Authentication and abilities
Sanctum personal tokens with read, create, and update abilities, sent as Authorization: Bearer.
Every /api/v1/* and /api/mcp route uses personal tokens. Each token belongs to a user and acts with that user's permissions: besides the token ability, the API requires the user's module permission ({module}.view to read, {module}.manage to change).
In Tario open Profile → API tokens and create a token with a name that identifies the integration.
Choose its abilities:
read,create,update. Grant only what the integration needs.Copy the token: it is shown only once.
Send it with every request as the
Authorization: Bearer <token>header.
| Ability | Allows |
|---|---|
read | Queries, lists, XML downloads, reports, and catalogs |
create | Registering and issuing invoices, notes, and acceptances |
update | E-mail resends, closes, withholdings, and webhook management |
Error responses
| Code | When |
|---|---|
401 | The token is missing, revoked, or expired |
403 | The token lacks the ability, the user lacks the module permission, or does not belong to the company |
404 | The record does not exist or belongs to another company (or the other Hacienda environment) |
422 | Validation: the body carries message and per-field errors |
429 | You exceeded the per-minute request limit |
For web connectors (claude.ai, ChatGPT) use OAuth 2.1 instead of a static token; see the OAuth guide.