Authentication
Create a Business token in the app, send it as a bearer token, and understand its scope and lifetime.
Every request to the F-sąskaita API is authenticated with a Business token. The token identifies one business in your account, and every invoice, expense or profile you touch belongs to that business.
Create a token
- Sign in to app.fsaskaita.lt as a user who can manage the business.
- Open Settings, then Integrations, then API.
- Give the token a name that tells you where it is used, such as
accounting-sync, and create it. - Copy the token immediately. It is shown once. Afterwards only its name is listed.
Tokens are only available on plans that include the API feature. If the section shows an upgrade notice instead of the form, the current plan does not include it.
Use the token
Send it in the Authorization header and always request JSON:
curl https://app.fsaskaita.lt/api/profile \
-H "Authorization: Bearer $FSASKAITA_TOKEN" \
-H "Accept: application/json"A successful response describes the business behind the token:
{
"data": {
"business_id": "9c1f7b2e-3a6d-4d5e-9f0a-2b7c8d9e0f11",
"business_title": "Pavyzdys, MB",
"business_type": "small_partnership",
"address": "Gedimino pr. 1, Vilnius",
"vat_code": "LT100001234567",
"company_name": "Pavyzdys, MB",
"company_code": "305000001"
}
}For a business registered as individual activity the profile carries individual_activity_id, first_name and last_name instead of company_name and company_code.
Why the Accept header matters
Application errors come back as JSON either way. Without Accept: application/json, however, a missing or revoked token answers with an HTML redirect to the login page, and a rate-limited request answers with an HTML error page. With the header you get 401 {"message":"Unauthenticated."} and 429 {"message":"Too Many Attempts."}.
Scope and lifetime
- A token grants full access to its business. There are no per-endpoint permissions.
- Tokens do not expire. Revoke a token by deleting it in the same settings page; requests with a deleted token receive
401. - If your account has several businesses, create a separate token for each one.
- All tokens of one business share the same rate limit of 60 requests per minute.
Keep it secret
Treat the token like a password. Store it in a secret manager or environment variable, never in a repository or in a browser-side application. If a token leaks, delete it in the app and create a new one.
Integrating as an AI agent
Compact, agent-oriented description of the F-sąskaita API. Base URL, authentication, spec location, pagination, error handling and rules that prevent common mistakes.
Invoices
The invoice model, invoice types, numbering and series, the create and update requests, and downloading the PDF.