Use the AvrioBooks REST API

The AvrioBooks REST API lets your own software read and write some of your data. It uses JSON and token authentication. Ask us if you would like to be set up for API use.

All plans 5 min read · Updated

Get a token

Send your email address and password to the token endpoint:

POST /api/token/
{"email": "you@example.com", "password": "your-password"}

The response contains an access token and a refresh token.

Call the API

Send the access token in an Authorization header on each request:

Authorization: Bearer <access token>

Refresh the token

Access tokens are short-lived (about five minutes) and refresh tokens last about a day. Exchange the refresh token for a new access token:

POST /api/token/refresh/
{"refresh": "<refresh token>"}

What you can reach

EndpointWhat it does
/api/businesses/The businesses you belong to
/api/<business-slug>/contacts/List, create, update and delete contacts
/api/<business-slug>/invoices/List, create, update and delete sales invoices. Filter with ?type=

Your business-slug is the part of the address after the domain when you are inside a business. You only see businesses you are a member of. Creating an invoice through the API posts it to your ledger just as the web app does.

Tip Create a dedicated user with a role that has only the access your integration needs, and use that sign-in for the API.
Good to know Available endpoints may grow over time. Contact us if you need access to something that is not listed.

An example: list your sales invoices

curl https://app.avriobooks.com/api/your-business-slug/invoices/ \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN"

To filter by type, add a query such as ?type=REVENUE. Replace your-business-slug with the slug that appears in your business’s web address.

Handling expired tokens

Access tokens are short-lived. If a request returns 401 Unauthorized, request a new access token with your refresh token at /api/token/refresh/ and retry. If the refresh token has also expired, sign in again at /api/token/.

Best practice

  • Keep credentials in environment variables or a secrets store, never in source code.
  • Use a dedicated user with only the access your integration needs.
  • Refresh tokens just before they expire rather than on every call.
  • Test against your demo company before writing to your real books.

What the API will not do

The API follows the same rules as the web app: documents dated in a locked period are refused, and the people you connect as can only reach businesses they belong to.

Still stuck? Our team is happy to help. Contact support or book a walkthrough.
Sign up freeContact us