Authentication

Organization API keys

Keys created under Developer → API keys are organization API keys (pk_…). Send Authorization: Api-Key <pk_…> on every authenticated API request. For taxpayer-specific operations, also send x-ae-taxpayer-id: <txpay_…>, even when your organization has only one taxpayer. This applies in Live and Sandbox.

OperationRequired headers with an organization API key
Send, validate, list or retrieve documents; reports; taxpayer settingsAuthorization and x-ae-taxpayer-id
A taxpayer's Business Card or Directory listingAuthorization and x-ae-taxpayer-id
List connected taxpayers or grantsAuthorization only

Create the key in the same portal mode as the taxpayer. Obtain its Taxpayer ID from Taxpayers → taxpayer details → Taxpayer ID, or taxpayer_id in GET /taxpayers after consent. An allocated ID alone does not authorize access: onboarding must be complete and your organization must hold an active grant with the required scopes. The taxpayer must be active.

Use the opaque txpay_… value, not the TIN, 0235:<TIN>, or organization ID. participant_id (0235:<TIN>) identifies the taxpayer on the Peppol network; it is not the Taxpayer ID.

Taxpayer access and OAuth

Taxpayers are not owned by an organization. They approve your organization's access and scopes on the Wafeq e-invoicing ASP consent screen. Use the connection flow: authorization code with PKCE (S256 only), followed by a server-side exchange at POST /oauth/token.

Send Authorization: Bearer <access_token> to act for the one taxpayer named by that token. The x-ae-taxpayer-id header is then optional.

ScopeAccess
taxpayer:readRead taxpayer details
invoices:readRead every document of the taxpayer, including documents other organizations issued
invoices:writeSend, validate and change documents
inbound:readRead documents other access points sent to the taxpayer

An organization API key with x-ae-taxpayer-id acts through all of that organization's active grants on the taxpayer. Add x-ae-grant-id: <tgr_…> to act through a single grant, so revoking it immediately stops those requests. An API key never bypasses consent.

Disconnecting and credential storage

Disconnect a taxpayer with DELETE /grants/{grant_id}. Requests outside your grants, or after the taxpayer revokes your access, return 403. Subscribe to taxpayer webhooks and reconcile grants when access changes.

Keep API keys, client secrets, access tokens and refresh tokens on your server. Use the matching Live or Sandbox OAuth client and credentials. Never embed secrets in browser code, mobile apps, URLs or logs.


Did this page help you?