tario.

Company (tenant) and limits

How the API picks the company for each request, isolation between companies, and usage limits.

A user can belong to several companies. The API resolves each request's company in this order:

  1. The X-Tario-Company: <company_id> header.

  2. The ?company_id=<id> query parameter.

  3. The token user's current company (current_company_id).

The user must belong to that company; otherwise the API answers 403. Tokens issued through OAuth are pinned to the company the user chose when authorizing, and the header cannot change it.

Isolation

  • Every resource belongs to the resolved company: an id from another company answers 404.
  • Fiscal documents also belong to the current Hacienda environment (sandbox or production); those of the other environment are hidden.

Limits

  • /api/v1/* and /api/mcp: 120 requests per minute per token.
  • GET /api/v1/openapi.json and GET /api/version: 30 per minute, no token.
  • Past the limit the API answers 429 with a Retry-After header.