curl --request POST \
--url http://localhost:3500/v1/invoices/imports \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"primary_document_id": "11111111-1111-4111-8111-111111111111"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({primary_document_id: '11111111-1111-4111-8111-111111111111'})
};
fetch('http://localhost:3500/v1/invoices/imports', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "http://localhost:3500/v1/invoices/imports"
payload = { "primary_document_id": "11111111-1111-4111-8111-111111111111" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"outcome": "duplicate",
"invoice_id": "55555555-5555-4555-8555-555555555555"
}{
"outcome": "accepted",
"import_id": "33333333-3333-4333-8333-333333333333",
"workflow_run_id": "44444444-4444-4444-8444-444444444444",
"workflow_run_item_id": "66666666-6666-4666-8666-666666666666"
}{
"error": {
"code": "validation_error",
"message": "Invalid request format, parameters, or body. Details contain up to 20 actionable field errors; the complete encoded request body must be at most 2 MiB (2,097,152 bytes).",
"request_id": "req_example"
}
}{
"error": {
"code": "invalid_token",
"message": "Missing or invalid bearer credential.",
"request_id": "req_example"
}
}{
"error": {
"code": "forbidden",
"message": "Access denied: forbidden, token_disabled, organization_required, insufficient_role, or mfa_required. Check the error code and effective permissions.",
"request_id": "req_example"
}
}{
"error": {
"code": "conflict",
"message": "Conflicting idempotency key or permanently deleted replay target, unavailable capacity, incompatible import state, or source already in use. source_unavailable means source bytes are missing or changed; inspect error.code. An execution conflict after admission includes import_id.",
"request_id": "req_example"
}
}{
"error": {
"code": "rate_limit_exceeded",
"message": "The IP or authenticated credential exceeded its request limit.",
"request_id": "req_example"
}
}{
"error": {
"code": "internal_error",
"message": "Unexpected server failure. Include the request ID when contacting support.",
"request_id": "req_example"
}
}{
"error": {
"code": "service_unavailable",
"message": "Authentication or admission is temporarily unavailable, or execution acceptance could not be confirmed. When error.import_id and Location are present, the import is retained: read its status before an explicit retry. Replaying the same key does not redispatch work.",
"request_id": "req_example"
}
}Import an invoice from Documents
Admits one primary Document and distinct, ordered attachments (100 bytes minimum per file; 50 MiB primary, 25 MiB per attachment; no attachment-count or combined-size cap) after their bytes have been uploaded. A known primary-file duplicate returns the existing invoice without starting work. The same business-identity guard used by structured creation checks extracted invoice fields before publication; a match completes as duplicate. Idempotency-Key is optional and protects request retries. New admissions reserve capacity and return 202 only after execution acceptance is confirmed. PDF imports use model extraction. Primary XML must be PEPPOL BIS Billing 3.0 UBL Invoice or CreditNote; unsupported XML fails during processing without model fallback. Usable extraction can publish a financially invalid invoice. A replay returns the original admission reference without starting or redispatching work; read the import for current status.
curl --request POST \
--url http://localhost:3500/v1/invoices/imports \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"primary_document_id": "11111111-1111-4111-8111-111111111111"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({primary_document_id: '11111111-1111-4111-8111-111111111111'})
};
fetch('http://localhost:3500/v1/invoices/imports', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "http://localhost:3500/v1/invoices/imports"
payload = { "primary_document_id": "11111111-1111-4111-8111-111111111111" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"outcome": "duplicate",
"invoice_id": "55555555-5555-4555-8555-555555555555"
}{
"outcome": "accepted",
"import_id": "33333333-3333-4333-8333-333333333333",
"workflow_run_id": "44444444-4444-4444-8444-444444444444",
"workflow_run_item_id": "66666666-6666-4666-8666-666666666666"
}{
"error": {
"code": "validation_error",
"message": "Invalid request format, parameters, or body. Details contain up to 20 actionable field errors; the complete encoded request body must be at most 2 MiB (2,097,152 bytes).",
"request_id": "req_example"
}
}{
"error": {
"code": "invalid_token",
"message": "Missing or invalid bearer credential.",
"request_id": "req_example"
}
}{
"error": {
"code": "forbidden",
"message": "Access denied: forbidden, token_disabled, organization_required, insufficient_role, or mfa_required. Check the error code and effective permissions.",
"request_id": "req_example"
}
}{
"error": {
"code": "conflict",
"message": "Conflicting idempotency key or permanently deleted replay target, unavailable capacity, incompatible import state, or source already in use. source_unavailable means source bytes are missing or changed; inspect error.code. An execution conflict after admission includes import_id.",
"request_id": "req_example"
}
}{
"error": {
"code": "rate_limit_exceeded",
"message": "The IP or authenticated credential exceeded its request limit.",
"request_id": "req_example"
}
}{
"error": {
"code": "internal_error",
"message": "Unexpected server failure. Include the request ID when contacting support.",
"request_id": "req_example"
}
}{
"error": {
"code": "service_unavailable",
"message": "Authentication or admission is temporarily unavailable, or execution acceptance could not be confirmed. When error.import_id and Location are present, the import is retained: read its status before an explicit retry. Replaying the same key does not redispatch work.",
"request_id": "req_example"
}
}Authorizations
Personal API key. Send X-Organization-Id. The required cumulative level is listed in x-watchdog-permission.
Headers
Required for personal API keys. Target one organization you have access to. Migrated keys may omit it to use their original organization. For Clerk sessions, it must match the active organization.
Optional protection for safely retrying a request after a timeout or lost response. Choose a unique value (for example, a UUID) for each action and reuse it with the same input when retrying. Omit it for a normal request.
1 - 200^[\x21-\x7e]+$