Fortnox Orders API

Sales orders.

OpenAPI Specification

fortnox-orders-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Fortnox REST API (Representative Subset) Accounts Orders API
  description: 'Grounded OpenAPI description of the Fortnox REST API - the Swedish cloud accounting/ERP platform for SMBs and accounting bureaus. Base URL is https://api.fortnox.se/3/. Authentication is OAuth2 Authorization Code Flow: each request carries the Access-Token (Bearer JWT, 1h) header plus the Client-Secret header issued to your Fortnox app. The old fixed Access-Token/Client-Secret integration keys were deprecated 2025-04-30.


    SCOPE / FIDELITY NOTE: The Fortnox API exposes 40+ resources. This document ships a solid, representative SUBSET (Invoices, Customers, Articles, Orders, Offers, Vouchers, Accounts, Financial Years, Suppliers, Supplier Invoices, Projects) with pragmatic, partial field-level schemas. Paths, methods, identifiers, the wrapper-object response envelope (e.g. { "Invoice": {...} }, { "Invoices": [...] }), and auth are grounded in Fortnox''s developer documentation. Per-field property coverage is intentionally partial and MODELED/summarized from the docs, not transcribed field-for-field for every resource. Verify exact field sets and validation against https://api.fortnox.se/apidocs before production use.'
  version: '3.0'
  contact:
    name: Fortnox Developer
    url: https://www.fortnox.se/developer
  license:
    name: Fortnox API License / Terms
    url: https://www.fortnox.se/developer
servers:
- url: https://api.fortnox.se/3
  description: Fortnox REST API v3
security:
- accessToken: []
  clientSecret: []
tags:
- name: Orders
  description: Sales orders.
paths:
  /orders:
    get:
      operationId: listOrders
      tags:
      - Orders
      summary: List orders
      parameters:
      - $ref: '#/components/parameters/page'
      - $ref: '#/components/parameters/limit'
      responses:
        '200':
          description: A list of orders.
          content:
            application/json:
              schema:
                type: object
                properties:
                  Orders:
                    type: array
                    items:
                      $ref: '#/components/schemas/OrderListItem'
                  MetaInformation:
                    $ref: '#/components/schemas/MetaInformation'
    post:
      operationId: createOrder
      tags:
      - Orders
      summary: Create an order
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                Order:
                  $ref: '#/components/schemas/Order'
      responses:
        '201':
          $ref: '#/components/responses/OrderResponse'
  /orders/{DocumentNumber}:
    parameters:
    - $ref: '#/components/parameters/DocumentNumber'
    get:
      operationId: getOrder
      tags:
      - Orders
      summary: Retrieve an order
      responses:
        '200':
          $ref: '#/components/responses/OrderResponse'
        '404':
          $ref: '#/components/responses/NotFound'
    put:
      operationId: updateOrder
      tags:
      - Orders
      summary: Update an order
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                Order:
                  $ref: '#/components/schemas/Order'
      responses:
        '200':
          $ref: '#/components/responses/OrderResponse'
components:
  parameters:
    DocumentNumber:
      name: DocumentNumber
      in: path
      required: true
      description: The document number identifying the invoice/order/offer.
      schema:
        type: string
    page:
      name: page
      in: query
      description: Page number for paginated results.
      schema:
        type: integer
        minimum: 1
    limit:
      name: limit
      in: query
      description: Number of records per page (max 500).
      schema:
        type: integer
        maximum: 500
  schemas:
    Order:
      type: object
      description: A sales order.
      properties:
        DocumentNumber:
          type: string
          readOnly: true
        CustomerNumber:
          type: string
        CustomerName:
          type: string
        OrderDate:
          type: string
          format: date
        DeliveryDate:
          type: string
          format: date
        Currency:
          type: string
        Total:
          type: number
        OrderRows:
          type: array
          items:
            $ref: '#/components/schemas/InvoiceRow'
      required:
      - CustomerNumber
    ErrorResponse:
      type: object
      description: Fortnox error envelope.
      properties:
        ErrorInformation:
          type: object
          properties:
            Error:
              type: integer
            Message:
              type: string
            Code:
              type: integer
    OrderListItem:
      type: object
      properties:
        DocumentNumber:
          type: string
        CustomerNumber:
          type: string
        CustomerName:
          type: string
        OrderDate:
          type: string
          format: date
        Total:
          type: number
    InvoiceRow:
      type: object
      description: A single line item on an invoice, order, or offer.
      properties:
        ArticleNumber:
          type: string
        Description:
          type: string
        DeliveredQuantity:
          type: string
        Price:
          type: number
        VAT:
          type: number
        AccountNumber:
          type: integer
        Unit:
          type: string
    MetaInformation:
      type: object
      description: Pagination metadata returned on list endpoints.
      properties:
        '@TotalResources':
          type: integer
        '@TotalPages':
          type: integer
        '@CurrentPage':
          type: integer
  responses:
    NotFound:
      description: The requested resource was not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    OrderResponse:
      description: A single order.
      content:
        application/json:
          schema:
            type: object
            properties:
              Order:
                $ref: '#/components/schemas/Order'
  securitySchemes:
    accessToken:
      type: apiKey
      in: header
      name: Access-Token
      description: OAuth2 Access-Token (Bearer JWT, valid 1 hour) obtained via the Authorization Code Flow from https://apps.fortnox.se/oauth-v1/token. Sent in the Access-Token header on every request.
    clientSecret:
      type: apiKey
      in: header
      name: Client-Secret
      description: The Client-Secret issued to your registered Fortnox developer application. Sent in the Client-Secret header alongside the Access-Token on every request.
Where this information came from

This is an independent, third-party profile of Fortnox Orders API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.