Get a token
Send your email address and password to the token endpoint:
POST /api/token/
{"email": "you@example.com", "password": "your-password"}
The response contains an access token and a refresh token.
Call the API
Send the access token in an Authorization header on each request:
Authorization: Bearer <access token>
Refresh the token
Access tokens are short-lived (about five minutes) and refresh tokens last about a day. Exchange the refresh token for a new access token:
POST /api/token/refresh/
{"refresh": "<refresh token>"}
What you can reach
| Endpoint | What it does |
|---|---|
/api/businesses/ | The businesses you belong to |
/api/<business-slug>/contacts/ | List, create, update and delete contacts |
/api/<business-slug>/invoices/ | List, create, update and delete sales invoices. Filter with ?type= |
Your business-slug is the part of the address after the domain when you are inside a business. You only see businesses you are a member of. Creating an invoice through the API posts it to your ledger just as the web app does.
An example: list your sales invoices
curl https://app.avriobooks.com/api/your-business-slug/invoices/ \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"
To filter by type, add a query such as ?type=REVENUE. Replace your-business-slug with the slug that appears in your business’s web address.
Handling expired tokens
Access tokens are short-lived. If a request returns 401 Unauthorized, request a new access token with your refresh token at /api/token/refresh/ and retry. If the refresh token has also expired, sign in again at /api/token/.
Best practice
- Keep credentials in environment variables or a secrets store, never in source code.
- Use a dedicated user with only the access your integration needs.
- Refresh tokens just before they expire rather than on every call.
- Test against your demo company before writing to your real books.
What the API will not do
The API follows the same rules as the web app: documents dated in a locked period are refused, and the people you connect as can only reach businesses they belong to.