Store a credential, encrypted; the value is never returned
- In the sandbox
In plain words
A process stores credentials for its own environment only. legal_entity ties one to the seller id it acts for (VAT id, NIP, SIREN or company id); an untagged one serves the client's other invoices. A client's admin key stores for its own client only.
apiKeyAuthorizationBearer <token>Send your key as a bearer token: Authorization: Bearer <your-api-key>. Health is the only call that needs no key.
application/json- body
client*stringOptional with a client key
^[A-Za-z0-9][A-Za-z0-9._-]{0,63}$route*string"PL-KSEF""RO-EFACTURA""PEPPOL""FR-PA""DE-XRECHNUNG"kind*stringissued_by*stringissued_on*stringdateexpires_on?stringdateenvironment?stringMust be this process's environment; that is the default.
"sandbox""production"legal_entity?stringlength <= 64value*stringStored.
application/json- response
id?stringclient?stringroute?stringkind?stringissued_by?stringissued_on?stringexpires_on?stringenvironment?|sandbox or production; null for a credential stored before 3 Oct 2026, which only a sandbox uses.
legal_entity?stringrevoked_at?stringstored?booleancurl -X POST "https://example.com/credentials" \ -H "Authorization: Bearer <your-api-key>" \ -H "Content-Type: application/json" \ -d '{ "client": "string", "route": "PL-KSEF", "kind": "string", "issued_by": "string", "issued_on": "2019-08-24", "value": "string" }'{ "id": "string", "client": "string", "route": "string", "kind": "string", "issued_by": "string", "issued_on": "string", "expires_on": "string", "environment": "string", "legal_entity": "string", "revoked_at": "string", "stored": true}Revoke a credential; the record stays for the audit trail POST
Previous
Stop an invoice that has not been submitted yet POST
Works only while the invoice is received, validated or queued. Since 0.18.3, once a send was tried and its answer was lost (a timeout or a 5xx), the invoice reads submitting and a cancel answers 409 send-in-progress, because the route may hold it; the worker settles it as submitted or dead_letter. Once the route has it, a cancellation is a business document (a credit note, or a KOR in Poland), not an API call. Since 0.18.5 a cancel of an invoice that is already cancelled answers 200 with it, so a retry after a lost answer is safe. Since 0.18.6 the operator's key may cancel a dead_letter invoice when no call to the route was ever made for it: nothing can be on the route, so the same document can be sent again afterwards. When a call was made, the answer is 409 dead-letter-reached-rail, because a send whose answer was lost may be there: check with the route first. A client's key gets 409 dead-letter; the operator decides.