curl --request GET \
--url https://{subdomain}.conveyour.com/api/org/invoices \
--header 'x-conveyour-token: <api-key>'const options = {method: 'GET', headers: {'x-conveyour-token': '<api-key>'}};
fetch('https://{subdomain}.conveyour.com/api/org/invoices', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const options = {method: 'GET', headers: {'x-conveyour-token': '<api-key>'}};
fetch('https://{subdomain}.conveyour.com/api/org/invoices', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{subdomain}.conveyour.com/api/org/invoices"
headers = {"x-conveyour-token": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{subdomain}.conveyour.com/api/org/invoices",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-conveyour-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"status": "ok",
"message": "success",
"data": {
"jwt_token": "eyJ...",
"invoices": [
{
"id": "in_...",
"date": 1719792000,
"status": "paid",
"number": "ACME-0001",
"subtotal": 9900,
"url": "https://invoice.stripe.com/i/...",
"action": "",
"payment_intent_id": "pi_..."
}
]
}
}{
"status": "failed",
"message": "Lacking necessary permission add_contacts",
"data": {
"permission": "add_contacts"
}
}List invoices
Returns the organization’s recent Stripe invoices (up to 12) plus a billing JWT. Requires the manage_billing permission.
List recent Stripe invoices (manage_billing)
Not callable with an API key. Requires manage_billing, which ConveYour never grants to service accounts (deny_for_types: [service]), so every API key gets 403. Only a signed-in user with this permission can call it.
Permission: requires manage_billing.
curl --request GET \
--url https://{subdomain}.conveyour.com/api/org/invoices \
--header 'x-conveyour-token: <api-key>'const options = {method: 'GET', headers: {'x-conveyour-token': '<api-key>'}};
fetch('https://{subdomain}.conveyour.com/api/org/invoices', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const options = {method: 'GET', headers: {'x-conveyour-token': '<api-key>'}};
fetch('https://{subdomain}.conveyour.com/api/org/invoices', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{subdomain}.conveyour.com/api/org/invoices"
headers = {"x-conveyour-token": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{subdomain}.conveyour.com/api/org/invoices",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-conveyour-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"status": "ok",
"message": "success",
"data": {
"jwt_token": "eyJ...",
"invoices": [
{
"id": "in_...",
"date": 1719792000,
"status": "paid",
"number": "ACME-0001",
"subtotal": 9900,
"url": "https://invoice.stripe.com/i/...",
"action": "",
"payment_intent_id": "pi_..."
}
]
}
}{
"status": "failed",
"message": "Lacking necessary permission add_contacts",
"data": {
"permission": "add_contacts"
}
}Authorizations
Your API key token. Contacts endpoints require a Server-only — Full API key — see Authentication.
Query Parameters
Team scope for the request, as one or more team ObjectIds. The brackets are required: PHP keeps only the last value for a repeated plain key, so teams=A&teams=B silently resolves to B alone. On requests with a JSON body you may send teams (no brackets) in the body instead.
Values that are not valid ObjectIds are silently ignored — a mistyped team ID behaves as if no team was sent. See the teams section of the API conventions guide.