Automation
API and webhooks
Connect your software, Zapier, Make or n8n with an API key, choose rights, repeat changes safely and set up webhooks.
5 min readLast reviewed: 09.10.2026
Open in SoPasstOverview
With the SoPasst API you connect your own software, your web shop or tools like Zapier, Make and n8n to your company in SoPasst. Webhooks tell your application at once when a document is issued or sent or a payment is recorded.
Requirements
- The Planet, Stern or Galaxie plan. The Komet plan does not include the API.
- You are the owner or an admin of the company.
- For issuing, sending and payments: you are the owner and have set up two-factor sign-in.
Create a key
- Open Settings › API.
- Give the key a name, for example “Zapier web shop”, and choose only the rights your application needs.
- Choose “Create key” and copy the key right away. It starts with soplive and is shown only this once.
- Enter the key in your application as a bearer token: the Authorization header with the value Bearer followed by the key.
Important
A key's rights
- Read: fetch documents including their PDF, customers, products and payments.
- Write drafts: create and change customers, products and drafts of quotes, orders, delivery notes, invoices and credit notes. A draft has no invoice number yet.
- Issue: issue a draft (invoice, quote, order, delivery note). SoPasst checks the mandatory details, assigns the next gapless number and locks the document.
- Send: send an issued document to the customer's stored e-mail address, with your template or your own text.
- Record payments: record incoming payments against invoices, with the same rules as in the app.
- The owner grants issuing, sending and payments once, when the key is created, with the code from the authenticator app. After that SoPasst does not ask again on every call. Storno and credit notes are issued in the app only.
The first request
- The API lives at https://app.sopasst.at/api/v1. The full description of every endpoint is at https://app.sopasst.at/api/v1/openapi.json; Zapier, Make, n8n and Postman can import it directly.
- Check the key with GET /api/v1/me. The answer names the key's rights, your plan and this month's usage.
- Amounts are always whole euro cents, dates have the form YYYY-MM-DD.
Repeat changes safely
- Every POST request needs the Idempotency-Key header with a unique value, for example a UUID.
- If your application sends the same request with the same key again, say after a dropped connection, SoPasst answers with the stored result. An invoice is therefore never issued twice, a payment never recorded twice and no invoice number used up.
- If a request fails, nothing is stored: after fixing it you can use the same value again.
Set up webhooks
- Open Settings › API and enter your application's address under Webhooks. Only https addresses on port 443 with a public host name are allowed.
- Choose the events: document.issued, document.sent and payment.recorded.
- Copy the signing secret shown (whsec…). It is shown only once.
- Verify every message in your application: the webhook-id, webhook-timestamp and webhook-signature headers follow the “Standard Webhooks” standard; many libraries check the signature in one line.
Important
Expected result
Your application receives answers in JSON: a created draft appears in SoPasst under Documents at once, an issued document has its final number and its PDF, and every webhook reaches your address with a valid signature. Settings › API shows this month's usage and the webhook delivery log.
Common problems
- Planet: 5,000 requests and 300 documents created through the API per month. Stern: 50,000 and 3,000. Galaxie: 500,000 requests and 10,000 documents.
- Issuing, sending and payments also have a daily limit; it is far above normal needs.
- When a quota is reached, the API answers HTTP 429 and states in the Retry-After header when it continues. There are never automatic extra charges.
- Every error has a fixed code, for example unauthorized, insufficientscope, validationfailed or quotaexceeded. When you contact support, quote the value of the x-request-id header.
Keep working safely
- Open Settings › API.
- Choose “Revoke” on the key or “Remove” on the webhook and confirm right below.
- Access ends immediately. Create a new key if you need one.