originstring
    manual, import, bank, recurring, depreciation, vat, year_end…
    e.g. manual
  • created_byinteger | null
  • posted_atstring <date-time>
  • reversed_entry_idinteger | null
    Entry this one reverses.
  • reversed_by_entry_idinteger | null
    Entry that reversed this one.
  • recurring_entry_idinteger | null
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • journalobject
    Properties
    • idinteger
      e.g. 3
    • codestring
      e.g. VEN
    • typestring
      e.g. sale
  • third_partyobject
    Properties
    • idinteger
      e.g. 18
    • namestring
      e.g. Brasserie Dubuisson SA
Example
{
    "id": 1284,
    "company_id": 7,
    "fiscal_year_id": 2,
    "period_id": 16,
    "journal_id": 3,
    "number": 412,
    "entry_date": "2026-03-15T00:00:00.000000Z",
    "due_date": "2026-03-15T09:41:00+00:00",
    "label": "Facture Brasserie Dubuisson SA",
    "reference": "F-2026-0412",
    "structured_communication": "000000000101",
    "third_party_id": 18,
    "status": "posted",
    "origin": "manual",
    "created_by": 1,
    "posted_at": "2026-03-15T09:41:00+00:00",
    "reversed_entry_id": 42,
    "reversed_by_entry_id": 42,
    "recurring_entry_id": 42,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal": {
        "id": 3,
        "code": "VEN",
        "type": "sale"
    },
    "third_party": {
        "id": 18,
        "name": "Brasserie Dubuisson SA"
    },
    "lines": [
        {
            "id": 3391,
            "journal_entry_id": 1284,
            "position": 1,
            "account_id": 580,
            "third_party_id": 18,
            "label": "Brasserie Dubuisson SA",
            "debit": "0.00",
            "credit": "1000.00",
            "vat_code_id": 4,
            "vat_base": "1000.00",
            "reconciliation_code": "AB",
            "cost_center_id": 42,
            "project_id": 42,
            "reminder_level": 0,
            "reminder_sent_at": "2026-03-15T09:41:00+00:00",
            "account": {
                "id": 580,
                "number": "702000",
                "label": "Prestations de services"
            },
            "vat_code": {}
        }
    ]
}
schemaJournalEntryLine
  • idinteger
    e.g. 3391
  • journal_entry_idinteger
    e.g. 1284
  • positioninteger
    e.g. 1
  • account_idinteger
    e.g. 580
  • third_party_idinteger | null
  • labelstring | null
    e.g. Brasserie Dubuisson SA
  • debitstring <decimal>
    e.g. 0.00
  • creditstring <decimal>
    e.g. 1000.00
  • vat_code_idinteger | null
    e.g. 4
  • vat_basestring <decimal> | null
    e.g. 1000.00
  • reconciliation_codestring | null
    Lettering code.
    e.g. AB
  • cost_center_idinteger | null
  • project_idinteger | null
  • reminder_levelinteger
    e.g. 0
  • reminder_sent_atstring <date-time> | null
  • accountobject
    Properties
    • idinteger
      Id
      e.g. 580
    • numberstring
      Account number
      e.g. 702000
    • labelstring
      Label
      e.g. Prestations de services
  • vat_codeobject | null
Example
{
    "id": 3391,
    "journal_entry_id": 1284,
    "position": 1,
    "account_id": 580,
    "third_party_id": 18,
    "label": "Brasserie Dubuisson SA",
    "debit": "0.00",
    "credit": "1000.00",
    "vat_code_id": 4,
    "vat_base": "1000.00",
    "reconciliation_code": "AB",
    "cost_center_id": 42,
    "project_id": 42,
    "reminder_level": 0,
    "reminder_sent_at": "2026-03-15T09:41:00+00:00",
    "account": {
        "id": 580,
        "number": "702000",
        "label": "Prestations de services"
    },
    "vat_code": {}
}
schemaJournalRuleRoutes imported documents to a journal according to their numbering series, payment provider or third party.

Routes imported documents to a journal according to their numbering series, payment provider or third party.

  • idinteger
    e.g. 4
  • company_idinteger
  • journal_idinteger
    e.g. 3
  • directionstring
    sale purchase
  • match_fieldstring
    payment_provider number_series number_prefix third_party
  • match_valuestring
    e.g. TK
  • priorityinteger
    e.g. 100
  • is_activeboolean
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • deleted_atstring <date-time> | null
    Set while the record is in the recycle bin.
  • deleted_byinteger | null
  • journalobject
    Properties
    • idinteger
      e.g. 3
    • codestring
      e.g. VEN
    • labelstring
      e.g. Ventes
    • typestring
      e.g. sale
Example
{
    "id": 4,
    "company_id": 7,
    "journal_id": 3,
    "direction": "sale",
    "match_field": "payment_provider",
    "match_value": "TK",
    "priority": 100,
    "is_active": true,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "journal": {
        "id": 3,
        "code": "VEN",
        "label": "Ventes",
        "type": "sale"
    }
}
schemaLicenceLicence and subscription of the firm: plan, status, usage of the month, estimate, last statements.

Licence and subscription of the firm: plan, status, usage of the month, estimate, last statements.

  • statusstring
    none trial active past_due suspended cancelled
  • subscriptionobject | null
  • planobject | null
  • usageobject
    Properties
    • monthstring
      e.g. 2026-10
    • companiesinteger
      e.g. 25
    • usersinteger
      e.g. 4
    • bank_accountsinteger
      e.g. 31
    • rowsobject[]
      Properties
      • company_idinteger
      • tokenstring
      • namestring
      • codestring | null
      • bank_accountsinteger
        e.g. 1
      • statusstring
        e.g. active
      • activated_atstring <date-time>
      • deactivated_atstring <date-time> | null
    • max_companiesinteger | null
    • over_limitboolean
      e.g. false
    • suggestionstring | null
  • estimateobject | null
    Estimated invoice of the month (excl. VAT).
  • companies_detailobject[]
    Properties
    • company_idinteger
    • namestring
    • public_tokenstring
    • statusstring
      e.g. active
    • activated_atstring <date-time>
    • deactivated_atstring <date-time> | null
    • billableboolean
  • next_month_previewobject
    Properties
    • companiesinteger
      e.g. 25
    • totalnumber
      e.g. 121.5
  • over_limitboolean
    e.g. false
  • over_limit_firm_totalnumber | null
  • entitlementsobject
    Properties
    • accountingboolean
    • peppolboolean
    • codaboolean
    • client_portalboolean
    • client_invoicingboolean
    • document_importboolean
  • limitsobject
    Properties
    • max_usersinteger | null
    • max_companiesinteger | null
    • users_countinteger
      e.g. 4
    • companies_countinteger
      e.g. 25
  • expires_atstring <date-time> | null
  • warningstring | null
  • activationobject | null
    Active licence key (masked) when the subscription comes from a key.
  • statementsobject[]
  • options_availableobject[]
    Properties
    • codestring
      client_portal client_invoicing
    • namestring
      e.g. Portail client
    • price_monthlynumber
      e.g. 6.9
    • unitstring
      e.g. client
  • can_manageboolean
Example
{
    "status": "none",
    "subscription": {},
    "plan": {},
    "usage": {
        "month": "2026-10",
        "companies": 25,
        "users": 4,
        "bank_accounts": 31,
        "rows": [
            {
                "company_id": 7,
                "token": "XBVD5O1L29HC",
                "name": "Le Comptoir Montois SRL",
                "code": "COMPTOIR",
                "bank_accounts": 1,
                "status": "active",
                "activated_at": "2026-03-15T09:41:00+00:00",
                "deactivated_at": "2026-03-15T09:41:00+00:00"
            }
        ],
        "max_companies": 1,
        "over_limit": false,
        "suggestion": "string"
    },
    "estimate": {},
    "companies_detail": [
        {
            "company_id": 7,
            "name": "Le Comptoir Montois SRL",
            "public_token": "XBVD5O1L29HC",
            "status": "active",
            "activated_at": "2026-03-15T09:41:00+00:00",
            "deactivated_at": "2026-03-15T09:41:00+00:00",
            "billable": true
        }
    ],
    "next_month_preview": {
        "companies": 25,
        "total": 121.5
    },
    "over_limit": false,
    "over_limit_firm_total": 12.5,
    "entitlements": {
        "accounting": true,
        "peppol": true,
        "coda": true,
        "client_portal": true,
        "client_invoicing": true,
        "document_import": true
    },
    "limits": {
        "max_users": 1,
        "max_companies": 1,
        "users_count": 4,
        "companies_count": 25
    },
    "expires_at": "2026-03-15T09:41:00+00:00",
    "warning": "string",
    "activation": {},
    "statements": [
        {}
    ],
    "options_available": [
        {
            "code": "client_portal",
            "name": "Portail client",
            "price_monthly": 6.9,
            "unit": "client"
        }
    ],
    "can_manage": true
}
schemaMailLog
  • idinteger
    e.g. 9012
  • template_keystring
    e.g. documents.send
  • tostring <email>
    e.g. gerant@comptoir-montois.example
  • subjectstring
    e.g. Vos documents comptables
  • statusstring
    queued sent failed bounced
  • localestring
    e.g. fr
  • created_atstring <date-time>
  • sent_atstring <date-time> | null
  • opened_atstring <date-time> | null
  • attachmentsobject[]
    Properties
    • namestring
      e.g. balance-2026.pdf
    • sizeinteger
      e.g. 48211
Example
{
    "id": 9012,
    "template_key": "documents.send",
    "to": "gerant@comptoir-montois.example",
    "subject": "Vos documents comptables",
    "status": "queued",
    "locale": "fr",
    "created_at": "2026-03-15T09:41:00+00:00",
    "sent_at": "2026-03-15T09:41:00+00:00",
    "opened_at": "2026-03-15T09:41:00+00:00",
    "attachments": [
        {
            "name": "balance-2026.pdf",
            "size": 48211
        }
    ]
}
schemaMessage
  • messagestring
    Translated confirmation.
    e.g. Mot de passe modifié.
Example
{
    "message": "Mot de passe modifié."
}
schemaPaginationLaravel length-aware pagination envelope; `data` holds the items.

Laravel length-aware pagination envelope; data holds the items.

  • current_pageinteger
    e.g. 1
  • dataany[]
  • first_page_urlstring <uri> | null
  • frominteger | null
    e.g. 1
  • last_pageinteger
    e.g. 4
  • last_page_urlstring <uri> | null
  • linksobject[]
    Properties
    • urlstring <uri> | null
    • labelstring
      e.g. 1
    • pageinteger | null
    • activeboolean
  • next_page_urlstring <uri> | null
  • pathstring <uri>
  • per_pageinteger
    e.g. 50
  • prev_page_urlstring <uri> | null
  • tointeger | null
    e.g. 50
  • totalinteger
    e.g. 187
Example
{
    "current_page": 1,
    "data": [
        null
    ],
    "first_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "from": 1,
    "last_page": 4,
    "last_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "links": [
        {
            "url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "label": "1",
            "page": 1,
            "active": true
        }
    ],
    "next_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "path": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "per_page": 50,
    "prev_page_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "to": 50,
    "total": 187
}
schemaPeppolAccessPoint
  • smp_hoststring | null
    e.g. smp.b2brouter.net
  • provider_namestring | null
    e.g. B2Brouter
  • endpoint_urlstring <uri> | null
  • technical_contactstring | null
Example
{
    "smp_host": "smp.b2brouter.net",
    "provider_name": "B2Brouter",
    "endpoint_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
    "technical_contact": "string"
}
schemaPeppolDocumentType
  • idstring
    e.g. bis_billing_invoice
  • namestring
    e.g. Invoice BIS Billing 3.0
  • familystring
    e.g. billing
  • descriptionstring
    e.g. Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.
  • document_idstring
    Full Peppol document type identifier.
Example
{
    "id": "bis_billing_invoice",
    "name": "Invoice BIS Billing 3.0",
    "family": "billing",
    "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
    "document_id": "string"
}
schemaPeppolStatePeppol registration state of a company file.

Peppol registration state of a company file.

  • identityobject | null
    Raw registration record.
  • participant_idstring | null
    e.g. 0208:0477472701
  • statusstring
    none pending active inactive deleted error external
  • accountobject | null
    Properties
    • idstring
    • namestring | null
    • archivedboolean
  • transportobject | null
    Transport options: enabled, reception, standard_documents, invoice, credit_note, self_billing, order, application_response.
  • smpobject
    Properties
    • publishedboolean
    • checked_atstring <date-time> | null
  • access_pointPeppolAccessPoint
  • supported_documentsPeppolDocumentType[]
  • can_registerboolean
  • blockersstring[]
  • blocker_codesstring[]
  • managed_by_novadeskoboolean
  • registered_elsewhereboolean
    The participant is already published by another access point.
  • external_providerstring | null
  • provider_configuredboolean
  • environmentstring
    production staging
  • contactobject
  • last_errorstring | null
Example
{
    "identity": {},
    "participant_id": "0208:0477472701",
    "status": "none",
    "account": {
        "id": "string",
        "name": "Le Comptoir Montois SRL",
        "archived": true
    },
    "transport": {},
    "smp": {
        "published": true,
        "checked_at": "2026-03-15T09:41:00+00:00"
    },
    "access_point": {
        "smp_host": "smp.b2brouter.net",
        "provider_name": "B2Brouter",
        "endpoint_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "technical_contact": "string"
    },
    "supported_documents": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "can_register": true,
    "blockers": [
        "string"
    ],
    "blocker_codes": [
        "string"
    ],
    "managed_by_novadesko": true,
    "registered_elsewhere": true,
    "external_provider": "string",
    "provider_configured": true,
    "environment": "production",
    "contact": {},
    "last_error": "string"
}
schemaPeppolThirdPartyStatus
  • identifierstring | null
    e.g. 0208:0402531376
  • registeredboolean | null
  • access_pointPeppolAccessPoint | null
  • document_typesPeppolDocumentType[]
  • checked_atstring <date-time> | null
  • staleboolean
  • errorstring | null
  • sourcestring | null
    e.g. sml+smp
Example
{
    "identifier": "0208:0402531376",
    "registered": true,
    "access_point": {
        "smp_host": "smp.b2brouter.net",
        "provider_name": "B2Brouter",
        "endpoint_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "technical_contact": "string"
    },
    "document_types": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "checked_at": "2026-03-15T09:41:00+00:00",
    "stale": true,
    "error": "string",
    "source": "sml+smp"
}
schemaPeriod
  • idinteger
    e.g. 16
  • fiscal_year_idinteger
    e.g. 2
  • numberinteger
    0 = opening, 1-12 = months, 99 = closing.
    e.g. 3
  • labelstring
    e.g. Mars 2026
  • starts_onstring <date-time>
  • ends_onstring <date-time>
  • is_lockedboolean
    e.g. false
  • locked_atstring <date-time> | null
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
Example
{
    "id": 16,
    "fiscal_year_id": 2,
    "number": 3,
    "label": "Mars 2026",
    "starts_on": "2026-03-15T09:41:00+00:00",
    "ends_on": "2026-03-15T09:41:00+00:00",
    "is_locked": false,
    "locked_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3
}
schemaPeriodLockedError422 of a write whose period is locked or whose fiscal year is closed.

422 of a write whose period is locked or whose fiscal year is closed.

  • messagestringrequired
    e.g. La période Mars 2026 est verrouillée.
  • codestringrequired
    period_locked
  • reasonstringrequired
    period_locked fiscal_year_closed
  • errorsobjectrequired
Example
{
    "message": "La période Mars 2026 est verrouillée.",
    "code": "period_locked",
    "reason": "period_locked",
    "errors": {
        "entry_date": [
            "La période Mars 2026 est verrouillée."
        ]
    }
}
schemaPricingGrid
  • currencystring
    e.g. EUR
  • vat_includedboolean
    e.g. false
  • plansobject[]
    Properties
    • codestring
      starter firm
    • namestring
      e.g. Firm
    • kindstring
      starter firm
    • base_price_monthlynumber
      e.g. 49
    • per_companynumber
      e.g. 2.9
    • tiersobject[]
      Properties
      • up_tointeger | null
        e.g. 100
      • pricenumber
        e.g. 2.9
    • max_companiesinteger | null
    • peppol_fair_use_per_companyinteger
      e.g. 100
    • annual_discount_pctnumber
      e.g. 10
    • includedstring[]
  • optionsobject[]
    Properties
    • codestring
      e.g. client_portal
    • namestring
      e.g. Client portal
    • price_monthlynumber
      e.g. 6.9
    • unitstring
      e.g. client
  • annual_discount_pctnumber
    e.g. 10
  • winauditorobject
    Reference prices used for the comparison.
  • pilotobject
    Properties
    • free_monthsinteger
      e.g. 3
    • max_firmsinteger
      e.g. 20
Example
{
    "currency": "EUR",
    "vat_included": false,
    "plans": [
        {
            "code": "starter",
            "name": "Firm",
            "kind": "starter",
            "base_price_monthly": 49,
            "per_company": 2.9,
            "tiers": [
                {
                    "up_to": 100,
                    "price": 2.9
                }
            ],
            "max_companies": 1,
            "peppol_fair_use_per_company": 100,
            "annual_discount_pct": 10,
            "included": [
                "Unlimited users"
            ]
        }
    ],
    "options": [
        {
            "code": "client_portal",
            "name": "Client portal",
            "price_monthly": 6.9,
            "unit": "client"
        }
    ],
    "annual_discount_pct": 10,
    "winauditor": {},
    "pilot": {
        "free_months": 3,
        "max_firms": 20
    }
}
schemaPricingSimulation
  • companiesinteger
    e.g. 25
  • yearlyboolean
    e.g. false
  • starterobject | null
    Null when the plan cannot hold that many companies.
  • firmobject
    Properties
    • planstring
      e.g. firm
    • billing_intervalstring
      monthly yearly
    • companiesinteger
      e.g. 25
    • basenumber
      e.g. 49
    • companies_breakdownobject[]
      Properties
      • frominteger
        e.g. 1
      • tointeger
        e.g. 100
      • quantityinteger
        e.g. 25
      • unit_pricenumber
        e.g. 2.9
      • totalnumber
        e.g. 72.5
    • companies_totalnumber
      e.g. 72.5
    • optionsobject[]
    • options_totalnumber
      e.g. 0
    • pilot_discountnumber
      e.g. 0
    • annual_discount_pctnumber
      e.g. 0
    • annual_discountnumber
      e.g. 0
    • discountnumber
      e.g. 0
    • totalnumber
      e.g. 121.5
    • yearly_totalnumber
      e.g. 1458
    • namestring
      e.g. Firm
    • saving_vs_winauditornumber
      e.g. 36
    • saving_pctnumber
      e.g. 22.9
  • winauditornumber
    e.g. 157.5
  • cheapeststring
    starter firm
Example
{
    "companies": 25,
    "yearly": false,
    "starter": {},
    "firm": {
        "plan": "firm",
        "billing_interval": "monthly",
        "companies": 25,
        "base": 49,
        "companies_breakdown": [
            {
                "from": 1,
                "to": 100,
                "quantity": 25,
                "unit_price": 2.9,
                "total": 72.5
            }
        ],
        "companies_total": 72.5,
        "options": [
            {}
        ],
        "options_total": 0,
        "pilot_discount": 0,
        "annual_discount_pct": 0,
        "annual_discount": 0,
        "discount": 0,
        "total": 121.5,
        "yearly_total": 1458,
        "name": "Firm",
        "saving_vs_winauditor": 36,
        "saving_pct": 22.9
    },
    "winauditor": 157.5,
    "cheapest": "starter"
}
schemaRecurringEntry
  • idinteger
    e.g. 5
  • company_idinteger
  • journal_idinteger
    e.g. 5
  • labelstring
    e.g. Loyer mensuel
  • referencestring | null
  • third_party_idinteger | null
  • frequencystring
    monthly quarterly yearly
  • next_datestring <date-time>
    e.g. 2026-04-01T00:00:00.000000Z
  • end_datestring <date-time> | null
  • linesobject[]
    Properties
    • account_idinteger
      e.g. 368
    • debitstring | null
      e.g. 1500.00
    • creditstring | null
    • labelstring | null
    • third_party_idinteger | null
  • is_activeboolean
  • last_generated_onstring <date> | null
  • generated_countinteger
    e.g. 3
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • deleted_atstring <date-time> | null
    Set while the record is in the recycle bin.
  • deleted_byinteger | null
  • journalobject
    Properties
    • idinteger
    • codestring
      e.g. OD
    • labelstring
      e.g. Opérations diverses
  • third_partyobject | null
Example
{
    "id": 5,
    "company_id": 7,
    "journal_id": 5,
    "label": "Loyer mensuel",
    "reference": "F-2026-0412",
    "third_party_id": 18,
    "frequency": "monthly",
    "next_date": "2026-04-01T00:00:00.000000Z",
    "end_date": "2026-03-15T09:41:00+00:00",
    "lines": [
        {
            "account_id": 368,
            "debit": "1500.00",
            "credit": "0.00",
            "label": "Facture Brasserie Dubuisson",
            "third_party_id": 18
        }
    ],
    "is_active": true,
    "last_generated_on": "2026-03-15",
    "generated_count": 3,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "journal": {
        "id": 42,
        "code": "OD",
        "label": "Opérations diverses"
    },
    "third_party": {}
}
schemaRevisionOne line of the version history.

One line of the version history.

  • idinteger
    e.g. 2301
  • actionstring
    created updated deleted restored reverted synced
  • effectstring
    e.g. updated
  • action_labelstring
    e.g. Modification · Tiers
  • subject_typestring
    e.g. third_parties
  • subject_type_labelstring
    e.g. Tiers
  • subject_idinteger
    e.g. 18
  • subject_labelstring
    e.g. DUBUISSON · Brasserie Dubuisson SA
  • userobject | null
  • actor_namestring | null
    e.g. Claire Dumont
  • changesobject[]
    Properties
    • fieldstring
      e.g. payment_terms_days
    • labelstring
      e.g. Délai de paiement
    • oldany
    • newany
  • versioninteger
    e.g. 4
  • operation_idstring <uuid>
  • client_mutation_idstring | null
  • originstring
    online offline_sync system bridge
  • device_idstring | null
  • device_namestring | null
  • reasonstring | null
  • reverts_revision_idinteger | null
  • reverted_atstring <date-time> | null
  • reverted_by_revision_idinteger | null
  • occurred_atstring <date-time>
  • created_atstring <date-time>
  • can_revertboolean
  • revert_blocked_reasonstring | null
  • revert_blocked_messagestring | null
  • revert_effectstring | null
    update, trash, restore, recreate or reverse.
  • snapshot_beforeobject | null
    Single revision only.
  • snapshot_afterobject | null
    Single revision only.
  • ipstring | null
    Single revision only.
Example
{
    "id": 2301,
    "action": "created",
    "effect": "updated",
    "action_label": "Modification · Tiers",
    "subject_type": "third_parties",
    "subject_type_label": "Tiers",
    "subject_id": 18,
    "subject_label": "DUBUISSON · Brasserie Dubuisson SA",
    "user": {
        "id": 12,
        "name": "Claire Dumont"
    },
    "actor_name": "Claire Dumont",
    "changes": [
        {
            "field": "payment_terms_days",
            "label": "Délai de paiement",
            "old": null,
            "new": null
        }
    ],
    "version": 4,
    "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    "origin": "online",
    "device_id": "mac-7F3A21",
    "device_name": "MacBook de Claire",
    "reason": "string",
    "reverts_revision_id": 42,
    "reverted_at": "2026-03-15T09:41:00+00:00",
    "reverted_by_revision_id": 42,
    "occurred_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "can_revert": true,
    "revert_blocked_reason": "string",
    "revert_blocked_message": "string",
    "revert_effect": "string",
    "snapshot_before": {},
    "snapshot_after": {},
    "ip": "string"
}
schemaSheetView
  • sheetCompanySheet | null
  • sheet_atstring <date-time> | null
  • addressobject
    Properties
    • streetstring | null
      Street
      e.g. Grand-Place
    • house_numberstring | null
      Number
      e.g. 14
    • boxstring | null
      Box
    • postal_codestring | null
      Postal code
      e.g. 7000
    • citystring | null
      City
      e.g. Mons
    • countrystring | null
      ISO 3166-1 alpha-2
      e.g. BE
  • address_linestring | null
  • legal_formobject | null
  • nace_codesobject[]
    Properties
    • codestring
    • classificationstring
    • labelstring | null
    • is_mainboolean
  • main_nace_codestring | null
  • vat_number_formattedstring | null
    e.g. BE 0477.472.701
  • mapobject
    Properties
    • querystring
      Address used for the map
      e.g. Grand-Place 14, 7000 Mons, Belgique
    • apple_urlstring <uri>
    • google_urlstring <uri>
    • static_urlstring <uri> | null
    • latitudenumber | null
    • longitudenumber | null
Example
{
    "sheet": {
        "identifier": "0477472701",
        "enterprise_number": "0477472701",
        "vat_number": "BE0477472701",
        "name": "Le Comptoir Montois",
        "legal_form": "SRL",
        "legal_form_code": "610",
        "status": "active",
        "start_date": "2026-03-15",
        "address": {
            "street": "Grand-Place",
            "house_number": "14",
            "box": "string",
            "postal_code": "7000",
            "city": "Mons",
            "country": "BE"
        },
        "address_line": "string",
        "latitude": 12.5,
        "longitude": 12.5,
        "nace_codes": [
            {
                "code": "56111",
                "classification": "MAIN",
                "label": "Facture Brasserie Dubuisson"
            }
        ],
        "main_nace_code": "string",
        "email": "claire.dumont@fiduciaire-dumont.be",
        "phone": "+32 65 31 42 18",
        "website": "https://www.comptoir-montois.be",
        "source": "companysearch",
        "fetched_at": "2026-03-15T09:41:00+00:00",
        "map": {
            "query": "Grand-Place 14, 7000 Mons, Belgique",
            "apple_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "google_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "static_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
            "latitude": 12.5,
            "longitude": 12.5
        }
    },
    "sheet_at": "2026-03-15T09:41:00+00:00",
    "address": {
        "street": "Grand-Place",
        "house_number": "14",
        "box": "string",
        "postal_code": "7000",
        "city": "Mons",
        "country": "BE"
    },
    "address_line": "string",
    "legal_form": {},
    "nace_codes": [
        {
            "code": "COMPTOIR",
            "classification": "string",
            "label": "Facture Brasserie Dubuisson",
            "is_main": true
        }
    ],
    "main_nace_code": "string",
    "vat_number_formatted": "BE 0477.472.701",
    "map": {
        "query": "Grand-Place 14, 7000 Mons, Belgique",
        "apple_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "google_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "static_url": "https://api.novafisko.com/v1/companies/XBVD5O1L29HC",
        "latitude": 12.5,
        "longitude": 12.5
    }
}
schemaSyncChange
  • resourcestring
    e.g. third_parties
  • opstring
    upsert delete
  • idinteger
    e.g. 18
  • versioninteger | null
    e.g. 4
  • dataobject | null
    Resource serialised as by its list endpoint; null for a tombstone.
  • changed_atstring <date-time>
  • seqinteger
    Position in the change feed.
    e.g. 1042
Example
{
    "resource": "third_parties",
    "op": "upsert",
    "id": 18,
    "version": 4,
    "data": {},
    "changed_at": "2026-03-15T09:41:00+00:00",
    "seq": 1042
}
schemaSyncConflict
  • idinteger
    e.g. 8
  • statusstring
    open resolved
  • typestring
    field delete_vs_update update_vs_delete duplicate locked
  • type_labelstring
  • resourcestring
    e.g. third_parties
  • record_idinteger | null
  • subject_idinteger | null
  • subject_labelstring | null
  • client_mutation_idstring | null
  • fieldsobject[]
    Properties
    • fieldstring
    • labelstring
    • serverany
    • clientany
    • winnerstring
    • rulestring
  • client_dataobject | null
  • server_dataobject | null
  • server_versioninteger | null
  • winnerstring | null
  • loserstring | null
  • resolutionstring | null
  • resolved_byinteger | null
  • client_userobject | null
  • server_userobject | null
  • resolved_by_userobject | null
  • device_idstring | null
  • created_atstring <date-time>
  • resolved_atstring <date-time> | null
  • choicesstring[]
    server client merge
Example
{
    "id": 8,
    "status": "open",
    "type": "field",
    "type_label": "string",
    "resource": "third_parties",
    "record_id": 42,
    "subject_id": 42,
    "subject_label": "string",
    "client_mutation_id": "b0a6f6f0-7d1c-4c5e-8a55-3f2b1c9d0e11",
    "fields": [
        {
            "field": "string",
            "label": "Facture Brasserie Dubuisson",
            "server": null,
            "client": null,
            "winner": "string",
            "rule": "string"
        }
    ],
    "client_data": {},
    "server_data": {},
    "server_version": 1,
    "winner": "string",
    "loser": "string",
    "resolution": "string",
    "resolved_by": 1,
    "client_user": {},
    "server_user": {},
    "resolved_by_user": {},
    "device_id": "mac-7F3A21",
    "created_at": "2026-03-15T09:41:00+00:00",
    "resolved_at": "2026-03-15T09:41:00+00:00",
    "choices": [
        "server"
    ]
}
schemaSyncMutationOne action made offline, replayed through the matching REST action (same validation, same body).

One action made offline, replayed through the matching REST action (same validation, same body).

  • client_mutation_idstring <uuid>required
    Idempotence key.
  • occurred_atstring <date-time>
    Date of the action on the device.
  • operation_idstring <uuid>
  • resourcestringrequired
    third_parties, accounts, journals, journal_rules, bank_rules, recurring_entries, analytic_codes, fixed_assets, entries, documents, document_lines, bank_transactions, company_settings.
    e.g. third_parties
  • opstringrequired
    create update delete action
  • actionstring
    ignore restore entry invoice reverse book update_line
  • idinteger | string | null
    Server id, or the tmp-… id of a record created earlier in the queue.
  • client_temp_idstring
    Temporary id of a creation (tmp-<uuid>), mapped to the server id.
    e.g. tmp-3c1f
  • parent_idinteger | string | null
  • base_versioninteger
    Version the client edited.
  • dataobject
    Body of the equivalent REST request.
Example
{
    "client_mutation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "occurred_at": "2026-03-15T09:41:00+00:00",
    "operation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "resource": "third_parties",
    "op": "create",
    "action": "ignore",
    "id": 42,
    "client_temp_id": "tmp-3c1f",
    "parent_id": 42,
    "base_version": 1,
    "data": {}
}
schemaSyncMutationResult
  • client_mutation_idstring <uuid>
  • statusstring
    applied duplicate conflict rejected
  • original_statusstring | null
  • codestring | null
    locked, not_supported_offline, validation, not_found, forbidden, invalid_mutation, unknown_temp_id, unprocessable, server_error.
  • messagestring | null
  • resourcestring
  • opstring
  • actionstring | null
  • idinteger | null
  • client_temp_idstring | null
  • versioninteger | null
  • dataobject | null
  • errorsobject | null
  • conflictobject | null
    Properties
    • server_versioninteger
    • server_dataobject
    • fieldsobject[]
      Properties
      • fieldstring
      • clientany
      • serverany
      • winnerstring
        client server
      • rulestring
    • resolutionstring
  • duplicate_ofinteger | null
  • retryableboolean
Example
{
    "client_mutation_id": "bf413a19-2136-4504-bc42-b314637eb5c7",
    "status": "applied",
    "original_status": "string",
    "code": "COMPTOIR",
    "message": "OK",
    "resource": "string",
    "op": "string",
    "action": "string",
    "id": 42,
    "client_temp_id": "string",
    "version": 3,
    "data": {},
    "errors": {},
    "conflict": {
        "server_version": 1,
        "server_data": {},
        "fields": [
            {
                "field": "string",
                "client": null,
                "server": null,
                "winner": "client",
                "rule": "string"
            }
        ],
        "resolution": "string"
    },
    "duplicate_of": 1,
    "retryable": true
}
schemaThirdPartyCustomer or supplier of a company file.

Customer or supplier of a company file.

  • idinteger
    e.g. 18
  • company_idinteger
    e.g. 7
  • typestring
    customer supplier
  • codestring
    e.g. DUBUISSON
  • namestring
    e.g. Brasserie Dubuisson SA
  • contact_namestring | null
  • vat_numberstring | null
    e.g. BE0402531376
  • enterprise_numberstring | null
    e.g. 0402531376
  • legal_form_codestring | null
  • vat_statusstring
    subject not_subject exempt intra_eu non_eu
  • countrystring
    e.g. BE
  • languagestring | null
    e.g. fr
  • categorystring | null
  • currencystring
    e.g. EUR
  • addressstring | null
    e.g. Chaussée de Mons 28
  • house_numberstring | null
  • boxstring | null
  • address_line_2string | null
  • postal_codestring | null
    e.g. 7904
  • citystring | null
    e.g. Pipaix
  • nace_codestring | null
  • ibanstring | null
    e.g. BE71096123456769
  • bicstring | null
    e.g. GKCCBEBB
  • bank_accountstring | null
  • emailstring <email> | null
    e.g. compta@dubuisson.example
  • phonestring | null
  • faxstring | null
  • websitestring | null
  • payment_terms_daysinteger
    e.g. 30
  • form_281_50_typestring | null
  • profession_281_50string | null
  • is_natural_personboolean
    e.g. false
  • notesstring | null
  • default_vat_code_idinteger | null
  • default_account_idinteger | null
  • vies_validboolean | null
  • vies_checked_atstring <date-time> | null
  • vies_namestring | null
  • peppol_identifierstring | null
    e.g. 0208:0402531376
  • peppol_registeredboolean | null
  • peppol_access_pointobject | null
  • peppol_document_typesPeppolDocumentType[] | null
  • peppol_checked_atstring <date-time> | null
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • deleted_atstring <date-time> | null
    Set while the record is in the recycle bin.
  • deleted_byinteger | null
  • default_accountobject | null
    Loaded on the single sheet.
  • default_vat_codeobject | null
    Loaded on the single sheet.
Example
{
    "id": 18,
    "company_id": 7,
    "type": "customer",
    "code": "DUBUISSON",
    "name": "Brasserie Dubuisson SA",
    "contact_name": "string",
    "vat_number": "BE0402531376",
    "enterprise_number": "0402531376",
    "legal_form_code": "string",
    "vat_status": "subject",
    "country": "BE",
    "language": "fr",
    "category": "string",
    "currency": "EUR",
    "address": "Chaussée de Mons 28",
    "house_number": "14",
    "box": "string",
    "address_line_2": "string",
    "postal_code": "7904",
    "city": "Pipaix",
    "nace_code": "string",
    "iban": "BE71096123456769",
    "bic": "GKCCBEBB",
    "bank_account": "string",
    "email": "compta@dubuisson.example",
    "phone": "+32 65 31 42 18",
    "fax": "string",
    "website": "https://www.comptoir-montois.be",
    "payment_terms_days": 30,
    "form_281_50_type": "string",
    "profession_281_50": "string",
    "is_natural_person": false,
    "notes": "string",
    "default_vat_code_id": 42,
    "default_account_id": 42,
    "vies_valid": true,
    "vies_checked_at": "2026-03-15T09:41:00+00:00",
    "vies_name": "string",
    "peppol_identifier": "0208:0402531376",
    "peppol_registered": true,
    "peppol_access_point": {},
    "peppol_document_types": [
        {
            "id": "bis_billing_invoice",
            "name": "Invoice BIS Billing 3.0",
            "family": "billing",
            "description": "Facture électronique européenne (EN 16931), format Peppol BIS Billing 3.0.",
            "document_id": "string"
        }
    ],
    "peppol_checked_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": 1,
    "default_account": {},
    "default_vat_code": {}
}
schemaTrashItem
  • typestring
    e.g. third_parties
  • idinteger
    e.g. 18
  • labelstring
    e.g. DUBUISSON · Brasserie Dubuisson SA
  • deleted_atstring <date-time>
  • deleted_byobject | null
  • purge_atstring <date-time>
    Date of the definitive purge.
  • restorableboolean
  • blocked_reasonstring | null
  • blocked_messagestring | null
  • versioninteger
Example
{
    "type": "third_parties",
    "id": 18,
    "label": "DUBUISSON · Brasserie Dubuisson SA",
    "deleted_at": "2026-03-15T09:41:00+00:00",
    "deleted_by": {
        "id": 12,
        "name": "Claire Dumont"
    },
    "purge_at": "2026-03-15T09:41:00+00:00",
    "restorable": true,
    "blocked_reason": "string",
    "blocked_message": "string",
    "version": 3
}
schemaTreasury
  • accountsobject[]
    Properties
    • journal_idinteger
      e.g. 7
    • codestring
      e.g. BNP
    • labelstring
      e.g. BNP Paribas Fortis
    • ibanstring | null
    • accountstring
      e.g. 550000
    • accounting_balancestring <decimal>
      e.g. 19630.11
    • last_statement_balancestring <decimal> | null
      e.g. 19630.11
    • last_statement_datestring <date> | null
    • pending_countinteger
      e.g. 3
    • pending_amountstring <decimal>
      e.g. 1842.50
    • differencestring <decimal> | null
      e.g. 0.00
  • total_accounting_balancestring <decimal>
    e.g. 21480.61
Example
{
    "accounts": [
        {
            "journal_id": 7,
            "code": "BNP",
            "label": "BNP Paribas Fortis",
            "iban": "BE68539007547034",
            "account": "550000",
            "accounting_balance": "19630.11",
            "last_statement_balance": "19630.11",
            "last_statement_date": "2026-03-15",
            "pending_count": 3,
            "pending_amount": "1842.50",
            "difference": "0.00"
        }
    ],
    "total_accounting_balance": "21480.61"
}
schemaUserAuthenticated user with the firms it belongs to.

Authenticated user with the firms it belongs to.

  • idinteger
    e.g. 12
  • namestring
    e.g. Claire Dumont
  • emailstring <email>
  • localestring
    fr nl en de
  • email_verifiedboolean
  • pending_emailstring <email> | null
    New address waiting for confirmation.
  • is_platform_adminboolean
    e.g. false
  • is_demoboolean
    True for the ephemeral user of the demo firm.
    e.g. false
  • firmsobject[]
    Properties
    • public_tokenstring
      e.g. NDTQVQU4AUAV
    • namestring
      e.g. Fiduciaire Dumont & Associés
    • rolestring
      admin manager encoder reviewer
  • managed_firmsobject[]
    Properties
    • public_tokenstring
      e.g. NDTQVQU4AUAV
    • namestring
      e.g. Fiduciaire Dumont & Associés
Example
{
    "id": 12,
    "name": "Claire Dumont",
    "email": "claire.dumont@fiduciaire-dumont.be",
    "locale": "fr",
    "email_verified": true,
    "pending_email": "claire.dumont@fiduciaire-dumont.be",
    "is_platform_admin": false,
    "is_demo": false,
    "firms": [
        {
            "public_token": "NDTQVQU4AUAV",
            "name": "Fiduciaire Dumont & Associés",
            "role": "admin"
        }
    ],
    "managed_firms": [
        {
            "public_token": "NDTQVQU4AUAV",
            "name": "Fiduciaire Dumont & Associés"
        }
    ]
}
schemaVatCode
  • idinteger
    e.g. 4
  • company_idinteger
  • codestring
    e.g. V21
  • labelstring
    e.g. Ventes 21 %
  • directionstring
    sale purchase
  • ratestring <decimal>
    e.g. 21.00
  • naturestring
    standard intra_eu cocontractor export exempt import out_of_scope
  • deductible_pctstring <decimal>
    e.g. 100.00
  • base_gridstring | null
    Grid of the taxable base.
    e.g. 03
  • vat_gridstring | null
    Grid of the VAT.
    e.g. 54
  • due_vat_gridstring | null
    Grid of the VAT due (reverse charge).
  • credit_base_gridstring | null
    Grid of the base on a credit note.
    e.g. 49
  • credit_vat_gridstring | null
    e.g. 64
  • vat_accountstring | null
    e.g. 451100
  • due_vat_accountstring | null
  • descriptionstring | null
  • is_activeboolean
  • sort_orderinteger
    e.g. 13
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
Example
{
    "id": 4,
    "company_id": 7,
    "code": "V21",
    "label": "Ventes 21 %",
    "direction": "sale",
    "rate": "21.00",
    "nature": "standard",
    "deductible_pct": "100.00",
    "base_grid": "03",
    "vat_grid": "54",
    "due_vat_grid": "string",
    "credit_base_grid": "49",
    "credit_vat_grid": "64",
    "vat_account": "451100",
    "due_vat_account": "string",
    "description": "Description",
    "is_active": true,
    "sort_order": 13,
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3
}
schemaVatComputation
  • gridsobject
    Belgian VAT grids: grid number => amount (decimal string).
  • amount_duestring <decimal>
    Grid 71.
    e.g. 157.50
  • amount_refundstring <decimal>
    Grid 72.
    e.g. 0.00
  • warningsstring[]
  • entriesinteger
    Entries carrying VAT in the period.
    e.g. 38
Example
{
    "grids": {
        "00": "0.00",
        "01": "0.00",
        "02": "0.00",
        "03": "1000.00",
        "54": "210.00",
        "59": "52.50",
        "71": "157.50",
        "72": "0.00",
        "81": "0.00",
        "82": "250.00",
        "83": "0.00"
    },
    "amount_due": "157.50",
    "amount_refund": "0.00",
    "warnings": [
        "string"
    ],
    "entries": 38
}
schemaVatDeclaration
  • idinteger
    e.g. 14
  • company_idinteger
  • period_typestring
    monthly quarterly
  • yearinteger
    e.g. 2026
  • periodinteger
    Month (1-12) or quarter (1-4).
    e.g. 1
  • starts_onstring <date-time>
  • ends_onstring <date-time>
  • gridsobject
    Belgian VAT grids: grid number => amount (decimal string).
  • amount_duestring <decimal>
    e.g. 157.50
  • amount_refundstring <decimal>
    e.g. 0.00
  • statusstring
    draft validated submitted
  • validated_atstring <date-time> | null
  • validated_byinteger | null
  • submitted_atstring <date-time> | null
  • submission_referencestring | null
    Intervat receipt reference.
  • journal_entry_idinteger | null
    VAT settlement entry.
  • warningsstring[]
  • created_atstring <date-time>
  • updated_atstring <date-time>
  • lock_versioninteger
    Internal lock counter.
    e.g. 3
  • versioninteger
    Version of the record, to send back as X-Base-Version / base_version.
    e.g. 3
  • journal_entryobject | null
Example
{
    "id": 14,
    "company_id": 7,
    "period_type": "monthly",
    "year": 2026,
    "period": 1,
    "starts_on": "2026-03-15T09:41:00+00:00",
    "ends_on": "2026-03-15T09:41:00+00:00",
    "grids": {
        "00": "0.00",
        "01": "0.00",
        "02": "0.00",
        "03": "1000.00",
        "54": "210.00",
        "59": "52.50",
        "71": "157.50",
        "72": "0.00",
        "81": "0.00",
        "82": "250.00",
        "83": "0.00"
    },
    "amount_due": "157.50",
    "amount_refund": "0.00",
    "status": "draft",
    "validated_at": "2026-03-15T09:41:00+00:00",
    "validated_by": 1,
    "submitted_at": "2026-03-15T09:41:00+00:00",
    "submission_reference": "string",
    "journal_entry_id": 1284,
    "warnings": [
        "string"
    ],
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00",
    "lock_version": 3,
    "version": 3,
    "journal_entry": {}
}
schemaVersionConflict409 of the optimistic lock (`X-Base-Version`).

409 of the optimistic lock (X-Base-Version).

  • messagestringrequired
  • codestringrequired
    conflict
  • server_versionintegerrequired
    Current version on the server.
    e.g. 4
  • server_dataobjectrequired
    Current state of the record.
Example
{
    "message": "OK",
    "code": "conflict",
    "server_version": 4,
    "server_data": {}
}
schemaWebhookDelivery
  • idinteger
    e.g. 1871
  • event_idstring
    e.g. evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE
  • eventstring
    e.g. entry.posted
  • statusstring
    pending delivered failed
  • attemptsinteger
    8 attempts at most.
    e.g. 1
  • next_attempt_atstring <date-time> | null
  • response_statusinteger | null
    e.g. 200
  • response_excerptstring | null
  • duration_msinteger | null
    e.g. 184
  • delivered_atstring <date-time> | null
  • created_atstring <date-time>
  • attemptinteger
    Alias of attempts.
    e.g. 1
  • http_statusinteger | null
    Alias of response_status.
    e.g. 200
Example
{
    "id": 1871,
    "event_id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "entry.posted",
    "status": "pending",
    "attempts": 1,
    "next_attempt_at": "2026-03-15T09:41:00+00:00",
    "response_status": 200,
    "response_excerpt": "string",
    "duration_ms": 184,
    "delivered_at": "2026-03-15T09:41:00+00:00",
    "created_at": "2026-03-15T09:41:00+00:00",
    "payload": {
        "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
        "event": "entry.posted",
        "api_version": "v1",
        "created_at": "2026-03-15T09:41:00+00:00",
        "firm": {
            "public_token": "NDTQVQU4AUAV",
            "name": "Fiduciaire Dumont & Associés"
        },
        "company": {
            "public_token": "XBVD5O1L29HC",
            "name": "Le Comptoir Montois SRL"
        },
        "data": {}
    },
    "attempt": 1,
    "http_status": 200
}
schemaWebhookEndpoint
  • idinteger
    e.g. 3
  • urlstring <uri>
    e.g. https://erp.example.com/hooks/novafisko
  • descriptionstring | null
    e.g. ERP connector
  • eventsstring[]
  • is_activeboolean
  • secret_hintstring
    Masked signing secret.
    e.g. whsec_…ab12
  • last_delivery_atstring <date-time> | null
  • last_statusstring | null
    Status of the last delivery.
    e.g. delivered
  • created_atstring <date-time>
  • updated_atstring <date-time>
Example
{
    "id": 3,
    "url": "https://erp.example.com/hooks/novafisko",
    "description": "ERP connector",
    "events": [
        "entry.posted"
    ],
    "is_active": true,
    "secret_hint": "whsec_…ab12",
    "last_delivery_at": "2026-03-15T09:41:00+00:00",
    "last_status": "delivered",
    "created_at": "2026-03-15T09:41:00+00:00",
    "updated_at": "2026-03-15T09:41:00+00:00"
}
schemaWebhookEventBody POSTed to a webhook endpoint. Verify `X-Novafisko-Signature` before trusting it.

Body POSTed to a webhook endpoint. Verify X-Novafisko-Signature before trusting it.

  • idstringrequired
    Unique event id; use it to deduplicate.
    e.g. evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE
  • eventstringrequired
    e.g. entry.posted
  • api_versionstringrequired
    e.g. v1
  • created_atstring <date-time>required
    UTC.
  • firmobjectrequired
    Properties
    • public_tokenstring
      e.g. NDTQVQU4AUAV
    • namestring
      e.g. Fiduciaire Dumont & Associés
  • companyobject | null
    Properties
    • public_tokenstring
      e.g. XBVD5O1L29HC
    • namestring
      e.g. Le Comptoir Montois SRL
  • dataobjectrequired
    Event-specific payload (ids, references, amounts).
Example
{
    "id": "evt_01JD8X5Q2M7Z4W9K3T6B0N1VCE",
    "event": "entry.posted",
    "api_version": "v1",
    "created_at": "2026-03-15T09:41:00+00:00",
    "firm": {
        "public_token": "NDTQVQU4AUAV",
        "name": "Fiduciaire Dumont & Associés"
    },
    "company": {
        "public_token": "XBVD5O1L29HC",
        "name": "Le Comptoir Montois SRL"
    },
    "data": {}
}