Overview
The e-invoice.be API uses Bearer token authentication. Each company has its own API key. Send the key in theAuthorization header of each request to https://api.e-invoice.be.
The API key identifies the company. Thus the key also controls if a send goes to the Peppol network (production company) or to email (sandbox company).
Develop and test with a sandbox company. A sandbox company runs in test mode: the API sends each document as UBL XML to the contact email address of the company, and nothing goes to the Peppol network. The API host and the endpoints are the same as for a production company. See Test mode and sandbox companies.
Get your API key
1
Sign in
Sign in to app.e-invoice.be.
2
Select the company
Select the company that you want to use. A sandbox company and a production company have different keys.
3
Copy the key
Open API Settings and copy the API key.
Make an authenticated request
Add the headerAuthorization: Bearer <your API key> to the request. The samples read the key from the environment variable E_INVOICE_API_KEY and call GET /api/me/, which returns the data of the company that owns the key.
200 response:
Endpoints without authentication
Three read-only Peppol lookup operations do not require an API key:GET /api/validate/peppol-id, GET /api/lookup and GET /api/lookup/participants. All other operations require the Authorization header.
Best practices
Keep the key in an environment variable
Do not write the key in your source code. Read it from an environment variable or from a secret manager.Use a different key for tests and for production
Use the key of a sandbox company in your development and test systems. Use the key of a production company only in your production system. The base URL and your code are the same for the two.Reset a key that is no longer safe
If a key is possibly known to other persons, open API Settings in the app and select Reset API key. The app creates a new key and the previous key stops working. Then update your applications with the new key.Error responses
A request with no valid key returns401 Unauthorized with the header WWW-Authenticate: Bearer.
If the Authorization header is missing:
Troubleshooting
1
Examine the header format
The header value must be
Bearer, one space, then the key.2
Remove spaces
Make sure that the key has no spaces or line breaks before or after it.
3
Make sure that the key is from the correct company
A sandbox company and a production company have different keys. A key that was reset in the app does not work.
4
Test with cURL
Call
GET /api/me/ with the -v option and read the response status.Next Steps
Test mode and sandbox companies
Create a sandbox company and learn what test mode does.
Quickstart
Make your first API call.
Create e-invoices
Create and send an e-invoice.
Validation during development
Validate invoice payloads during development.