curl --request GET \
--url https://api.gigstack.io/v2/sat-lists \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.gigstack.io/v2/sat-lists', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/sat-lists"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"success": true,
"data": [
{
"key": "art_69b_definitivos",
"label": "Definitivos 69-B",
"source": "art_69b",
"is_risky": true,
"filename": "Definitivos.csv",
"sync": {
"last_sync_at": "2026-09-06T06:00:00.000Z",
"last_status": "ok",
"row_count": 12843,
"previous_row_count": 12790,
"net_new": 53,
"removed": 0,
"duration_ms": 48210
}
}
],
"message": "SAT lists retrieved successfully",
"timestamp": 1767225600000
}List SAT lists and sync status
Returns every SAT list definition tracked by gigstack, together with the metadata from its most recent sync.
gigstack mirrors the RFC lists the SAT publishes under Artículo 69, Artículo 69-B and Artículo 69-B Bis. The lists are re-synced automatically every Sunday from the SAT’s published CSVs.
Each list carries an is_risky flag. Risky lists (for example Cancelados, Definitivos 69-B, No localizados,
CSD sin efectos) are the ones that indicate a counterparty you should not invoice; the remaining lists are
informational only.
The sync object is null for a list that has never completed a sync.
curl --request GET \
--url https://api.gigstack.io/v2/sat-lists \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.gigstack.io/v2/sat-lists', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/sat-lists"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"success": true,
"data": [
{
"key": "art_69b_definitivos",
"label": "Definitivos 69-B",
"source": "art_69b",
"is_risky": true,
"filename": "Definitivos.csv",
"sync": {
"last_sync_at": "2026-09-06T06:00:00.000Z",
"last_status": "ok",
"row_count": 12843,
"previous_row_count": 12790,
"net_new": 53,
"removed": 0,
"duration_ms": 48210
}
}
],
"message": "SAT lists retrieved successfully",
"timestamp": 1767225600000
}Authorizations
Authentication Method: HTTP Bearer token.
The runtime requires the literal Bearer prefix — a bare token in the
Authorization header is rejected with 401 unauthorized.
Header Format: Authorization: Bearer YOUR_API_KEY
Your API key is a JWT. Live keys operate on live data (livemode: true);
test keys operate on isolated test data (livemode: false).
Get your key at: app.gigstack.pro/settings?tab=api
Errors: credential failures are answered by the authentication layer with a raw
{ "message": … } body, not the standardized envelope — 401 for a missing, malformed or
expired token, 403 for a revoked key or a plan without API access. See the Unauthorized
and AuthForbidden responses.
Query Parameters
gigstack Connect: Target team ID for multi-team access.
Requires gigstack Connect enabled on your team and shared billing account.
Also requires the multipleIssuerAccounts feature on your plan. Requests targeting a
team other than the one your API key belongs to return 403 without it.
Only API keys can use it: an OAuth access token sent with another team's id is rejected with
403 Team mismatch with OAuth token.
Optional — omit it entirely unless you are acting on another team. It deliberately
carries no example value so generated snippets do not emit ?team=undefined; when the
parameter is absent, the team is derived from your API key.
Example: ?team=team_xyz789