curl --request POST \
--url https://api.gigstack.io/v2/clients/validate/{id} \
--header 'Authorization: Bearer <token>'const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.gigstack.io/v2/clients/validate/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/clients/validate/{id}"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text){
"success": true,
"message": "Client info validated successfully",
"data": {
"fiscal_validation": {
"status": "not_valid",
"message": "Fiscal info validation failed. El campo DomicilioFiscalReceptor del receptor..."
},
"efos": {
"is_valid": false
},
"sat_status": {
"is_risky": true,
"efos": {
"is_valid": false
},
"hits": [
{
"list": "art_69b_definitivos",
"label": "Definitivos 69-B",
"source": "art_69b",
"is_risky": true,
"detail": {
"nombre_del_contribuyente": "ASESORES Y ADMINISTRADORES AGRICOLAS, S. DE R.L. DE C.V.",
"situacion_del_contribuyente": "Definitivo",
"publicacion_dof_definitivos": "28/06/2018"
}
}
],
"checked_at": 1776887458784
}
}
}Validate client fiscal information
Re-runs the full SAT validation for a client on demand. Performs three independent checks in parallel
and persists the results on the client doc (is_valid, efos, sat_status):
- Fiscal validation — attempts to stamp a test CFDI against the PAC. Detects RFC/legal_name/CP mismatches with SAT registry.
- EFOS check — Art. 69-B blacklist lookup.
- SAT lists — fan-out lookup across 20 Datos Abiertos lists (Art. 69 Cancelados/Firmes/No localizados/CSD sin efectos/…, Art. 69-B Definitivos/Presuntos/…, Art. 69-B Bis). Lists are refreshed weekly from
sat.gob.mx.
gigstack Connect: Validate other teams’ clients using the team parameter.
curl --request POST \
--url https://api.gigstack.io/v2/clients/validate/{id} \
--header 'Authorization: Bearer <token>'const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.gigstack.io/v2/clients/validate/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/clients/validate/{id}"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text){
"success": true,
"message": "Client info validated successfully",
"data": {
"fiscal_validation": {
"status": "not_valid",
"message": "Fiscal info validation failed. El campo DomicilioFiscalReceptor del receptor..."
},
"efos": {
"is_valid": false
},
"sat_status": {
"is_risky": true,
"efos": {
"is_valid": false
},
"hits": [
{
"list": "art_69b_definitivos",
"label": "Definitivos 69-B",
"source": "art_69b",
"is_risky": true,
"detail": {
"nombre_del_contribuyente": "ASESORES Y ADMINISTRADORES AGRICOLAS, S. DE R.L. DE C.V.",
"situacion_del_contribuyente": "Definitivo",
"publicacion_dof_definitivos": "28/06/2018"
}
}
],
"checked_at": 1776887458784
}
}
}Authorizations
Authentication Method: HTTP Bearer token.
The runtime requires the literal Bearer prefix — a bare token in the
Authorization header is rejected with 401 unauthorized.
Header Format: Authorization: Bearer YOUR_API_KEY
Your API key is a JWT. Live keys operate on live data (livemode: true);
test keys operate on isolated test data (livemode: false).
Get your key at: app.gigstack.pro/settings?tab=api
Errors: credential failures are answered by the authentication layer with a raw
{ "message": … } body, not the standardized envelope — 401 for a missing, malformed or
expired token, 403 for a revoked key or a plan without API access. See the Unauthorized
and AuthForbidden responses.
Path Parameters
Query Parameters
gigstack Connect: Target team ID for multi-team access.
Requires gigstack Connect enabled on your team and shared billing account.
Also requires the multipleIssuerAccounts feature on your plan. Requests targeting a
team other than the one your API key belongs to return 403 without it.
Only API keys can use it: an OAuth access token sent with another team's id is rejected with
403 Team mismatch with OAuth token.
Optional — omit it entirely unless you are acting on another team. It deliberately
carries no example value so generated snippets do not emit ?team=undefined; when the
parameter is absent, the team is derived from your API key.
Example: ?team=team_xyz789