Syntage DS MX Buró de Crédito Authorizations API
Buró de Crédito authorizations store the consent, RFC, address, and identity data required before Syntage can request Buró de Crédito reports for an entity.
Buró de Crédito authorizations store the consent, RFC, address, and identity data required before Syntage can request Buró de Crédito reports for an entity.
openapi: 3.0.2
info:
version: '2020-06-28'
title: Syntage Accounts Payable Insight DS MX Buró de Crédito Authorizations API
contact:
name: Email
email: support@syntage.com
description: "# Introduction\n\nThe Syntage API is organized around [REST](https://en.wikipedia.org/wiki/Representational_State_Transfer).\nOur API has predictable resource-oriented URLs, accepts form-encoded request bodies, returns [JSON-LD](https://json-ld.org) responses, and uses standard HTTP response codes, authentication, and verbs.\n\n# Environments\n\n| Name | Description | Base URL |\n|------|-------------|----------|\n| **Sandbox** | The Sandbox environment is dedicated to development and testing. In this environment, no real taxpayer credentials are required and all interaction with the SAT is simulated generating life-like data, allowing you to pull test data from all endpoints. | https://api.sandbox.syntage.com |\n| **Production** | The Production environment is dedicated to live applications with real connections to the SAT. In this environment, real taxpayer credentials are required, and you will pull real fiscal data directly from the SAT. | https://api.syntage.com |\n\nEach environment has a different API Key for [authentication](#section/Authentication).\n\n# Request IDs\n\nEach API request has an associated request identifier.\nYou can find this value in the response headers, under `X-Request-ID`:\n\n```curl\ncurl -i https://api.syntage.com\nHTTP/1.1 200 OK\nDate: Sun, 29 Nov 2020 19:21:21 GMT\nX-Request-ID: Root=1-6532dcae-169bf139354cd48959f55c55\n```\n\nIf you need to contact us about a specific request, providing the request identifier will ensure the fastest possible resolution.\n\n# Rate Limiting\n\nOur API employs a number of safeguards against bursts of incoming traffic to help maximize its stability.\nThe returned HTTP headers of any API request show your current rate limit status:\n\n```curl\ncurl -i https://api.syntage.com\nHTTP/1.1 200 OK\nDate: Sun, 29 Nov 2020 19:21:21 GMT\nX-RateLimit-Limit: 60\nX-RateLimit-Remaining: 56\nX-RateLimit-Reset: 1606678044\n```\n\n| Header Name | Description |\n|-----------------------|------------------------------------------------------------------------------|\n| X-RateLimit-Limit | The maximum number of requests you're permitted to make. |\n| X-RateLimit-Remaining | The number of requests remaining in the current rate limit window. |\n| X-RateLimit-Reset | The time at which the current rate limit window resets in UTC epoch seconds. |\n\nIf you exceed the rate limit, a [429 Too Many Requests](https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/429) response is returned:\n\n```http\nHTTP/1.1 429 Too Many Requests\nDate: Sun, 29 Nov 2020 19:21:21 GMT\nX-RateLimit-Limit: 60\nX-RateLimit-Remaining: 0\nX-RateLimit-Reset: 1606678044\n```\n\nWe may reduce limits to prevent abuse, or increase limits to enable high-traffic operations.\nYou can check your current limits in the [dashboard](https://app.syntage.com/settings/usage).\nTo request an increased rate limit, please [contact support](https://support.syntage.com/).\n# Pagination\nWhen issuing a GET request on a collection containing more than 1 page (e.g. [/events](#operation/ListEvent)), a collection is returned. Links to the first, the last, previous and the next page in the collection are displayed as well as the number of total items in the collection.\nAll endpoints that support this operation have a query parameter defined by:\n - `itemsPerPage` The number of items per page (default: 20, max: 1000)\n - `page` The collection page number\n\n```bash\n \"hydra:totalItems\": 1,\n \"hydra:view\": {\n \"@id\": \"/events?page=1\",\n \"@type\": \"hydra:PartialCollectionView\",\n \"hydra:first\": \"/events?page=1\",\n \"hydra:next\": \"/events?page=2\",\n \"hydra:last\": \"/events?page=3\"\n },\n```\n## Cursor Pagination\nCursor pagination is a technique used for navigating through large datasets efficiently. It allows you to retrieve a specific subset of results from a collection by using a cursor value that represents the position within the collection. The cursor serves as a reference point for fetching the next or previous set of results.\n### Benefits of Cursor Pagination:\n1. **Efficient Navigation:** Cursor pagination eliminates the need to fetch the entire dataset at once, making it more scalable and faster. You can retrieve data in smaller, manageable chunks based on the cursor values.\n2. **Consistent Results:** Each page of results in cursor pagination is stable and doesn't change even if new items are added or removed from the collection. This ensures that you get consistent and reliable results.\n3. **Flexibility:** Cursors can be used to navigate forwards and backwards in the collection without impacting performance.\n\n### How to Use Cursor Pagination:\nTo use cursor pagination with our API, follow these instructions:\n1. Make a request to retrieve the initial page of results. The response will be a JSON-LD document that includes a `hydra:next` attribute with the URI for the next page. The URI already includes the cursor attribute.\n2. To retrieve the next page of results, make a GET request to the URI provided in the `hydra:next` attribute. This URI will automatically include the cursor value for the next page.\n3. If you want to navigate to the previous page, you can use the `hydra:previous` attribute in the JSON-LD response. It will contain the URI for the previous page, including the cursor value.\n4. You can continue making requests to the `hydra:next` and `hydra:previous` URIs to navigate through the paginated results, based on your requirements.\nMake sure to update your request headers to include the necessary headers for JSON-LD content negotiation, such as `Accept: application/ld+json` or `Content-Type: application/ld+json`.\nBy following these instructions, you can effectively navigate through the paginated results using the cursor values provided in the `hydra:next` and `hydra:previous` attributes, without the need to manually include the cursor in your requests. This simplifies the pagination process and enhances the usability of our API.\n\n### Considerations About Cursor Pagination:\n\n - By default, the API uses offset-based pagination (except for a few endpoints that we will list below). If you want to switch to cursor pagination, you need to include an additional header in your request. Set the `X-Pagination-Style` header with the value `\"cursor\"` to enable cursor pagination. If not specified, the API will assume offset-based pagination.\n\n - After enabling cursor pagination, the API response will no longer include the `hydra:totalItems` field by default. Retrieving the total count can be resource intensive and impact response times, especially for large datasets. However, if you need the `hydra:totalItems` information, you can include an additional header in your request. Set the `X-Pagination-Enable-Partial` header with the value `0` to indicate that the response should include extra information, including the `hydra:totalItems` count. Please be aware that enabling this feature may impact API response times, as the backend needs to perform a count operation on the dataset.\n\nIf you require the `hydra:totalItems` count, please consider the potential impact on API response times.\n### Example\n```bash\n curl -i 'https://api.syntage.com/entities/{entityId}/invoices?itemsPerPage=10' \\\n --header 'Accept: application/ld+json' \\\n --header 'X-Api-Key: {apiKey}' \\\n --header 'X-Pagination-Style: cursor' \\\n --header 'X-Pagination-Enable-Partial: 0'\n```\n**Note:** We only support cursor pagination for the following endpoints:\n - `GET /entities/{entityId}/invoices`\n - `GET /entities/{entityId}/invoices/line-items`\n - `GET /entities/{entityId}/invoices/{invoiceId}/line-items`\n - `GET /invoices/{invoiceId}/line-items`\n - `GET /entities/{entityId}/invoices/payments`\n\nFeel free to reach out if you have any further questions or need additional assistance!\n\n# Property Filtering\nThe property filter adds the possibility to select the properties for GET operations.\nSyntax: `?properties[]=<property>&properties[<relation>][]=<property>`\nYou can add as many properties as you need. The following example shows how to select `paymentType` and `issuer.rfc` when fetching a list of invoices.\n```curl\n curl -i https://api.syntage.com/entities/{entityId}/invoices?properties[]=paymentType&properties[issuer]=rfc\n```\n# Filtering\n**Warning:** Collection endpoints only apply the filter query parameters documented for that endpoint. If you send an unsupported or misspelled filter query parameter, the API ignores it and processes the request as if that parameter was not sent.\n\n# API Versioning Guide\nGuidance on changes between versions.\n## Version: 2020-01-01 to 2020-06-28\n### **Invoice**\n_**Affected Endpoints:** `GET /invoices/{id}` and `GET /entities/{entityId}/invoices`_\n- The `amount` property has been removed from API responses. Use the `total` property instead.\n- Retrieval by invoice's `uuid` at `/invoices/{id}` is now removed. To retrieve an invoice, use the invoice's `id` at the specified endpoint. To find an invoice using its `uuid`, filter the invoice collection at `/entities/{entityId}/invoices?uuid[]={uuid}`.\n- Previously, the `@iri` property for an invoice pointed to the resource using `uuid`, like `/invoices/{uuid}`. Now, it points using its `id`, like `/invoices/{id}`.\n\n### **Entity (Formerly Link)**\n_**Affected Endpoint:** `GET /entities`_\n- Filtering entities by `status` is removed. Use `credential.status` instead. For example, utilize `GET /entities?credential.status[]=active` instead of `GET /entities?status[]=active`.\n\n### **Tax Return**\n_**Affected Endpoints:** `GET /tax-returns/{id}` and `GET /entities/{entityId}/tax-returns`_\n- Retrieval by tax return's `operationNumber` at `/tax-returns/{id}` is removed. To retrieve a tax return, use the tax return's `id` at the mentioned endpoint. To find a tax return using its `operationNumber`, filter the collection at `/entities/{entityId}/tax-returns?operationNumber[]={operationNumber}`.\n- Previously, the `@iri` property for a tax return pointed to the resource using `operationNumber`, like `/tax-returns/{operationNumber}`. Now, it directs to its `id`, like `/tax-returns/{id}`.\n\n### **Event**\n_**Affected Endpoints:** `GET /events` and `GET /events/{id}`_\n- For events associated to an `tax-return`, the `@iri` property now directs to `/tax-returns/{id}` instead of the previous `/tax-returns/{operationNumber}`.\n- For events associated to an `invoice`, the `@iri` property now directs to `/invoices/{id}` instead of the previous `/invoices/{uuid}`.\n\n### **Extraction**\n_**Affected Endpoints:** `GET /extractions` and `GET /extractions/{id}`_\n- The `periodFrom` property has been removed. Use `options.period.from` instead.\n- The `periodTo` property has been removed. Use `options.period.to` instead.\n\n### **File**\n_**Affected Endpoint:** `GET /file/{id}`_\n- For files associated to an `tax-return`, the `@iri` property now directs to `/tax-returns/{id}`, instead of the previous `/tax-returns/{operationNumber}`.\n- For files associated to an `invoice`, the `@iri` property now directs to `/invoices/{id}`, instead of the previous `/invoices/{uuid}`.\n\n### Trying Out This Version\nIf you want to test this version, you can do so by making any request with the `Accept-Version` header pointing to the latest version:\n```curl\n curl -i 'https://api.syntage.com/entities/{entityId}/invoices' \\\n --header 'Accept-Version: 2020-06-28' \\\n --header 'X-Api-Key: {apiKey}'\n```\n"
servers:
- url: https://api.syntage.com
description: Production
- url: https://api.sandbox.syntage.com
description: Sandbox
security:
- ApiKey: []
tags:
- name: DS MX Buró de Crédito Authorizations
description: 'Buró de Crédito authorizations store the consent, RFC, address, and identity data required before Syntage can request Buró de Crédito reports for an entity.
'
paths:
/datasources/mx/buro-de-credito/authorizations:
get:
tags:
- DS MX Buró de Crédito Authorizations
operationId: GetMxBuroDeCreditoAuthorizations
summary: Get Buró de Crédito authorizations
description: List Buró de Crédito authorizations for the organization
parameters:
- $ref: '#/components/parameters/collectionCursorNextPageParam'
- $ref: '#/components/parameters/collectionCursorPreviousPageParam'
- $ref: '#/components/parameters/collectionLimit'
responses:
'200':
description: Buró de Crédito Authorizations
content:
application/ld+json:
schema:
type: object
allOf:
- $ref: '#/components/schemas/CursorCollection'
- type: object
properties:
'@context':
default: /contexts/BuroDeCreditoAuthorization
'@id':
example: /datasources/mx/buro-de-credito/authorizations
hydra:member:
type: array
items:
$ref: '#/components/schemas/BuroDeCreditoAuthorization'
'401':
$ref: '#/components/responses/Unauthorized'
/entities/{entityId}/datasources/mx/buro-de-credito/authorizations:
get:
tags:
- DS MX Buró de Crédito Authorizations
operationId: GetEntityMxBuroDeCreditoAuthorization
summary: Get an entity's Buró de Crédito authorizations
description: List Buró de Crédito authorizations associated with an entity
parameters:
- $ref: '#/components/parameters/entityId'
- $ref: '#/components/parameters/collectionCursorNextPageParam'
- $ref: '#/components/parameters/collectionCursorPreviousPageParam'
- $ref: '#/components/parameters/collectionLimit'
responses:
'200':
description: Buró de Crédito Authorizations
content:
application/ld+json:
schema:
type: object
allOf:
- $ref: '#/components/schemas/CursorCollection'
- type: object
properties:
'@context':
default: /contexts/BuroDeCreditoAuthorization
'@id':
example: /entities/9bd4a640-9f41-4cd5-a158-20767b386ca0/datasources/mx/buro-de-credito/authorizations
hydra:member:
type: array
items:
$ref: '#/components/schemas/BuroDeCreditoAuthorization'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
post:
tags:
- DS MX Buró de Crédito Authorizations
operationId: CreateMxBuroDeCreditoAuthorization
summary: Create a Buró de Crédito authorization
description: Create a Buró de Crédito authorization for an entity so report extractions can use it
parameters:
- $ref: '#/components/parameters/entityId'
requestBody:
required: true
content:
application/json:
schema:
oneOf:
- title: Person
properties:
authorizedAt:
type: string
format: date-time
description: Date and time when authorization was granted
example: '2024-01-31T00:00:00+00:00'
taxpayer:
type: object
description: Person identity and address data authorized for Buró de Crédito
required:
- rfc
- nationality
- birthdate
- firstName
- firstLastName
- secondLastName
- address
properties:
rfc:
type: string
description: Person RFC
example: PRPU800101HM2
nationality:
type: string
description: Two-letter nationality code
example: MX
birthdate:
type: string
format: date
description: Person birth date
example: '1980-01-01'
firstName:
type: string
description: Person first name
example: UNO
middleName:
type: string
nullable: true
description: Person middle name
example: DOS
firstLastName:
type: string
description: Person first last name
example: PRUEBA
secondLastName:
type: string
description: Person second last name
example: PROSPECTOR
address:
type: object
description: Mexico address data in the format required by Buró de Crédito
required:
- address
- city
- municipality
- state
- postalCode
- neighborhood
- country
properties:
address:
type: string
description: Street name
example: Jaime Balmes
city:
type: string
description: City
example: Cd de Mexico
municipality:
type: string
description: Municipality or borough
example: Miguel Hidalgo
state:
type: string
description: Buró de Crédito state code
example: CMX
postalCode:
type: string
description: Five-digit postal code
example: '11510'
exteriorNumber:
type: string
nullable: true
description: Exterior number
example: '8'
interiorNumber:
type: string
nullable: true
description: Interior number
example: ''
neighborhood:
type: string
description: Neighborhood
example: Los morales
country:
type: string
description: Two-letter country code
example: MX
- title: Company
properties:
authorizedAt:
type: string
format: date-time
description: Date and time when authorization was granted
example: '2024-01-31T00:00:00+00:00'
taxpayer:
type: object
description: Company identity and address data authorized for Buró de Crédito
properties:
rfc:
type: string
description: Company RFC
example: AGS930324RN7
nationality:
type: string
description: Two-letter nationality code
example: MX
tradeName:
type: string
description: Company trade or legal name
example: ALMACENES GHINOS, SA DE CV
address:
type: object
description: Mexico address data in the format required by Buró de Crédito
required:
- address
- city
- municipality
- state
- postalCode
- neighborhood
- country
properties:
address:
type: string
description: Street name
example: AV IGNACIO ALLENDE LOTE 11-B LOCAL 2
city:
type: string
description: City
example: TEPEAPULCO
municipality:
type: string
description: Municipality or borough
example: Cd de Mexico
state:
type: string
description: Buró de Crédito state code
example: CMX
postalCode:
type: string
description: Five-digit postal code
example: '11510'
exteriorNumber:
type: string
nullable: true
description: Exterior number
example: '8'
interiorNumber:
type: string
nullable: true
description: Interior number
example: ''
neighborhood:
type: string
description: Neighborhood
example: CD SAHAGUN HGO
country:
type: string
description: Two-letter country code
example: MX
required:
- rfc
- nationality
- tradeName
- address
required:
- authorizedAt
- taxpayer
required:
- authorizedAt
- taxpayer
responses:
'201':
description: Buró de Crédito Authorization created successfully
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
/datasources/mx/buro-de-credito/authorizations/{id}:
get:
tags:
- DS MX Buró de Crédito Authorizations
operationId: GetMxBuroDeCreditoAuthorization
summary: Get a Buró de Crédito authorization
description: Get a single Buró de Crédito authorization by authorization ID
parameters:
- $ref: '#/components/parameters/resourceId'
responses:
'200':
description: Buró de Crédito Authorization
content:
application/ld+json:
schema:
type: object
allOf:
- type: object
properties:
'@context':
default: /contexts/BuroDeCreditoAuthorization
'@id':
example: /entities/9bd4a640-9f41-4cd5-a158-20767b386ca0/datasources/mx/buro-de-credito/authorizations/9bd4a640-9f41-4cd5-a158-20767b386cb0
- $ref: '#/components/schemas/BuroDeCreditoAuthorization'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
delete:
tags:
- DS MX Buró de Crédito Authorizations
operationId: DeleteMxBuroDeCreditoAuthorization
summary: Delete a Buró de Crédito authorization
description: Delete a Buró de Crédito authorization by authorization ID
parameters:
- $ref: '#/components/parameters/resourceId'
responses:
'204':
description: Buró de Crédito Authorization deleted
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
components:
schemas:
TaxpayerID:
type: string
minLength: 12
maxLength: 13
description: RFC (Registro Federal de Contribuyentes)
example: PEIC211118IS0
TaxpayerPersonType:
type: string
enum:
- physical
- legal
example: physical
Entity:
type: object
properties:
'@id':
type: string
format: iri-reference
description: Entity IRI reference
example: /entities/91106968-1abd-4d64-85c1-4e73d96fb997
'@type':
type: string
description: JSON-LD resource type; Entity resources currently use the legacy `Link` JSON-LD type for backwards compatibility
default: Link
id:
$ref: '#/components/schemas/uuid'
type:
$ref: '#/components/schemas/EntityType'
taxpayer:
$ref: '#/components/schemas/Taxpayer'
credential:
$ref: '#/components/schemas/Credential'
tags:
$ref: '#/components/schemas/EntityTagCollection'
createdAt:
$ref: '#/components/schemas/createdAt'
updatedAt:
$ref: '#/components/schemas/updatedAt'
updatedAt:
type: string
description: Date and time the resource was last updated
example: '2020-01-01T12:15:00.000Z'
TaxpayerName:
type: string
minLength: 1
maxLength: 254
description: Taxpayer name
example: Pedro Infante Cruz
CollectionLimit:
type: integer
default: 20
minimum: 1
maximum: 1000
Credential:
type: object
properties:
'@id':
type: string
format: iri-reference
description: SAT Credential IRI reference
example: /credentials/91106968-1abd-4d64-85c1-4e73d96fb997
'@type':
type: string
default: Credential
id:
type: string
format: uuid
description: Credential ID
example: 91106968-1abd-4d64-85c1-4e73d96fb997
type:
$ref: '#/components/schemas/CredentialType'
rfc:
$ref: '#/components/schemas/TaxpayerID'
status:
$ref: '#/components/schemas/CredentialStatus'
createdAt:
$ref: '#/components/schemas/createdAt'
updatedAt:
$ref: '#/components/schemas/updatedAt'
EntityTagCollection:
type: array
items:
$ref: '#/components/schemas/EntityTag'
createdAt:
type: string
description: Date and time the resource was created
example: '2020-01-01T12:15:00.000Z'
EntityType:
type: string
enum:
- company
- person
description: Type of entity
example: company
Taxpayer:
type: object
properties:
'@id':
type: string
format: iri-reference
description: Taxpayer IRI reference
example: /taxpayers/PEIC211118IS0
'@type':
type: string
default: Taxpayer
id:
$ref: '#/components/schemas/TaxpayerID'
personType:
$ref: '#/components/schemas/TaxpayerPersonType'
registrationDate:
type: string
format: date
description: Taxpayer registration date
name:
$ref: '#/components/schemas/TaxpayerName'
BuroDeCreditoAuthorization:
oneOf:
- title: Person
type: object
required:
- id
- rfc
- authorizedAt
- authorizedUntil
- link
- nationality
- birthdate
- firstName
- firstLastName
- secondLastName
- address
- city
- municipality
- state
- postalCode
- neighborhood
- country
- createdAt
- updatedAt
properties:
id:
type: string
format: uuid
description: Unique authorization ID
example: 9bd4a640-9f41-4cd5-a158-20767b386ca0
rfc:
type: string
description: RFC authorized for Buró de Crédito report requests
example: PRPU800101HM2
link:
description: Entity associated with the authorization
$ref: '#/components/schemas/Entity'
authorizedAt:
type: string
format: date-time
description: Date and time when authorization was granted
example: '2024-01-31T00:00:00+00:00'
authorizedUntil:
type: string
format: date-time
description: Date and time when authorization expires
example: '2027-01-31T00:00:00+00:00'
nationality:
type: string
description: Two-letter nationality code
example: MX
birthdate:
type: string
format: date
description: Person birth date
example: '1980-01-01'
firstName:
type: string
description: Person first name
example: UNO
middleName:
type: string
nullable: true
description: Person middle name
example: DOS
firstLastName:
type: string
description: Person first last name
example: PRUEBA
secondLastName:
type: string
description: Person second last name
example: PROSPECTOR
address:
type: string
description: Street name used for the authorization address
example: Jaime Balmes
city:
type: string
description: City used for the authorization address
example: Cd de Mexico
municipality:
type: string
description: Municipality or borough used for the authorization address
example: Miguel Hidalgo
state:
type: string
description: Buró de Crédito state code for the authorization address
example: CMX
postalCode:
type: string
description: Five-digit postal code used for the authorization address
example: '11510'
exteriorNumber:
type: string
nullable: true
description: Exterior number used for the authorization address
example: '8'
interiorNumber:
type: string
nullable: true
description: Interior number used for the authorization address
example: ''
neighborhood:
type: string
description: Neighborhood used for the authorization address
example: Los morales
country:
type: string
description: Two-letter country code for the authorization address
example: MX
email:
type: string
nullable: true
description: Email address associated with the authorization when available
example: person@example.com
origin:
type: string
enum:
- external
- onboarding
description: How the authorization was created
example: external
isValid:
type: boolean
description: Whether the authorization has not expired
example: true
createdAt:
type: string
format: date-time
desc
# --- truncated at 32 KB (42 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/syntage/refs/heads/main/openapi/syntage-ds-mx-bur-de-cr-dito-authorizations-api-openapi.yml