Company (tenant) and limits
How the API picks the company for each request, isolation between companies, and usage limits.
A user can belong to several companies. The API resolves each request's company in this order:
The
X-Tario-Company: <company_id>header.The
?company_id=<id>query parameter.The token user's current company (
current_company_id).
The user must belong to that company; otherwise the API answers 403. Tokens issued through OAuth are pinned to the company the user chose when authorizing, and the header cannot change it.
Isolation
- Every resource belongs to the resolved company: an id from another company answers
404. - Fiscal documents also belong to the current Hacienda environment (sandbox or production); those of the other environment are hidden.
Limits
/api/v1/*and/api/mcp: 120 requests per minute per token.GET /api/v1/openapi.jsonandGET /api/version: 30 per minute, no token.- Past the limit the API answers
429with aRetry-Afterheader.