openapi: 3.0.3 info: title: Quaderno Authentication API description: 'The Quaderno API is a REST API for tax compliance, invoicing, and sales tax / VAT automation. It exposes resources with predictable, account-scoped URLs and uses standard HTTP features - HTTP Basic Authentication, standard methods, and response codes. All requests and responses are JSON, and every endpoint path ends in `.json` to indicate JSON serialization. The base URL is account-scoped: `https://ACCOUNT_NAME.quadernoapp.com/api`, where `ACCOUNT_NAME` is your Quaderno account subdomain. Authenticate with your private API key as the HTTP Basic Auth username (any value for the password). Sandbox testing is available on a separate sandbox host. Core resources include Contacts, Items, Invoices, Credits, Estimates, Expenses, Recurring documents, Payments, Transactions, Checkout Sessions, Webhooks, and the tax engine (tax rate calculation, tax jurisdictions, tax codes, and tax ID validation). Endpoint paths and the account-scoped base URL are confirmed against Quaderno''s public developer documentation and the official quaderno-ruby SDK; request and response bodies are modeled and should be verified against the live API reference.' version: '1.0' contact: name: Quaderno url: https://developers.quaderno.io license: name: Proprietary url: https://quaderno.io/terms/ servers: - url: https://{account}.quadernoapp.com/api description: Production (account-scoped) variables: account: default: ACCOUNT_NAME description: Your Quaderno account subdomain. security: - basicAuth: [] tags: - name: Authentication description: Ping the API and inspect the authenticated account and rate-limit state. paths: /ping.json: get: operationId: ping tags: - Authentication summary: Ping the API description: Tests service availability, validates your API key, and returns your remaining request allowance without consuming rate limit. responses: '200': description: The service is available and the token is valid. content: application/json: schema: type: object properties: status: type: string '401': $ref: '#/components/responses/Unauthorized' /authorization.json: get: operationId: getAuthorization tags: - Authentication summary: Get authorization details description: Returns the identity and account details associated with the authenticated API key, including the account-scoped API URL to use. responses: '200': description: Authorization details for the authenticated key. content: application/json: schema: type: object additionalProperties: true '401': $ref: '#/components/responses/Unauthorized' components: responses: Unauthorized: description: Missing or invalid API key. content: application/json: schema: $ref: '#/components/schemas/Error' schemas: Error: type: object properties: error: type: string errors: type: object additionalProperties: true securitySchemes: basicAuth: type: http scheme: basic description: HTTP Basic Authentication. Use your private API key as the username; the password can be any value. API keys are managed in the Quaderno account settings.