openapi: 3.2.0 info: title: Lawmatics OAuth Payment Invoices API version: 1.22.0 description: 'The official Lawmatics REST API for legal CRM, client intake and law firm automation. Manage matters (prospects), contacts, companies, custom forms and form entries, custom fields, events and appointments, tasks, notes, files, tags, users, time entries, expenses, invoices and transactions. Authentication is OAuth 2.0 authorization code grant; access tokens do not expire, there are no refresh tokens, and Lawmatics does not currently support scopes - an authorized app receives full CRUD access to the granted account. All list endpoints support the shared query-parameter grammar documented in the Param Guide: `fields` (field selection, one level deep, `fields=all` to expand), `page` (pagination), `sort_by`/`sort_order`, and `filter_by`/`filter_on`/`filter_with` (one filter at a time; operators `=`, `!=`, `<=`, `<`, `>=`, `>`, `like`, `ilike`, `null`, `not_null`). Responses follow a JSON:API-style `data` / `attributes` / `relationships` envelope.' contact: name: Lawmatics API Support email: api@lawmatics.com url: https://docs.lawmatics.com/ termsOfService: https://www.lawmatics.com/terms-of-use servers: - url: https://api.lawmatics.com description: Lawmatics production API security: - oauth2: [] - bearerAuth: [] tags: - name: Payment Invoices paths: /v1/invoices/{invoice_id}: get: operationId: getInvoice summary: Invoice description: A specific Invoice in Lawmatics tags: - Payment Invoices parameters: - name: invoice_id in: path required: true description: The invoice id schema: type: string responses: '200': description: OK content: application/json: schema: type: object examples: getInvoice: summary: GET Invoice value: data: id: '1' type: invoice attributes: number: 1 status: sent target_account_type: operating payment_terms: due_date include_balance_forward: false enable_online_payment: false include_statement_of_accounts: false invoiced_at: '2021-11-02' due_at: '2021-11-02' voided_at: null contactable_address: null contactable_name: Roey Tester note: "hey zsolt this is a specific invoice note\n\nhere \nis\na \nbunch\n\nof (two)\nnewlines" amount_cents: 0 amount_paid_cents: 0 outstanding_amount_cents: 0 pdf_url: http://localhost:3000/attachments/80623eb43ae0fa961d5a32b8d169fd54a0249de1/store/511432f743969f1e7b9cc636c1a9c7b4ca1a4d5dd902ef0a1ba405ff89f7/Invoice+%231.pdf created_at: '2021-11-02T10:28:40.535-07:00' updated_at: '2022-01-10T19:43:47.382-08:00' relationships: invoice_type: data: null prospect: data: id: '101' type: prospect created_by: data: id: '5' type: created_by forwarded_to: data: null time_entries: data: - id: '8' type: time_entry expenses: data: [] invoice_adjustments: data: [] transactions: data: [] forwarded_from: data: [] '401': description: Unauthorized - missing or invalid OAuth 2.0 bearer token '429': description: Too Many Requests - the per-firm rate limit was exceeded; a Retry-After header is returned headers: Retry-After: description: Seconds to wait before retrying schema: type: integer /v1/invoices: get: operationId: getInvoices summary: Invoices description: A paginated list of all Invoices in Lawmatics tags: - Payment Invoices responses: '200': description: OK content: application/json: schema: type: object examples: getInvoices: summary: GET Invoices value: data: - id: '1' type: invoice attributes: number: 1 status: sent target_account_type: operating payment_terms: due_date include_balance_forward: false enable_online_payment: false include_statement_of_accounts: false invoiced_at: '2021-11-02' due_at: '2021-11-02' voided_at: null contactable_address: null contactable_name: Roey Tester note: "hey zsolt this is a specific invoice note\n\nhere \nis\na \nbunch\n\nof (two)\nnewlines" amount_cents: 0 amount_paid_cents: 0 outstanding_amount_cents: 0 pdf_url: http://localhost:3000/attachments/80623eb43ae0fa961d5a32b8d169fd54a0249de1/store/511432f743969f1e7b9cc636c1a9c7b4ca1a4d5dd902ef0a1ba405ff89f7/Invoice+%231.pdf created_at: '2021-11-02T10:28:40.535-07:00' updated_at: '2022-01-10T19:43:47.382-08:00' relationships: invoice_type: data: null prospect: data: id: '101' type: prospect created_by: data: id: '5' type: created_by forwarded_to: data: null time_entries: data: - id: '8' type: time_entry expenses: data: [] invoice_adjustments: data: [] transactions: data: [] forwarded_from: data: [] meta: total_pages: 1 limit_per_page: 25 total_entries: 1 links: self: /v1/invoices?page=1 '401': description: Unauthorized - missing or invalid OAuth 2.0 bearer token '429': description: Too Many Requests - the per-firm rate limit was exceeded; a Retry-After header is returned headers: Retry-After: description: Seconds to wait before retrying schema: type: integer components: securitySchemes: oauth2: type: oauth2 description: OAuth 2.0 authorization code grant. Register a developer app at https://app.lawmatics.com/settings/developers (developer settings must be enabled by Lawmatics support). Access tokens are non-expiring; no refresh tokens are issued and scopes are not supported. flows: authorizationCode: authorizationUrl: https://app.lawmatics.com/oauth/authorize tokenUrl: https://api.lawmatics.com/oauth/token scopes: {} bearerAuth: type: http scheme: bearer description: 'The OAuth 2.0 access token is sent as `Authorization: Bearer `.' externalDocs: description: Official Lawmatics RESTful API documentation (Postman) url: https://docs.lawmatics.com/ x-provenance: generated: '2026-08-13' method: derived publisher: API Evangelist source: https://docs.lawmatics.com/api/collections/26379991/2sA3JM7gbw?segregateAuth=true&versionTag=latest source_type: Postman collection published by Lawmatics as its official API documentation source_file: postman/lawmatics-oauth-api.postman_collection.json note: 'NOT published by Lawmatics. Lawmatics publishes no OpenAPI. Every path, method, parameter, request example and response example in this document was converted mechanically from the provider-published Postman collection "Lawmatics OAuth API v1.22.0"; nothing was invented. Schemas are typed as generic objects because the collection carries examples, not JSON Schema. The server URL is the base documented in the collection Param Guide (https://api.lawmatics.com), not the collection''s disabled {{host}} placeholder. The 401 and 429 responses added to every authenticated operation are the provider-documented, globally applicable responses: the collection''s auth guide states a per-firm rate limit applies to all endpoints and returns 429 with a Retry-After header, and https://api.lawmatics.com/v1/contacts was observed returning 401 unauthenticated on 2026-08-13.'