curl --request POST \
--url https://api.gigstack.io/v2/teams/{id}/manifest/sign \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"key": "MIIFDjBABgkqhkiG9w0BBQ0wMz...",
"cert": "MIIFuzCCA6OgAwIBAgIUMzAwMD...",
"password": "my_secure_password"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
key: 'MIIFDjBABgkqhkiG9w0BBQ0wMz...',
cert: 'MIIFuzCCA6OgAwIBAgIUMzAwMD...',
password: 'my_secure_password'
})
};
fetch('https://api.gigstack.io/v2/teams/{id}/manifest/sign', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/teams/{id}/manifest/sign"
payload = {
"key": "MIIFDjBABgkqhkiG9w0BBQ0wMz...",
"cert": "MIIFuzCCA6OgAwIBAgIUMzAwMD...",
"password": "my_secure_password"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"message": "Manifest signed successfully",
"data": {
"xmlBase64": "PD94bWwgdmVyc2lvbj0iMS4wIi...",
"pdfBase64": "JVBERi0xLjQKJeLjz9MKMyAwIG...",
"fechaFirma": "2024-01-08T15:30:00.000Z",
"mensajeResultado": "Firma exitosa"
}
}Sign manifest document
Signs a manifest document (Carta Manifiesto) using the FIEL (Firma Electrónica Avanzada) for SAT compliance.
This endpoint is used to sign the authorization manifest that authorizes the PAC (Proveedor Autorizado de Certificación) to issue CFDI invoices on behalf of your team’s RFC. The manifest must be signed to grant the PAC permission to stamp and process invoices under your team’s tax identification.
Important Notes:
- Your SAT configuration must be completed before signing the manifest
- The FIEL certificate must be valid and issued by SAT
- The certificate must match your team’s RFC
- Once signed, the manifest is stored in your team’s SAT configuration
- The manifest includes both XML and PDF files
Supported Formats:
-
JSON format (application/json):
- Send Base64 encoded certificate files
- Useful for API integrations
-
Form Data format (multipart/form-data):
- Upload certificate files directly
- Useful for web form submissions
Note: The team and livemode parameters are automatically extracted from your JWT token and applied to the request.
You do not need to include these fields in the request body.
curl --request POST \
--url https://api.gigstack.io/v2/teams/{id}/manifest/sign \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"key": "MIIFDjBABgkqhkiG9w0BBQ0wMz...",
"cert": "MIIFuzCCA6OgAwIBAgIUMzAwMD...",
"password": "my_secure_password"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
key: 'MIIFDjBABgkqhkiG9w0BBQ0wMz...',
cert: 'MIIFuzCCA6OgAwIBAgIUMzAwMD...',
password: 'my_secure_password'
})
};
fetch('https://api.gigstack.io/v2/teams/{id}/manifest/sign', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/teams/{id}/manifest/sign"
payload = {
"key": "MIIFDjBABgkqhkiG9w0BBQ0wMz...",
"cert": "MIIFuzCCA6OgAwIBAgIUMzAwMD...",
"password": "my_secure_password"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"message": "Manifest signed successfully",
"data": {
"xmlBase64": "PD94bWwgdmVyc2lvbj0iMS4wIi...",
"pdfBase64": "JVBERi0xLjQKJeLjz9MKMyAwIG...",
"fechaFirma": "2024-01-08T15:30:00.000Z",
"mensajeResultado": "Firma exitosa"
}
}Authorizations
Authentication Method: HTTP Bearer token.
The runtime requires the literal Bearer prefix — a bare token in the
Authorization header is rejected with 401 unauthorized.
Header Format: Authorization: Bearer YOUR_API_KEY
Your API key is a JWT. Live keys operate on live data (livemode: true);
test keys operate on isolated test data (livemode: false).
Get your key at: app.gigstack.pro/settings?tab=api
Errors: credential failures are answered by the authentication layer with a raw
{ "message": … } body, not the standardized envelope — 401 for a missing, malformed or
expired token, 403 for a revoked key or a plan without API access. See the Unauthorized
and AuthForbidden responses.
Path Parameters
Team ID to sign manifest for
Query Parameters
gigstack Connect: Target team ID for multi-team access.
Requires gigstack Connect enabled on your team and shared billing account.
Also requires the multipleIssuerAccounts feature on your plan. Requests targeting a
team other than the one your API key belongs to return 403 without it.
Only API keys can use it: an OAuth access token sent with another team's id is rejected with
403 Team mismatch with OAuth token.
Optional — omit it entirely unless you are acting on another team. It deliberately
carries no example value so generated snippets do not emit ?team=undefined; when the
parameter is absent, the team is derived from your API key.
Example: ?team=team_xyz789