Skip to main content
The Envoi API uses OAuth 2.0 client credentials. You exchange a client ID and secret for a token, and send the token with every call.

Create an API client

Only the company’s owner and admins can create API clients.
1

Go to API clients

Open Settings → API clients in Envoi and choose Create API client.
2

Choose a type

Accounting client comes set up with access to invoices, customers, journal entries and reports. Advanced setup lets you choose the environment and exactly which permissions the client gets.
3

Copy the secret

The secret is shown once, and Envoi does not store it. Copy it right away and keep it safe. You also need the client ID and account ID.
The secret gives access to the company’s data. Never put it in code that runs in a browser or an app, and never in a public repository.

Get a token

The response:
The token lasts 15 minutes. There is no refresh token: request a new one with the same credentials when it expires.

Use the token

A token covers one company in one environment. Which company a call acts on is decided by the token and cannot be changed with a header or in the URL.

Permissions

Permissions are written as resource:level, for example invoices:write. Levels build on each other: admin includes write, and write includes read. If the client lacks the permission an endpoint needs, you get 403 insufficient_scope.

Changes apply immediately

Envoi checks the client against the database on every call, not just the token:
  • Delete the client, and its tokens are refused on the next call.
  • Rotate the secret, and tokens issued with the old one are refused on the next call.
  • Remove a permission or an environment, and it applies from the next call.

Token endpoint errors

The token endpoint answers with { "error": "<code>" }, as OAuth 2.0 describes.