# Koalaboox (Cegid Invoice & Financing / Cegid Click & Finance) > Belgian cloud invoicing and cash-flow platform for small businesses, self-employed > professionals and their accountants, now operating as Cegid Invoice & Financing after > its acquisition by Cegid. Covers sales invoicing, quotes, purchase invoices, recurring > invoices, dashboards, bank-account connections and Peppol electronic invoicing for the > Belgian 2026 e-invoicing mandate, sold in Belgium and Spain — plus invoice financing > (cash advances against outstanding invoices) underwritten by Cegid Fin Belgium. > The public REST API is branded Cegid Click & Finance. Generated by the API Evangelist enrichment pipeline on 2026-07-19 from public sources. Method: generated from the catalog and repo artifacts; no provider-published llms.txt exists (/llms.txt returns 404 on developers.cegid.be and connect.koalaboox.com). ## API - [Cegid Click & Finance API](https://developers.cegid.be/): REST, JSON, standard HTTP status codes, OAuth 2.0 authorization-code authentication. Base URL https://connect.koalaboox.com, paths under /api. Used to automate invoice encoding, import invoices from another system, and offer invoice financing inside third-party software. Confirmed endpoints (all require a bearer access token): - `GET /api/invoices` — list the connected account's invoices - `GET /api/invoices/{id}` — retrieve one invoice - `GET /api/user` — the authenticated account holder - `GET /oauth/authorize` — OAuth 2.0 authorization endpoint - `POST /oauth/token` — OAuth 2.0 token endpoint (authorization_code, refresh_token) Successful responses are wrapped in a top-level `data` member. Send `Accept: application/json` on every request. API errors are `{"message": "..."}`; token-endpoint errors use the RFC 6749 envelope. There is no published scope catalogue, no documented idempotency contract, and no documented rate-limit policy. ## Docs - [Developer portal](https://developers.cegid.be/) — Stoplight, workspace "Click & Finance" (formerly developers.koala.eu). Note: the workspace is currently locked and every documentation and API-reference node returns 404; only the portal home renders. - [Product page](https://www.cegid.com/be/fr/produits/cegid-invoice-financing/) - [Pricing](https://www.invoice-financing.cegid.com/v3/pricing) - [Sign in](https://www.invoice-financing.cegid.com/v3/login) - [Support](https://www.cegid.com/fr/assistance-clients/) — developer contact koala-b2b-support@cegid.com ## Code - [koalaboox/api-refarch](https://github.com/koalaboox/api-refarch) — first-party Laravel reference architecture (MIT, (c) 2019 Koalaboox) showing the full OAuth 2.0 authorization-code integration, bearer-token middleware, state CSRF validation, token-error recovery and invoice retrieval. There is no published client library in any package registry. - [GitHub organization](https://github.com/koalaboox) ## Artifacts - authentication/koalaboox-authentication.yml — OAuth 2.0 profile - conventions/koalaboox-conventions.yml — REST/JSON semantics, response envelope - errors/koalaboox-problem-types.yml — observed error envelopes and conditions - conformance/koalaboox-conformance.yml — standards posture (OAuth 2.0, Peppol, ...) - lifecycle/koalaboox-lifecycle.yml — Koalaboox to Cegid migration, domain moves, docs health - data-model/koalaboox-data-model.yml — Invoice / User entity graph - plans/koalaboox-plans.yml — four published subscription tiers - packages/koalaboox-packages.yml — registry sweep (no client libraries) - mcp/koalaboox-mcp.yml — candidate MCP tool list - security/koalaboox-domain-security.yml — TLS/HSTS/DNS posture - security/koalaboox-vulnerability-disclosure.yml — Cegid VDP (YesWeHack) - well-known/koalaboox-well-known.yml — /.well-known/ sweep ## Notes for agents - Koalaboox-branded marketing and application hosts now redirect to Cegid (koalaboox.com to cegid.be, app.koalaboox.com to app.invoice-financing.cegid.com). The API host connect.koalaboox.com has NOT been migrated and is still live under the Koalaboox name. - No OpenAPI definition is publicly retrievable at this time, so operation coverage here is limited to what was verified from first-party source code and live probes.