curl --request GET \
--url https://api.gigstack.io/v2/sat-lists/32d/{rfc} \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.gigstack.io/v2/sat-lists/32d/{rfc}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/sat-lists/32d/{rfc}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"success": true,
"data": {
"rfc": "EKU9003173C9",
"status": "no_autorizado",
"found": false,
"pdf_url": null,
"checked_at": 1767225600000
},
"message": "SAT publishes no 32-D opinion for RFC EKU9003173C9 — the result is unknown, not negative",
"timestamp": 1767225600000
}Consult the SAT "Opinión del Cumplimiento" (32-D) for an RFC
Consults the SAT’s public Opinión del Cumplimiento de Obligaciones Fiscales (Artículo 32-D) service for an RFC and, when the SAT publishes one, returns a link to the constancia PDF.
How to read the result — please read before building on this
The SAT’s public service only ever publishes positive opinions, and only for taxpayers who explicitly authorized public disclosure of their opinion. There are exactly two outcomes:
status: "positiva"(found: true) — the SAT publishes a positive opinion for this RFC, andpdf_urllinks to the constancia.status: "no_autorizado"(found: false) — the SAT publishes nothing for this RFC. This means the result is unknown. Either the taxpayer never opted in to public disclosure, or no opinion is published. It is not a negative opinion, it is not evidence of non-compliance, and it must never be shown to a user as “opinión negativa”, “incumplido”, or anything equivalent. The only correct reading is “the SAT does not publish an opinion for this RFC”.
There is no third status: the SAT never exposes negative opinions through this service, so this endpoint can never tell you that a taxpayer is non-compliant.
A failure reaching the SAT — network error, or the SAT changing its page — returns 500. It is never
collapsed into no_autorizado, so no_autorizado always reflects a real answer from the SAT.
curl --request GET \
--url https://api.gigstack.io/v2/sat-lists/32d/{rfc} \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.gigstack.io/v2/sat-lists/32d/{rfc}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/sat-lists/32d/{rfc}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"success": true,
"data": {
"rfc": "EKU9003173C9",
"status": "no_autorizado",
"found": false,
"pdf_url": null,
"checked_at": 1767225600000
},
"message": "SAT publishes no 32-D opinion for RFC EKU9003173C9 — the result is unknown, not negative",
"timestamp": 1767225600000
}Authorizations
Authentication Method: HTTP Bearer token.
The runtime requires the literal Bearer prefix — a bare token in the
Authorization header is rejected with 401 unauthorized.
Header Format: Authorization: Bearer YOUR_API_KEY
Your API key is a JWT. Live keys operate on live data (livemode: true);
test keys operate on isolated test data (livemode: false).
Get your key at: app.gigstack.pro/settings?tab=api
Errors: credential failures are answered by the authentication layer with a raw
{ "message": … } body, not the standardized envelope — 401 for a missing, malformed or
expired token, 403 for a revoked key or a plan without API access. See the Unauthorized
and AuthForbidden responses.
Path Parameters
The RFC to consult. Case-insensitive; must be 10-13 characters.
10 - 13"EKU9003173C9"
Query Parameters
gigstack Connect: Target team ID for multi-team access.
Requires gigstack Connect enabled on your team and shared billing account.
Also requires the multipleIssuerAccounts feature on your plan. Requests targeting a
team other than the one your API key belongs to return 403 without it.
Only API keys can use it: an OAuth access token sent with another team's id is rejected with
403 Team mismatch with OAuth token.
Optional — omit it entirely unless you are acting on another team. It deliberately
carries no example value so generated snippets do not emit ?team=undefined; when the
parameter is absent, the team is derived from your API key.
Example: ?team=team_xyz789
Response
The SAT was consulted successfully (for both positiva and no_autorizado)
Standardized success envelope emitted by sendSuccessResponse.
true true
Result of consulting the SAT's public "Opinión del Cumplimiento" (32-D) service for a single RFC.
Read status carefully: the SAT's public service only ever publishes positive opinions, and only
for taxpayers who explicitly authorized public disclosure. no_autorizado therefore means the result
is unknown — it is not a negative opinion and must never be presented as non-compliance.
Show child attributes
Show child attributes
Server time in epoch milliseconds (Luxon.now().toMillis()).
1767225600000
Human-readable summary. Present only when the handler supplies one.
"Operation completed successfully"