API reference
The API is the same set of routes the app itself calls, so anything you can do on a screen you can do over HTTP. 197 endpoints, listed below.
Authentication
Create a personal token in the app under Settings → API Access. Send it as a bearer credential on any /api route. Choose which business the request acts on with the X-Business-Id header (ids come from GET /api/businesses), or set a default business on the token itself.
curl https://cashlucent.com/api/customers \ -H "Authorization: Bearer clk_your_token_here" \ -H "X-Business-Id: your_business_id"
A token acts as you, with exactly your roles, in every business you can reach. For read-only access, invite a Viewer teammate and use their token instead.
What you can do
- Everything the app itself does. The API is the same set of routes the UI calls, so any screen has an endpoint behind it.
- Customers, vendors, and products/services: list, create, update, delete, and CSV import.
- Transactions of every kind through one endpoint: sales receipts, invoices, payments, expenses, bills, bill payments, refunds, credit memos, vendor credits, transfers, journal entries. Tag lines to projects for program P&L.
- Estimates, purchase orders, recurring templates, bank deposits, and banking imports, rules, and reconciliation.
- Projects and project budgets, company budgets, payment terms, sales tax agencies and rates.
- Every report: P&L, Balance Sheet, Trial Balance, General Ledger, Cash Flow, aging and open balances, sales tax, sales by customer or item, expenses by vendor, budget vs actual, inventory, project, transaction detail, audit log, 1099.
- Customer and vendor statements, saved report views, and switching the active business per request with the X-Business-Id header.
Conventions
- Money is integer cents everywhere. $65.00 is 6500.
- Dates are ISO YYYY-MM-DD, interpreted in UTC.
- Every transaction must balance: total debits equal total credits, in cents, or the request is rejected.
- IDs (accounts, customers, projects) come from the matching list endpoint. Errors return JSON { error } with 400, 401, 402, 403, or 404.
- The token in the Authorization header is the only credential. It replaces any cookies you send.
Endpoints
Every route is relative to your Cashlucent host. A segment in brackets is an id, so /api/customers/[id] becomes /api/customers/abc123.
Businesses & session
| GETPOST | /api/businesses |
| PUTDELETE | /api/businesses/[id] |
| PUT | /api/organization |
| GET | /api/plan/features |
| PUT | /api/profile |
| PUT | /api/profile/password |
| GETPOST | /api/session/business |
| GETPUTDELETE | /api/settings/ai-key |
| GETPUT | /api/settings/invoice |
| GET | /api/team |
| POST | /api/team/invitations |
| POSTDELETE | /api/team/invitations/[id] |
| PATCHDELETE | /api/team/members/[id] |
Chart of accounts
| GETPOST | /api/accounts |
| PUTDELETE | /api/accounts/[id] |
| GET | /api/accounts/[id]/delete-check |
| GET | /api/accounts/balances |
| POST | /api/accounts/bulk |
| POST | /api/accounts/import |
| POST | /api/accounts/switch-chart |
People
| GETPOST | /api/customers |
| GETPUTDELETE | /api/customers/[id] |
| POST | /api/customers/import |
| GETPOST | /api/vendors |
| PUTDELETE | /api/vendors/[id] |
| POST | /api/vendors/import |
Products & services
| GETPOST | /api/items |
| GETPUTDELETE | /api/items/[id] |
| POST | /api/items/[id]/adjust |
| POST | /api/items/[id]/receive |
| POST | /api/items/import |
Transactions
| POST | /api/attachments |
| GETPATCHDELETE | /api/attachments/[id] |
| POST | /api/attachments/[id]/confirm |
| GET | /api/attachments/config |
| GET | /api/bills |
| POST | /api/deposits |
| GET | /api/invoices |
| GET | /api/invoices/[id] |
| POSTDELETE | /api/invoices/[id]/pay-link |
| POST | /api/invoices/[id]/send |
| GETPOST | /api/transactions |
| GETPUTDELETE | /api/transactions/[id] |
| GET | /api/transactions/[id]/attachments |
| POST | /api/transactions/[id]/duplicate |
| POST | /api/transactions/bulk-recategorize |
| POST | /api/transactions/import |
| GET | /api/undeposited |
| GET | /api/vendor-credits |
| POST | /api/vendor-credits/[id]/apply |
Estimates & purchasing
| GETPOST | /api/estimates |
| GETPUTDELETE | /api/estimates/[id] |
| POST | /api/estimates/[id]/accept |
| GETPOST | /api/purchase-orders |
| GETPUTDELETE | /api/purchase-orders/[id] |
| POST | /api/purchase-orders/[id]/convert |
Recurring
| GETPOST | /api/recurring |
| GETPUTDELETE | /api/recurring/[id] |
| POST | /api/recurring/[id]/run |
| POST | /api/recurring/run-due |
Banking
| GET | /api/banking/accounts |
| POST | /api/banking/import |
| GET | /api/banking/inbox |
| PUT | /api/banking/inbox/order |
| PATCH | /api/banking/plaid/accounts/[id] |
| POST | /api/banking/plaid/exchange |
| GET | /api/banking/plaid/items |
| PATCHDELETE | /api/banking/plaid/items/[id] |
| PUT | /api/banking/plaid/items/order |
| POST | /api/banking/plaid/link-token |
| POST | /api/banking/plaid/sync |
| POST | /api/banking/plaid/webhook |
| GET | /api/banking/reconcile |
| GETDELETE | /api/banking/reconcile/[id] |
| POST | /api/banking/reconcile/finalize |
| GET | /api/banking/reconcile/history |
| POST | /api/banking/reconcile/toggle |
| GETPOST | /api/banking/rules |
| PUTDELETE | /api/banking/rules/[id] |
| GET | /api/banking/transactions |
| POST | /api/banking/transactions/[id] |
Projects & budgets
| GETPOST | /api/budgets |
| GETPUTDELETE | /api/budgets/[id] |
| GETPOST | /api/projects |
| PUTDELETE | /api/projects/[id] |
| GETPUT | /api/projects/[id]/budget |
| POST | /api/projects/[id]/duplicate |
| GET | /api/zbb |
| GETPOST | /api/zbb/accounts |
| PATCHDELETE | /api/zbb/accounts/[id] |
| POST | /api/zbb/accounts/[id]/starting-balance |
| GET | /api/zbb/activity |
| POST | /api/zbb/assign |
| POST | /api/zbb/categories |
| PATCHDELETE | /api/zbb/categories/[id] |
| POSTPATCH | /api/zbb/contributions/[id] |
| POST | /api/zbb/copy-month |
| GET | /api/zbb/debt |
| PUT | /api/zbb/debt/terms |
| POSTPATCH | /api/zbb/draws/[id] |
| POST | /api/zbb/fresh-start |
| POST | /api/zbb/fund-targets |
| POST | /api/zbb/groups |
| PATCHDELETE | /api/zbb/groups/[id] |
| GET | /api/zbb/history |
| POST | /api/zbb/import |
| GET | /api/zbb/inbox |
| POST | /api/zbb/inbox/[id] |
| POST | /api/zbb/inbox/bulk |
| POST | /api/zbb/inbox/opening |
| GETPOST | /api/zbb/income-sources |
| PATCHDELETE | /api/zbb/income-sources/[id] |
| GET | /api/zbb/insights |
| GETPOST | /api/zbb/loans |
| PATCH | /api/zbb/loans/[id] |
| POST | /api/zbb/loans/[id]/close |
| POST | /api/zbb/move |
| GETPOSTPATCH | /api/zbb/onboarding |
| GET | /api/zbb/payees |
| GETPOST | /api/zbb/projects |
| PATCHDELETE | /api/zbb/projects/[id] |
| POST | /api/zbb/register/cleared |
| POST | /api/zbb/register/reconcile |
| GET | /api/zbb/rules |
| PATCHDELETE | /api/zbb/rules/[id] |
| GETPOST | /api/zbb/scheduled |
| PUTPATCHDELETE | /api/zbb/scheduled/[id] |
| GETPATCH | /api/zbb/settings |
| GETPOST | /api/zbb/sharing |
| DELETE | /api/zbb/sharing/[id] |
| POST | /api/zbb/starter |
| GETPOST | /api/zbb/transactions |
| GETPUTDELETE | /api/zbb/transactions/[id] |
Sales tax & terms
| GETPOST | /api/payment-terms |
| PUTDELETE | /api/payment-terms/[id] |
| GETPOST | /api/tax/agencies |
| PUTDELETE | /api/tax/agencies/[id] |
| POST | /api/tax/payments |
| GETPOST | /api/tax/rates |
| PUTDELETE | /api/tax/rates/[id] |
Reports & statements
| GET | /api/audit-log |
| GET | /api/reports/1099 |
| GET | /api/reports/ap-aging |
| GET | /api/reports/ap-detail |
| GET | /api/reports/ar-aging |
| GET | /api/reports/ar-detail |
| GET | /api/reports/balance-sheet |
| GET | /api/reports/budget-vs-actual |
| GET | /api/reports/cash-flow |
| GET | /api/reports/cash-flow-planner |
| GET | /api/reports/expenses-by-vendor |
| GET | /api/reports/general-ledger |
| GET | /api/reports/inventory |
| GET | /api/reports/profit-loss |
| GET | /api/reports/project |
| GET | /api/reports/sales-by-customer |
| GET | /api/reports/sales-by-item |
| GET | /api/reports/sales-tax |
| GET | /api/reports/transaction-detail |
| GET | /api/reports/trial-balance |
| GETPOST | /api/saved-reports |
| DELETE | /api/saved-reports/[id] |
| GET | /api/statements/customer/[id] |
| GET | /api/statements/vendor/[id] |
Account & tokens
| GETDELETE | /api/account |
| GETPOST | /api/account/api-tokens |
| DELETE | /api/account/api-tokens/[id] |
Other
| GETPOST | /api/account-templates |
| PATCHDELETE | /api/account-templates/[id] |
| GET | /api/accountant |
| POST | /api/clickup/webhook |
| GET | /api/contractors |
| GET | /api/contractors/export |
| GET | /api/contractors/forms |
| PUT | /api/contractors/payer |
| GETPOST | /api/custom-fields |
| PATCHDELETE | /api/custom-fields/[id] |
| GETPUT | /api/custom-fields/values |
| GETPOST | /api/delayed-charges |
| PATCHDELETE | /api/delayed-charges/[id] |
| POST | /api/delayed-charges/mark-invoiced |
| GETPOST | /api/document-requests |
| PATCHDELETE | /api/document-requests/[id] |
| GET | /api/documents |
| GET | /api/export |
| GETPOST | /api/feedback |
| GETPOST | /api/help-requests |
| GET | /api/integrations |
| GETPOST | /api/receipts |
| PATCHDELETE | /api/receipts/[id] |
| POST | /api/receipts/[id]/extract |
| POST | /api/receipts/[id]/file |
| POST | /api/receipts/inbound |
| GETPOST | /api/receipts/inbox |
| POSTDELETE | /api/sample-data |
| GET | /api/taxes/overview |
| POST | /api/whats-new/seen |
What it can't do yet
- No webhooks or event subscriptions. Nothing calls you when data changes; poll the list or report endpoints instead.
- No OAuth and no third-party app authorization. Tokens are personal and act as you, with your exact roles. For read-only access, invite a Viewer teammate and use their token.
- No per-token scopes. A token can do anything your account can do in the UI, in every business you can reach.
- No pagination cursors. List endpoints return the full set (transactions accept a limit). Large books mean large responses.
- No idempotency keys. A retried POST creates a second record. Document numbers are assigned server-side, so dedupe on your side before posting.
- No file uploads beyond inline data URLs (attachments up to 2 MB, logos smaller). No sandbox environment and no versioned API: the shapes mirror the UI and can change, so watch the changelog.
- Token management is refused to token callers, and account, 2FA, signup, and team routes should be managed in the app.
Need a request body?
This page lists the surface. For request and response shapes with worked examples, email support@cashlucent.com and we'll send the full guide.