Skip to main content

Overview

The SAT publishes lists of taxpayers under Artículo 69, Artículo 69-B and Artículo 69-B Bis of the Código Fiscal — for example taxpayers with cancelled certificates, taxpayers that could not be located, and companies presumed or confirmed to issue simulated invoices (EFOS). Invoicing a taxpayer on one of the risky lists can cost you the deduction. gigstack mirrors these lists and re-syncs them from the SAT’s published CSVs every Sunday, so you can screen a counterparty’s RFC with one call. It also consults the SAT’s public Opinión del Cumplimiento (32-D) service. Base path: https://api.gigstack.io/v2/sat-lists. All endpoints are read-only and require a valid API key.

Endpoints

List the Tracked Lists

Returns every list gigstack tracks and the result of its latest sync.

Check an RFC

The response data: An RFC on no list returns 200 with found: false — a clean RFC is not a 404. An RFC that is not 10-13 characters returns 400. Typical use: before issuing an invoice or registering a new supplier, call this endpoint and block or flag the operation when is_risky is true.

Opinión del Cumplimiento (32-D)

Consults the SAT’s public Opinión del Cumplimiento de Obligaciones Fiscales service for an RFC. Read this before building on it. The SAT’s public service only publishes positive opinions, and only for taxpayers who authorized public disclosure. There are exactly two outcomes: Never present no_autorizado to a user as “opinión negativa”, “incumplido” or anything equivalent: this service cannot tell you that a taxpayer is non-compliant. The response also includes checked_at (epoch ms) and, for no_autorizado, the SAT’s own message. If the SAT cannot be reached or its page cannot be parsed, the call returns 500. That is never reported as no_autorizado, so a no_autorizado is always a real answer from the SAT.

Errors