curl --request POST \
--url https://api.gigstack.io/v2/invoices/download/pfx \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"pfx": "<BASE64_PFX_PLACEHOLDER>",
"pfx_password": "<PFX_PASSWORD_PLACEHOLDER>"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({pfx: '<BASE64_PFX_PLACEHOLDER>', pfx_password: '<PFX_PASSWORD_PLACEHOLDER>'})
};
fetch('https://api.gigstack.io/v2/invoices/download/pfx', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/invoices/download/pfx"
payload = {
"pfx": "<BASE64_PFX_PLACEHOLDER>",
"pfx_password": "<PFX_PASSWORD_PLACEHOLDER>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"success": true,
"message": "FIEL credentials connected successfully",
"data": {
"rfc": "MEE200101ABC",
"expires_at": 1893456000000,
"expires_at_readable": "31/12/2029",
"serial_number": "00001000000512345678",
"sync_start_date": "2023-08-05",
"registered": true,
"registered_at": 1767225600000
}
}Connect FIEL credentials from a PFX file
Register the team’s FIEL (e.firma) with the bulk-download service by uploading a PKCS#12 / PFX bundle and its password.
⚠️ Sensitive credentials
pfxandpfx_passwordare live security credentials — the PFX embeds the FIEL private key, and the password unlocks it. Together they can impersonate the taxpayer before the SAT.
- Send them only over TLS, only to this endpoint.
- Never log them, never put them in a URL, never commit them, never paste them into a shared document or ticket.
- The example values below are placeholders, not usable credentials. Do not treat any example in this document as a real secret to copy.
The server encrypts both values at rest and never returns them in any response.
The certificate is validated before anything is stored: it must parse with the supplied password, must not be expired, and its RFC must match the team’s configured RFC. Each RFC needs its own team.
curl --request POST \
--url https://api.gigstack.io/v2/invoices/download/pfx \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"pfx": "<BASE64_PFX_PLACEHOLDER>",
"pfx_password": "<PFX_PASSWORD_PLACEHOLDER>"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({pfx: '<BASE64_PFX_PLACEHOLDER>', pfx_password: '<PFX_PASSWORD_PLACEHOLDER>'})
};
fetch('https://api.gigstack.io/v2/invoices/download/pfx', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/invoices/download/pfx"
payload = {
"pfx": "<BASE64_PFX_PLACEHOLDER>",
"pfx_password": "<PFX_PASSWORD_PLACEHOLDER>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"success": true,
"message": "FIEL credentials connected successfully",
"data": {
"rfc": "MEE200101ABC",
"expires_at": 1893456000000,
"expires_at_readable": "31/12/2029",
"serial_number": "00001000000512345678",
"sync_start_date": "2023-08-05",
"registered": true,
"registered_at": 1767225600000
}
}Authorizations
Authentication Method: HTTP Bearer token.
The runtime requires the literal Bearer prefix — a bare token in the
Authorization header is rejected with 401 unauthorized.
Header Format: Authorization: Bearer YOUR_API_KEY
Your API key is a JWT. Live keys operate on live data (livemode: true);
test keys operate on isolated test data (livemode: false).
Get your key at: app.gigstack.pro/settings?tab=api
Errors: credential failures are answered by the authentication layer with a raw
{ "message": … } body, not the standardized envelope — 401 for a missing, malformed or
expired token, 403 for a revoked key or a plan without API access. See the Unauthorized
and AuthForbidden responses.
Query Parameters
gigstack Connect: Target team ID for multi-team access.
Requires gigstack Connect enabled on your team and shared billing account.
Also requires the multipleIssuerAccounts feature on your plan. Requests targeting a
team other than the one your API key belongs to return 403 without it.
Only API keys can use it: an OAuth access token sent with another team's id is rejected with
403 Team mismatch with OAuth token.
Optional — omit it entirely unless you are acting on another team. It deliberately
carries no example value so generated snippets do not emit ?team=undefined; when the
parameter is absent, the team is derived from your API key.
Example: ?team=team_xyz789
Body
Sensitive. Base64-encoded PFX/PKCS#12 file containing the FIEL certificate and private key. Never logged or echoed back.
"<BASE64_PFX_PLACEHOLDER>"
Sensitive. Password protecting the PFX file. Never logged or echoed back.
"<PFX_PASSWORD_PLACEHOLDER>"