Fortnox Customers API

Customer register.

OpenAPI Specification

fortnox-customers-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Fortnox REST API (Representative Subset) Accounts Customers API
  description: 'Grounded OpenAPI description of the Fortnox REST API - the Swedish cloud accounting/ERP platform for SMBs and accounting bureaus. Base URL is https://api.fortnox.se/3/. Authentication is OAuth2 Authorization Code Flow: each request carries the Access-Token (Bearer JWT, 1h) header plus the Client-Secret header issued to your Fortnox app. The old fixed Access-Token/Client-Secret integration keys were deprecated 2025-04-30.


    SCOPE / FIDELITY NOTE: The Fortnox API exposes 40+ resources. This document ships a solid, representative SUBSET (Invoices, Customers, Articles, Orders, Offers, Vouchers, Accounts, Financial Years, Suppliers, Supplier Invoices, Projects) with pragmatic, partial field-level schemas. Paths, methods, identifiers, the wrapper-object response envelope (e.g. { "Invoice": {...} }, { "Invoices": [...] }), and auth are grounded in Fortnox''s developer documentation. Per-field property coverage is intentionally partial and MODELED/summarized from the docs, not transcribed field-for-field for every resource. Verify exact field sets and validation against https://api.fortnox.se/apidocs before production use.'
  version: '3.0'
  contact:
    name: Fortnox Developer
    url: https://www.fortnox.se/developer
  license:
    name: Fortnox API License / Terms
    url: https://www.fortnox.se/developer
servers:
- url: https://api.fortnox.se/3
  description: Fortnox REST API v3
security:
- accessToken: []
  clientSecret: []
tags:
- name: Customers
  description: Customer register.
paths:
  /customers:
    get:
      operationId: listCustomers
      tags:
      - Customers
      summary: List customers
      parameters:
      - $ref: '#/components/parameters/page'
      - $ref: '#/components/parameters/limit'
      responses:
        '200':
          description: A list of customers.
          content:
            application/json:
              schema:
                type: object
                properties:
                  Customers:
                    type: array
                    items:
                      $ref: '#/components/schemas/Customer'
                  MetaInformation:
                    $ref: '#/components/schemas/MetaInformation'
        '401':
          $ref: '#/components/responses/Unauthorized'
    post:
      operationId: createCustomer
      tags:
      - Customers
      summary: Create a customer
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                Customer:
                  $ref: '#/components/schemas/Customer'
      responses:
        '201':
          $ref: '#/components/responses/CustomerResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /customers/{CustomerNumber}:
    parameters:
    - $ref: '#/components/parameters/CustomerNumber'
    get:
      operationId: getCustomer
      tags:
      - Customers
      summary: Retrieve a customer
      responses:
        '200':
          $ref: '#/components/responses/CustomerResponse'
        '404':
          $ref: '#/components/responses/NotFound'
    put:
      operationId: updateCustomer
      tags:
      - Customers
      summary: Update a customer
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                Customer:
                  $ref: '#/components/schemas/Customer'
      responses:
        '200':
          $ref: '#/components/responses/CustomerResponse'
    delete:
      operationId: deleteCustomer
      tags:
      - Customers
      summary: Delete a customer
      responses:
        '204':
          description: Customer deleted.
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  parameters:
    CustomerNumber:
      name: CustomerNumber
      in: path
      required: true
      description: The customer number.
      schema:
        type: string
    page:
      name: page
      in: query
      description: Page number for paginated results.
      schema:
        type: integer
        minimum: 1
    limit:
      name: limit
      in: query
      description: Number of records per page (max 500).
      schema:
        type: integer
        maximum: 500
  schemas:
    ErrorResponse:
      type: object
      description: Fortnox error envelope.
      properties:
        ErrorInformation:
          type: object
          properties:
            Error:
              type: integer
            Message:
              type: string
            Code:
              type: integer
    Customer:
      type: object
      description: A customer in the customer register.
      properties:
        CustomerNumber:
          type: string
        Name:
          type: string
        OrganisationNumber:
          type: string
        Email:
          type: string
        Address1:
          type: string
        City:
          type: string
        ZipCode:
          type: string
        CountryCode:
          type: string
        Currency:
          type: string
        VATNumber:
          type: string
        Type:
          type: string
          enum:
          - COMPANY
          - PRIVATE
      required:
      - Name
    MetaInformation:
      type: object
      description: Pagination metadata returned on list endpoints.
      properties:
        '@TotalResources':
          type: integer
        '@TotalPages':
          type: integer
        '@CurrentPage':
          type: integer
  responses:
    NotFound:
      description: The requested resource was not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Unauthorized:
      description: Missing or invalid Access-Token / Client-Secret.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    CustomerResponse:
      description: A single customer.
      content:
        application/json:
          schema:
            type: object
            properties:
              Customer:
                $ref: '#/components/schemas/Customer'
  securitySchemes:
    accessToken:
      type: apiKey
      in: header
      name: Access-Token
      description: OAuth2 Access-Token (Bearer JWT, valid 1 hour) obtained via the Authorization Code Flow from https://apps.fortnox.se/oauth-v1/token. Sent in the Access-Token header on every request.
    clientSecret:
      type: apiKey
      in: header
      name: Client-Secret
      description: The Client-Secret issued to your registered Fortnox developer application. Sent in the Client-Secret header alongside the Access-Token on every request.
Where this information came from

This is an independent, third-party profile of Fortnox Customers API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.