Developer docsv1
Guides

Authentication

Create a Business token in the app, send it as a bearer token, and understand its scope and lifetime.

Every request to the F-sąskaita API is authenticated with a Business token. The token identifies one business in your account, and every invoice, expense or profile you touch belongs to that business.

Create a token

  1. Sign in to app.fsaskaita.lt as a user who can manage the business.
  2. Open Settings, then Integrations, then API.
  3. Give the token a name that tells you where it is used, such as accounting-sync, and create it.
  4. Copy the token immediately. It is shown once. Afterwards only its name is listed.

Tokens are only available on plans that include the API feature. If the section shows an upgrade notice instead of the form, the current plan does not include it.

Use the token

Send it in the Authorization header and always request JSON:

curl https://app.fsaskaita.lt/api/profile \
  -H "Authorization: Bearer $FSASKAITA_TOKEN" \
  -H "Accept: application/json"

A successful response describes the business behind the token:

{
  "data": {
    "business_id": "9c1f7b2e-3a6d-4d5e-9f0a-2b7c8d9e0f11",
    "business_title": "Pavyzdys, MB",
    "business_type": "small_partnership",
    "address": "Gedimino pr. 1, Vilnius",
    "vat_code": "LT100001234567",
    "company_name": "Pavyzdys, MB",
    "company_code": "305000001"
  }
}

For a business registered as individual activity the profile carries individual_activity_id, first_name and last_name instead of company_name and company_code.

Why the Accept header matters

Application errors come back as JSON either way. Without Accept: application/json, however, a missing or revoked token answers with an HTML redirect to the login page, and a rate-limited request answers with an HTML error page. With the header you get 401 {"message":"Unauthenticated."} and 429 {"message":"Too Many Attempts."}.

Scope and lifetime

  • A token grants full access to its business. There are no per-endpoint permissions.
  • Tokens do not expire. Revoke a token by deleting it in the same settings page; requests with a deleted token receive 401.
  • If your account has several businesses, create a separate token for each one.
  • All tokens of one business share the same rate limit of 60 requests per minute.

Keep it secret

Treat the token like a password. Store it in a secret manager or environment variable, never in a repository or in a browser-side application. If a token leaks, delete it in the app and create a new one.

F-sąskaita / DevelopersWhat’s new

On this page