Skip to main content

Overview

The e-invoice.be API uses Bearer token authentication. Each company has its own API key. Send the key in the Authorization header of each request to https://api.e-invoice.be. The API key identifies the company. Thus the key also controls if a send goes to the Peppol network (production company) or to email (sandbox company).
Develop and test with a sandbox company. A sandbox company runs in test mode: the API sends each document as UBL XML to the contact email address of the company, and nothing goes to the Peppol network. The API host and the endpoints are the same as for a production company. See Test mode and sandbox companies.

Get your API key

1

Sign in

Sign in to app.e-invoice.be.
2

Select the company

Select the company that you want to use. A sandbox company and a production company have different keys.
3

Copy the key

Open API Settings and copy the API key.
Keep your API key secret. Do not put it in version control, in client-side code or in a public location.

Make an authenticated request

Add the header Authorization: Bearer <your API key> to the request. The samples read the key from the environment variable E_INVOICE_API_KEY and call GET /api/me/, which returns the data of the company that owns the key.
A correct key gives a 200 response:
The response also contains the plan and the credit balance. See Usage statistics and credits.

Endpoints without authentication

Three read-only Peppol lookup operations do not require an API key: GET /api/validate/peppol-id, GET /api/lookup and GET /api/lookup/participants. All other operations require the Authorization header.

Best practices

Keep the key in an environment variable

Do not write the key in your source code. Read it from an environment variable or from a secret manager.

Use a different key for tests and for production

Use the key of a sandbox company in your development and test systems. Use the key of a production company only in your production system. The base URL and your code are the same for the two.

Reset a key that is no longer safe

If a key is possibly known to other persons, open API Settings in the app and select Reset API key. The app creates a new key and the previous key stops working. Then update your applications with the new key.

Error responses

A request with no valid key returns 401 Unauthorized with the header WWW-Authenticate: Bearer. If the Authorization header is missing:
If the key is not correct or is deleted:

Troubleshooting

1

Examine the header format

The header value must be Bearer, one space, then the key.
2

Remove spaces

Make sure that the key has no spaces or line breaks before or after it.
3

Make sure that the key is from the correct company

A sandbox company and a production company have different keys. A key that was reset in the app does not work.
4

Test with cURL

Call GET /api/me/ with the -v option and read the response status.
For all status codes and error formats, see Errors and troubleshooting.

Next Steps

Test mode and sandbox companies

Create a sandbox company and learn what test mode does.

Quickstart

Make your first API call.

Create e-invoices

Create and send an e-invoice.

Validation during development

Validate invoice payloads during development.