Skip to main content
Help guide

API reference

The API is the same set of routes the app itself calls, so anything you can do on a screen you can do over HTTP. 197 endpoints, listed below.

Authentication

Create a personal token in the app under Settings → API Access. Send it as a bearer credential on any /api route. Choose which business the request acts on with the X-Business-Id header (ids come from GET /api/businesses), or set a default business on the token itself.

curl https://cashlucent.com/api/customers \
  -H "Authorization: Bearer clk_your_token_here" \
  -H "X-Business-Id: your_business_id"

A token acts as you, with exactly your roles, in every business you can reach. For read-only access, invite a Viewer teammate and use their token instead.

What you can do

  • Everything the app itself does. The API is the same set of routes the UI calls, so any screen has an endpoint behind it.
  • Customers, vendors, and products/services: list, create, update, delete, and CSV import.
  • Transactions of every kind through one endpoint: sales receipts, invoices, payments, expenses, bills, bill payments, refunds, credit memos, vendor credits, transfers, journal entries. Tag lines to projects for program P&L.
  • Estimates, purchase orders, recurring templates, bank deposits, and banking imports, rules, and reconciliation.
  • Projects and project budgets, company budgets, payment terms, sales tax agencies and rates.
  • Every report: P&L, Balance Sheet, Trial Balance, General Ledger, Cash Flow, aging and open balances, sales tax, sales by customer or item, expenses by vendor, budget vs actual, inventory, project, transaction detail, audit log, 1099.
  • Customer and vendor statements, saved report views, and switching the active business per request with the X-Business-Id header.

Conventions

  • Money is integer cents everywhere. $65.00 is 6500.
  • Dates are ISO YYYY-MM-DD, interpreted in UTC.
  • Every transaction must balance: total debits equal total credits, in cents, or the request is rejected.
  • IDs (accounts, customers, projects) come from the matching list endpoint. Errors return JSON { error } with 400, 401, 402, 403, or 404.
  • The token in the Authorization header is the only credential. It replaces any cookies you send.

Endpoints

Every route is relative to your Cashlucent host. A segment in brackets is an id, so /api/customers/[id] becomes /api/customers/abc123.

Businesses & session

GETPOST/api/businesses
PUTDELETE/api/businesses/[id]
PUT/api/organization
GET/api/plan/features
PUT/api/profile
PUT/api/profile/password
GETPOST/api/session/business
GETPUTDELETE/api/settings/ai-key
GETPUT/api/settings/invoice
GET/api/team
POST/api/team/invitations
POSTDELETE/api/team/invitations/[id]
PATCHDELETE/api/team/members/[id]

Chart of accounts

GETPOST/api/accounts
PUTDELETE/api/accounts/[id]
GET/api/accounts/[id]/delete-check
GET/api/accounts/balances
POST/api/accounts/bulk
POST/api/accounts/import
POST/api/accounts/switch-chart

People

GETPOST/api/customers
GETPUTDELETE/api/customers/[id]
POST/api/customers/import
GETPOST/api/vendors
PUTDELETE/api/vendors/[id]
POST/api/vendors/import

Products & services

GETPOST/api/items
GETPUTDELETE/api/items/[id]
POST/api/items/[id]/adjust
POST/api/items/[id]/receive
POST/api/items/import

Transactions

POST/api/attachments
GETPATCHDELETE/api/attachments/[id]
POST/api/attachments/[id]/confirm
GET/api/attachments/config
GET/api/bills
POST/api/deposits
GET/api/invoices
GET/api/invoices/[id]
POSTDELETE/api/invoices/[id]/pay-link
POST/api/invoices/[id]/send
GETPOST/api/transactions
GETPUTDELETE/api/transactions/[id]
GET/api/transactions/[id]/attachments
POST/api/transactions/[id]/duplicate
POST/api/transactions/bulk-recategorize
POST/api/transactions/import
GET/api/undeposited
GET/api/vendor-credits
POST/api/vendor-credits/[id]/apply

Estimates & purchasing

GETPOST/api/estimates
GETPUTDELETE/api/estimates/[id]
POST/api/estimates/[id]/accept
GETPOST/api/purchase-orders
GETPUTDELETE/api/purchase-orders/[id]
POST/api/purchase-orders/[id]/convert

Recurring

GETPOST/api/recurring
GETPUTDELETE/api/recurring/[id]
POST/api/recurring/[id]/run
POST/api/recurring/run-due

Banking

GET/api/banking/accounts
POST/api/banking/import
GET/api/banking/inbox
PUT/api/banking/inbox/order
PATCH/api/banking/plaid/accounts/[id]
POST/api/banking/plaid/exchange
GET/api/banking/plaid/items
PATCHDELETE/api/banking/plaid/items/[id]
PUT/api/banking/plaid/items/order
POST/api/banking/plaid/link-token
POST/api/banking/plaid/sync
POST/api/banking/plaid/webhook
GET/api/banking/reconcile
GETDELETE/api/banking/reconcile/[id]
POST/api/banking/reconcile/finalize
GET/api/banking/reconcile/history
POST/api/banking/reconcile/toggle
GETPOST/api/banking/rules
PUTDELETE/api/banking/rules/[id]
GET/api/banking/transactions
POST/api/banking/transactions/[id]

Projects & budgets

GETPOST/api/budgets
GETPUTDELETE/api/budgets/[id]
GETPOST/api/projects
PUTDELETE/api/projects/[id]
GETPUT/api/projects/[id]/budget
POST/api/projects/[id]/duplicate
GET/api/zbb
GETPOST/api/zbb/accounts
PATCHDELETE/api/zbb/accounts/[id]
POST/api/zbb/accounts/[id]/starting-balance
GET/api/zbb/activity
POST/api/zbb/assign
POST/api/zbb/categories
PATCHDELETE/api/zbb/categories/[id]
POSTPATCH/api/zbb/contributions/[id]
POST/api/zbb/copy-month
GET/api/zbb/debt
PUT/api/zbb/debt/terms
POSTPATCH/api/zbb/draws/[id]
POST/api/zbb/fresh-start
POST/api/zbb/fund-targets
POST/api/zbb/groups
PATCHDELETE/api/zbb/groups/[id]
GET/api/zbb/history
POST/api/zbb/import
GET/api/zbb/inbox
POST/api/zbb/inbox/[id]
POST/api/zbb/inbox/bulk
POST/api/zbb/inbox/opening
GETPOST/api/zbb/income-sources
PATCHDELETE/api/zbb/income-sources/[id]
GET/api/zbb/insights
GETPOST/api/zbb/loans
PATCH/api/zbb/loans/[id]
POST/api/zbb/loans/[id]/close
POST/api/zbb/move
GETPOSTPATCH/api/zbb/onboarding
GET/api/zbb/payees
GETPOST/api/zbb/projects
PATCHDELETE/api/zbb/projects/[id]
POST/api/zbb/register/cleared
POST/api/zbb/register/reconcile
GET/api/zbb/rules
PATCHDELETE/api/zbb/rules/[id]
GETPOST/api/zbb/scheduled
PUTPATCHDELETE/api/zbb/scheduled/[id]
GETPATCH/api/zbb/settings
GETPOST/api/zbb/sharing
DELETE/api/zbb/sharing/[id]
POST/api/zbb/starter
GETPOST/api/zbb/transactions
GETPUTDELETE/api/zbb/transactions/[id]

Sales tax & terms

GETPOST/api/payment-terms
PUTDELETE/api/payment-terms/[id]
GETPOST/api/tax/agencies
PUTDELETE/api/tax/agencies/[id]
POST/api/tax/payments
GETPOST/api/tax/rates
PUTDELETE/api/tax/rates/[id]

Reports & statements

GET/api/audit-log
GET/api/reports/1099
GET/api/reports/ap-aging
GET/api/reports/ap-detail
GET/api/reports/ar-aging
GET/api/reports/ar-detail
GET/api/reports/balance-sheet
GET/api/reports/budget-vs-actual
GET/api/reports/cash-flow
GET/api/reports/cash-flow-planner
GET/api/reports/expenses-by-vendor
GET/api/reports/general-ledger
GET/api/reports/inventory
GET/api/reports/profit-loss
GET/api/reports/project
GET/api/reports/sales-by-customer
GET/api/reports/sales-by-item
GET/api/reports/sales-tax
GET/api/reports/transaction-detail
GET/api/reports/trial-balance
GETPOST/api/saved-reports
DELETE/api/saved-reports/[id]
GET/api/statements/customer/[id]
GET/api/statements/vendor/[id]

Account & tokens

GETDELETE/api/account
GETPOST/api/account/api-tokens
DELETE/api/account/api-tokens/[id]

Other

GETPOST/api/account-templates
PATCHDELETE/api/account-templates/[id]
GET/api/accountant
POST/api/clickup/webhook
GET/api/contractors
GET/api/contractors/export
GET/api/contractors/forms
PUT/api/contractors/payer
GETPOST/api/custom-fields
PATCHDELETE/api/custom-fields/[id]
GETPUT/api/custom-fields/values
GETPOST/api/delayed-charges
PATCHDELETE/api/delayed-charges/[id]
POST/api/delayed-charges/mark-invoiced
GETPOST/api/document-requests
PATCHDELETE/api/document-requests/[id]
GET/api/documents
GET/api/export
GETPOST/api/feedback
GETPOST/api/help-requests
GET/api/integrations
GETPOST/api/receipts
PATCHDELETE/api/receipts/[id]
POST/api/receipts/[id]/extract
POST/api/receipts/[id]/file
POST/api/receipts/inbound
GETPOST/api/receipts/inbox
POSTDELETE/api/sample-data
GET/api/taxes/overview
POST/api/whats-new/seen

What it can't do yet

  • No webhooks or event subscriptions. Nothing calls you when data changes; poll the list or report endpoints instead.
  • No OAuth and no third-party app authorization. Tokens are personal and act as you, with your exact roles. For read-only access, invite a Viewer teammate and use their token.
  • No per-token scopes. A token can do anything your account can do in the UI, in every business you can reach.
  • No pagination cursors. List endpoints return the full set (transactions accept a limit). Large books mean large responses.
  • No idempotency keys. A retried POST creates a second record. Document numbers are assigned server-side, so dedupe on your side before posting.
  • No file uploads beyond inline data URLs (attachments up to 2 MB, logos smaller). No sandbox environment and no versioned API: the shapes mirror the UI and can change, so watch the changelog.
  • Token management is refused to token callers, and account, 2FA, signup, and team routes should be managed in the app.

Need a request body?

This page lists the surface. For request and response shapes with worked examples, email support@cashlucent.com and we'll send the full guide.