curl --request POST \
--url https://api.gigstack.io/v2/invoices/download/import \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"uuids": [
"<string>"
],
"confirm_cost_mxn": 12.4
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({uuids: ['<string>'], confirm_cost_mxn: 12.4})
};
fetch('https://api.gigstack.io/v2/invoices/download/import', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/invoices/download/import"
payload = {
"uuids": ["<string>"],
"confirm_cost_mxn": 12.4
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"success": true,
"message": "2 facturas en cola de descarga",
"data": {
"queued": 2,
"estimated_cost_mxn": 0.4,
"skipped": [
{
"uuid": "A1B2C3D4-E5F6-7890-ABCD-1234567890AB",
"reason": "already_imported"
}
]
}
}Download XMLs for chosen CFDIs
Availability: This operation has no configured public API gateway route and is not available through the documented base URL.
This is the billed call. Each XML costs $0.20 MXN, charged once per CFDI.
Takes UUIDs that are currently in the metadata stage — typically ones you found via a preview and GET /invoices/sat?sync_state=metadata — and queues their XML download.
Cost confirmation. The server always recomputes the cost; confirm_cost_mxn is only ever checked against it, never trusted. Send it and a mismatch returns 409 rather than charging a different amount than you were shown. Omit it and the call is allowed only up to 100 invoices; past that confirmation is required, so a large import cannot happen by accident.
Anything not importable is reported in skipped with a reason rather than failing the call: not_found, wrong_team, already_imported, already_queued, is_nomina (nómina XMLs carry employee PII and are never downloadable), not_importable.
curl --request POST \
--url https://api.gigstack.io/v2/invoices/download/import \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"uuids": [
"<string>"
],
"confirm_cost_mxn": 12.4
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({uuids: ['<string>'], confirm_cost_mxn: 12.4})
};
fetch('https://api.gigstack.io/v2/invoices/download/import', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/invoices/download/import"
payload = {
"uuids": ["<string>"],
"confirm_cost_mxn": 12.4
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"success": true,
"message": "2 facturas en cola de descarga",
"data": {
"queued": 2,
"estimated_cost_mxn": 0.4,
"skipped": [
{
"uuid": "A1B2C3D4-E5F6-7890-ABCD-1234567890AB",
"reason": "already_imported"
}
]
}
}Authorizations
Authentication Method: HTTP Bearer token.
The runtime requires the literal Bearer prefix — a bare token in the
Authorization header is rejected with 401 unauthorized.
Header Format: Authorization: Bearer YOUR_API_KEY
Your API key is a JWT. Live keys operate on live data (livemode: true);
test keys operate on isolated test data (livemode: false).
Get your key at: app.gigstack.pro/settings?tab=api
Errors: credential failures are answered by the authentication layer with a raw
{ "message": … } body, not the standardized envelope — 401 for a missing, malformed or
expired token, 403 for a revoked key or a plan without API access. See the Unauthorized
and AuthForbidden responses.
Query Parameters
gigstack Connect: Target team ID for multi-team access.
Requires gigstack Connect enabled on your team and shared billing account.
Also requires the multipleIssuerAccounts feature on your plan. Requests targeting a
team other than the one your API key belongs to return 403 without it.
Only API keys can use it: an OAuth access token sent with another team's id is rejected with
403 Team mismatch with OAuth token.
Optional — omit it entirely unless you are acting on another team. It deliberately
carries no example value so generated snippets do not emit ?team=undefined; when the
parameter is absent, the team is derived from your API key.
Example: ?team=team_xyz789