tario.

Authentication and abilities

Sanctum personal tokens with read, create, and update abilities, sent as Authorization: Bearer.

Every /api/v1/* and /api/mcp route uses personal tokens. Each token belongs to a user and acts with that user's permissions: besides the token ability, the API requires the user's module permission ({module}.view to read, {module}.manage to change).

  1. In Tario open Profile → API tokens and create a token with a name that identifies the integration.

  2. Choose its abilities: read, create, update. Grant only what the integration needs.

  3. Copy the token: it is shown only once.

  4. Send it with every request as the Authorization: Bearer <token> header.

AbilityAllows
readQueries, lists, XML downloads, reports, and catalogs
createRegistering and issuing invoices, notes, and acceptances
updateE-mail resends, closes, withholdings, and webhook management

Error responses

CodeWhen
401The token is missing, revoked, or expired
403The token lacks the ability, the user lacks the module permission, or does not belong to the company
404The record does not exist or belongs to another company (or the other Hacienda environment)
422Validation: the body carries message and per-field errors
429You exceeded the per-minute request limit

For web connectors (claude.ai, ChatGPT) use OAuth 2.1 instead of a static token; see the OAuth guide.