Income statement totals per calendar month
const url = 'https://api.flychain.us/external/v1/provider/9c1e7a42-0b3d-4e58-9f21-6a8b5c4d3e2f/business_entity/3f5d8b16-7c94-42a1-b0e6-58d9c2a71b43/financial_reports/income_statement/monthly/summary?start_date=2026-07-01&end_date=2026-07-31';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url 'https://api.flychain.us/external/v1/provider/9c1e7a42-0b3d-4e58-9f21-6a8b5c4d3e2f/business_entity/3f5d8b16-7c94-42a1-b0e6-58d9c2a71b43/financial_reports/income_statement/monthly/summary?start_date=2026-07-01&end_date=2026-07-31' \ --header 'Authorization: Bearer <token>'Partner and provider keys.
The category totals per calendar month across the range, plus the whole period — one request covers a trailing-twelve-month reconciliation for an entity.
Each period carries its own is_closed and is_complete flags, so a recurring job
can narrow its work to the months that can still move and treat closed months as
settled. This is the endpoint a daily job should use.
Months at the edge of the range are clipped, not extended: a range starting
mid-month yields a first period that starts on your start_date. See
guides/data-semantics.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”The provider, from GET /providers or the provider_id on a business-entity
record. With a partner key it must be a provider in your partner relationship;
with a provider key it is always your own provider_id, which GET /providers
returns.
Example
9c1e7a42-0b3d-4e58-9f21-6a8b5c4d3e2fThe business entity, from GET /business_entities. Must belong to the
provider_id in the same path.
Example
3f5d8b16-7c94-42a1-b0e6-58d9c2a71b43Query Parameters
Section titled “Query Parameters”First day of the requested range, inclusive.
Must be a real calendar date, zero-padded, in YYYY-MM-DD form — 2026-7-1 and
2026-02-31 are both 400 INVALID_REQUEST. Ranges are evaluated in UTC.
Raised to the entity’s books_start_date when it falls earlier. If the whole
requested range sits before the books begin, the result is
400 INVALID_REQUEST rather than a zero statement, so a range with no books
behind it can never read as a period with no revenue.
Example
2026-07-01Last day of the requested range, inclusive. Same format rules as start_date, and
must not be earlier than it.
Capped at today when it falls in the future, which is the ordinary case for a job that asks for the current month every day. The response echoes the effective range it used.
Example
2026-07-31Responses
Section titled “Responses”Category totals per period, plus the whole period.
Category totals per period, plus the whole range.
object
The basis an entity’s financials are prepared on.
A property of the entity, not a request parameter. A report is produced on the
basis the underlying books are kept on; there is no per-request switch. It is
returned on every entity record and every report so a figure is never ambiguous,
and it will not change without notice. See guides/data-semantics.
null only where the entity has no books yet — every entity with
reporting_available: true carries a basis.
When this payload was produced, ISO 8601 UTC.
Chronological, one entry per month in the effective range.
A period carrying the category totals.
object
Month and year of this period, e.g. July 2026. Derived from start_date, so
a clipped period still reads as its calendar month — use the dates, not the
label, to know what the period covers.
First day of the period, inclusive.
Last day of the period, inclusive.
Whether a Flychain bookkeeper has finalized the books through end_date.
This is the flag that says a figure is final.
Whether this period’s end_date is in the past. false for the in-progress
current month.
Note this is about the period, not the calendar month: a period clipped by
the requested range reads true once its end date has passed, even though the
calendar month it is labelled with is not fully covered.
The nine income-statement category totals, in statement order, plus
net_other_income_cents.
Every value is a signed integer in cents and is the rolled-up figure for that category, including every account beneath it. Expense categories are positive magnitudes, as they appear on the statement.
See guides/migrating-from-quickbooks for the mapping onto a QuickBooks Profit &
Loss.
object
Income earned from core services. This is gross revenue, and the figure to use as a revenue base.
Operating revenue net of refunds, discounts and write-offs. Equal to
operating_revenues_cents for most entities; where it differs it is the more
conservative revenue measure.
Direct costs of delivering the service.
Total net sales less cost of goods sold.
Overhead — administrative salaries, rent, software and the like.
Profit from operations, before non-operating items.
Non-operating costs, such as loan interest.
Non-operating income, such as grants or interest earned.
The bottom line, after everything above.
other_income_cents minus other_expenses_cents. The one derived value here,
returned directly so it does not have to be computed on your side.
The whole range carrying the category totals.
object
First day of the effective range, inclusive.
Last day of the effective range, inclusive.
Whether the books are finalized through end_date.
The nine income-statement category totals, in statement order, plus
net_other_income_cents.
Every value is a signed integer in cents and is the rolled-up figure for that category, including every account beneath it. Expense categories are positive magnitudes, as they appear on the statement.
See guides/migrating-from-quickbooks for the mapping onto a QuickBooks Profit &
Loss.
object
Income earned from core services. This is gross revenue, and the figure to use as a revenue base.
Operating revenue net of refunds, discounts and write-offs. Equal to
operating_revenues_cents for most entities; where it differs it is the more
conservative revenue measure.
Direct costs of delivering the service.
Total net sales less cost of goods sold.
Overhead — administrative salaries, rent, software and the like.
Profit from operations, before non-operating items.
Non-operating costs, such as loan interest.
Non-operating income, such as grants or interest earned.
The bottom line, after everything above.
other_income_cents minus other_expenses_cents. The one derived value here,
returned directly so it does not have to be computed on your side.
Examples
Two months of totals, plus the whole range
GET .../financial_reports/income_statement/monthly/summary?start_date=2026-06-01&end_date=2026-07-31
June is closed and settled; July is complete as a calendar month but its books are
not yet closed, so its figures can still move. whole_period is computed over the
whole range independently rather than summed from the periods.
{ "provider_id": "9c1e7a42-0b3d-4e58-9f21-6a8b5c4d3e2f", "business_entity_id": "3f5d8b16-7c94-42a1-b0e6-58d9c2a71b43", "accounting_basis": "CASH", "currency": "USD", "generated_at": "2026-08-20T14:02:11Z", "periods": [ { "label": "June 2026", "start_date": "2026-06-01", "end_date": "2026-06-30", "is_closed": true, "is_complete": true, "totals": { "operating_revenues_cents": 3510000, "total_net_sales_cents": 3510000, "cost_of_goods_sold_cents": 1750000, "gross_profit_cents": 1760000, "operating_expenses_cents": 880000, "total_operating_profit_cents": 880000, "other_expenses_cents": 12000, "other_income_cents": 0, "net_profit_cents": 868000, "net_other_income_cents": -12000 } }, { "label": "July 2026", "start_date": "2026-07-01", "end_date": "2026-07-31", "is_closed": false, "is_complete": true, "totals": { "operating_revenues_cents": 3642500, "total_net_sales_cents": 3642500, "cost_of_goods_sold_cents": 1820000, "gross_profit_cents": 1822500, "operating_expenses_cents": 910000, "total_operating_profit_cents": 912500, "other_expenses_cents": 15000, "other_income_cents": 0, "net_profit_cents": 897500, "net_other_income_cents": -15000 } } ], "whole_period": { "start_date": "2026-06-01", "end_date": "2026-07-31", "is_closed": false, "totals": { "operating_revenues_cents": 7152500, "total_net_sales_cents": 7152500, "cost_of_goods_sold_cents": 3570000, "gross_profit_cents": 3582500, "operating_expenses_cents": 1790000, "total_operating_profit_cents": 1792500, "other_expenses_cents": 27000, "other_income_cents": 0, "net_profit_cents": 1765500, "net_other_income_cents": -27000 } }}Malformed request — a missing or unparseable date, a path id that is not a UUID,
start_date after end_date, or a range that does not overlap the period this
entity has books for. Also returned when the request reached us over plaintext
HTTP; see INSECURE_TRANSPORT below and guides/authentication.
The failure shape for every error — validation, authorization, ours — so a client needs a single error path.
Match on code, not on message: the code set below is the contract and is
stable, while wording may be clarified. New codes may be added within v1 (see
guides/versioning), so treat an unrecognised code as “the HTTP status is
authoritative”.
This includes a request that never reaches a documented operation at all — an
unrouted path or a method we do not serve on that path, which is the failure you
are most likely to meet while integrating. Those are answered before any operation
runs, so no operation below lists them, but they arrive in this same shape, as
ENDPOINT_NOT_FOUND (404) and METHOD_NOT_ALLOWED (405). Either one means
check the URL rather than your credentials: the operations below are the whole
surface.
object
object
Machine-readable cause.
INVALID_REQUEST(400) — malformed dates, a non-UUID path id, an inverted range, or a range with no reportable books behind it.INSECURE_TRANSPORT(400) — the request was sent over plaintexthttp, so the key crossed the network in the clear. Rotate the key, then fix the URL; we refuse rather than redirect so this cannot pass unnoticed.INVALID_API_KEY(401) — missing, invalid, expired or revoked key.PARTNER_API_NOT_ENABLED(403) — your key is valid, but your organization is not enrolled in the API programme. Contact us; do not rotate the key.PROVIDER_NOT_ACTIVE(403) — a provider key whose Flychain account is not active. Contact us; do not rotate the key.PROVIDER_API_NOT_ENABLED(403) — a provider key on an account that is not enrolled in the API programme. Contact us; do not rotate the key.ENDPOINT_NOT_AVAILABLE(403) — the path exists and your key is valid, but that operation is not served for your kind of key. The balance sheet and cash flow families are provider-only. Your URL is not wrong; do not rotate the key.PROVIDER_NOT_IN_PARTNER_SCOPE(403) — the provider exists but is not in your relationship, including one that has left it.BUSINESS_ENTITY_NOT_IN_PARTNER_SCOPE(403) — the entity exists but does not belong to theprovider_idin the path.PROVIDER_NOT_FOUND(404) — no provider with that id.BUSINESS_ENTITY_NOT_FOUND(404) — no business entity with that id.ENDPOINT_NOT_FOUND(404) — the URL itself is not one we serve, as opposed to a record we do not have. Check the path against the operations below.METHOD_NOT_ALLOWED(405) — the path exists but not with that method; theAllowresponse header lists the ones it takes. Every operation here is aGET.BOOKS_NOT_AVAILABLE(409) — the entity has no reportable books.INTERNAL_ERROR(500) — ours; retry with backoff.AUTH_SERVICE_UNAVAILABLE(503) — we could not verify your key; retry with backoff, and do not treat it as an authentication failure.
Human-readable detail. Do not match on it.
Examples
Unparseable date
{ "error": { "code": "INVALID_REQUEST", "message": "start_date must be a valid date in YYYY-MM-DD format." }}Path id is not a UUID
{ "error": { "code": "INVALID_REQUEST", "message": "business_entity_id is not a valid UUID." }}Range sits entirely outside the reportable period
{ "error": { "code": "INVALID_REQUEST", "message": "The requested range does not overlap the period this entity has reportable books for. It must fall on or after books_start_date (see GET /business_entities) and must not be entirely in the future." }}Request sent over plaintext HTTP
{ "error": { "code": "INSECURE_TRANSPORT", "message": "This request was sent over plaintext HTTP, so any API key it carried was transmitted in the clear. Reissue it over HTTPS, and treat the key as compromised: rotate it." }}Missing, invalid, expired or revoked API key. One message covers every case on purpose — a caller cannot tell a revoked key from an unknown one.
The failure shape for every error — validation, authorization, ours — so a client needs a single error path.
Match on code, not on message: the code set below is the contract and is
stable, while wording may be clarified. New codes may be added within v1 (see
guides/versioning), so treat an unrecognised code as “the HTTP status is
authoritative”.
This includes a request that never reaches a documented operation at all — an
unrouted path or a method we do not serve on that path, which is the failure you
are most likely to meet while integrating. Those are answered before any operation
runs, so no operation below lists them, but they arrive in this same shape, as
ENDPOINT_NOT_FOUND (404) and METHOD_NOT_ALLOWED (405). Either one means
check the URL rather than your credentials: the operations below are the whole
surface.
object
object
Machine-readable cause.
INVALID_REQUEST(400) — malformed dates, a non-UUID path id, an inverted range, or a range with no reportable books behind it.INSECURE_TRANSPORT(400) — the request was sent over plaintexthttp, so the key crossed the network in the clear. Rotate the key, then fix the URL; we refuse rather than redirect so this cannot pass unnoticed.INVALID_API_KEY(401) — missing, invalid, expired or revoked key.PARTNER_API_NOT_ENABLED(403) — your key is valid, but your organization is not enrolled in the API programme. Contact us; do not rotate the key.PROVIDER_NOT_ACTIVE(403) — a provider key whose Flychain account is not active. Contact us; do not rotate the key.PROVIDER_API_NOT_ENABLED(403) — a provider key on an account that is not enrolled in the API programme. Contact us; do not rotate the key.ENDPOINT_NOT_AVAILABLE(403) — the path exists and your key is valid, but that operation is not served for your kind of key. The balance sheet and cash flow families are provider-only. Your URL is not wrong; do not rotate the key.PROVIDER_NOT_IN_PARTNER_SCOPE(403) — the provider exists but is not in your relationship, including one that has left it.BUSINESS_ENTITY_NOT_IN_PARTNER_SCOPE(403) — the entity exists but does not belong to theprovider_idin the path.PROVIDER_NOT_FOUND(404) — no provider with that id.BUSINESS_ENTITY_NOT_FOUND(404) — no business entity with that id.ENDPOINT_NOT_FOUND(404) — the URL itself is not one we serve, as opposed to a record we do not have. Check the path against the operations below.METHOD_NOT_ALLOWED(405) — the path exists but not with that method; theAllowresponse header lists the ones it takes. Every operation here is aGET.BOOKS_NOT_AVAILABLE(409) — the entity has no reportable books.INTERNAL_ERROR(500) — ours; retry with backoff.AUTH_SERVICE_UNAVAILABLE(503) — we could not verify your key; retry with backoff, and do not treat it as an authentication failure.
Human-readable detail. Do not match on it.
Examples
{ "error": { "code": "INVALID_API_KEY", "message": "Missing, invalid, expired or revoked API key." }}Your key is valid, but this call is not allowed: your organization is not enrolled
in the API programme (or, for a provider key, its Flychain account is not active),
or the provider or business entity exists but is not in your partner relationship
— including one that has left it. The partner scope cases are distinct from 404
on purpose, so “gone” and “never existed” are tellable apart. None of these is a
credential problem; rotating the key will not help.
The failure shape for every error — validation, authorization, ours — so a client needs a single error path.
Match on code, not on message: the code set below is the contract and is
stable, while wording may be clarified. New codes may be added within v1 (see
guides/versioning), so treat an unrecognised code as “the HTTP status is
authoritative”.
This includes a request that never reaches a documented operation at all — an
unrouted path or a method we do not serve on that path, which is the failure you
are most likely to meet while integrating. Those are answered before any operation
runs, so no operation below lists them, but they arrive in this same shape, as
ENDPOINT_NOT_FOUND (404) and METHOD_NOT_ALLOWED (405). Either one means
check the URL rather than your credentials: the operations below are the whole
surface.
object
object
Machine-readable cause.
INVALID_REQUEST(400) — malformed dates, a non-UUID path id, an inverted range, or a range with no reportable books behind it.INSECURE_TRANSPORT(400) — the request was sent over plaintexthttp, so the key crossed the network in the clear. Rotate the key, then fix the URL; we refuse rather than redirect so this cannot pass unnoticed.INVALID_API_KEY(401) — missing, invalid, expired or revoked key.PARTNER_API_NOT_ENABLED(403) — your key is valid, but your organization is not enrolled in the API programme. Contact us; do not rotate the key.PROVIDER_NOT_ACTIVE(403) — a provider key whose Flychain account is not active. Contact us; do not rotate the key.PROVIDER_API_NOT_ENABLED(403) — a provider key on an account that is not enrolled in the API programme. Contact us; do not rotate the key.ENDPOINT_NOT_AVAILABLE(403) — the path exists and your key is valid, but that operation is not served for your kind of key. The balance sheet and cash flow families are provider-only. Your URL is not wrong; do not rotate the key.PROVIDER_NOT_IN_PARTNER_SCOPE(403) — the provider exists but is not in your relationship, including one that has left it.BUSINESS_ENTITY_NOT_IN_PARTNER_SCOPE(403) — the entity exists but does not belong to theprovider_idin the path.PROVIDER_NOT_FOUND(404) — no provider with that id.BUSINESS_ENTITY_NOT_FOUND(404) — no business entity with that id.ENDPOINT_NOT_FOUND(404) — the URL itself is not one we serve, as opposed to a record we do not have. Check the path against the operations below.METHOD_NOT_ALLOWED(405) — the path exists but not with that method; theAllowresponse header lists the ones it takes. Every operation here is aGET.BOOKS_NOT_AVAILABLE(409) — the entity has no reportable books.INTERNAL_ERROR(500) — ours; retry with backoff.AUTH_SERVICE_UNAVAILABLE(503) — we could not verify your key; retry with backoff, and do not treat it as an authentication failure.
Human-readable detail. Do not match on it.
Examples
Your organization is not enrolled in the API programme
{ "error": { "code": "PARTNER_API_NOT_ENABLED", "message": "This partner is not enrolled in the Flychain external API programme. Contact Flychain to request access." }}Provider key whose Flychain account is not active
{ "error": { "code": "PROVIDER_NOT_ACTIVE", "message": "This provider's Flychain account is not active, so the API is not available to it. Contact Flychain." }}Provider key on an account not enrolled in the API programme
{ "error": { "code": "PROVIDER_API_NOT_ENABLED", "message": "This provider is not enrolled in the Flychain external API programme. Contact Flychain to request access." }}Provider not in your relationship
{ "error": { "code": "PROVIDER_NOT_IN_PARTNER_SCOPE", "message": "The provider is not associated with this partner." }}Entity does not belong to the provider in the path
{ "error": { "code": "BUSINESS_ENTITY_NOT_IN_PARTNER_SCOPE", "message": "The business entity does not belong to the requested provider." }}No provider or business entity exists with that id.
The failure shape for every error — validation, authorization, ours — so a client needs a single error path.
Match on code, not on message: the code set below is the contract and is
stable, while wording may be clarified. New codes may be added within v1 (see
guides/versioning), so treat an unrecognised code as “the HTTP status is
authoritative”.
This includes a request that never reaches a documented operation at all — an
unrouted path or a method we do not serve on that path, which is the failure you
are most likely to meet while integrating. Those are answered before any operation
runs, so no operation below lists them, but they arrive in this same shape, as
ENDPOINT_NOT_FOUND (404) and METHOD_NOT_ALLOWED (405). Either one means
check the URL rather than your credentials: the operations below are the whole
surface.
object
object
Machine-readable cause.
INVALID_REQUEST(400) — malformed dates, a non-UUID path id, an inverted range, or a range with no reportable books behind it.INSECURE_TRANSPORT(400) — the request was sent over plaintexthttp, so the key crossed the network in the clear. Rotate the key, then fix the URL; we refuse rather than redirect so this cannot pass unnoticed.INVALID_API_KEY(401) — missing, invalid, expired or revoked key.PARTNER_API_NOT_ENABLED(403) — your key is valid, but your organization is not enrolled in the API programme. Contact us; do not rotate the key.PROVIDER_NOT_ACTIVE(403) — a provider key whose Flychain account is not active. Contact us; do not rotate the key.PROVIDER_API_NOT_ENABLED(403) — a provider key on an account that is not enrolled in the API programme. Contact us; do not rotate the key.ENDPOINT_NOT_AVAILABLE(403) — the path exists and your key is valid, but that operation is not served for your kind of key. The balance sheet and cash flow families are provider-only. Your URL is not wrong; do not rotate the key.PROVIDER_NOT_IN_PARTNER_SCOPE(403) — the provider exists but is not in your relationship, including one that has left it.BUSINESS_ENTITY_NOT_IN_PARTNER_SCOPE(403) — the entity exists but does not belong to theprovider_idin the path.PROVIDER_NOT_FOUND(404) — no provider with that id.BUSINESS_ENTITY_NOT_FOUND(404) — no business entity with that id.ENDPOINT_NOT_FOUND(404) — the URL itself is not one we serve, as opposed to a record we do not have. Check the path against the operations below.METHOD_NOT_ALLOWED(405) — the path exists but not with that method; theAllowresponse header lists the ones it takes. Every operation here is aGET.BOOKS_NOT_AVAILABLE(409) — the entity has no reportable books.INTERNAL_ERROR(500) — ours; retry with backoff.AUTH_SERVICE_UNAVAILABLE(503) — we could not verify your key; retry with backoff, and do not treat it as an authentication failure.
Human-readable detail. Do not match on it.
Examples
{ "error": { "code": "PROVIDER_NOT_FOUND", "message": "No provider exists with that id." }}{ "error": { "code": "BUSINESS_ENTITY_NOT_FOUND", "message": "No business entity exists with that id." }}The entity exists and is in your relationship, but has no books a report can be
produced from — it is still onboarding, or it has been deactivated. It appears in
GET /business_entities with reporting_available: false; skip it rather than
recording a zero.
The failure shape for every error — validation, authorization, ours — so a client needs a single error path.
Match on code, not on message: the code set below is the contract and is
stable, while wording may be clarified. New codes may be added within v1 (see
guides/versioning), so treat an unrecognised code as “the HTTP status is
authoritative”.
This includes a request that never reaches a documented operation at all — an
unrouted path or a method we do not serve on that path, which is the failure you
are most likely to meet while integrating. Those are answered before any operation
runs, so no operation below lists them, but they arrive in this same shape, as
ENDPOINT_NOT_FOUND (404) and METHOD_NOT_ALLOWED (405). Either one means
check the URL rather than your credentials: the operations below are the whole
surface.
object
object
Machine-readable cause.
INVALID_REQUEST(400) — malformed dates, a non-UUID path id, an inverted range, or a range with no reportable books behind it.INSECURE_TRANSPORT(400) — the request was sent over plaintexthttp, so the key crossed the network in the clear. Rotate the key, then fix the URL; we refuse rather than redirect so this cannot pass unnoticed.INVALID_API_KEY(401) — missing, invalid, expired or revoked key.PARTNER_API_NOT_ENABLED(403) — your key is valid, but your organization is not enrolled in the API programme. Contact us; do not rotate the key.PROVIDER_NOT_ACTIVE(403) — a provider key whose Flychain account is not active. Contact us; do not rotate the key.PROVIDER_API_NOT_ENABLED(403) — a provider key on an account that is not enrolled in the API programme. Contact us; do not rotate the key.ENDPOINT_NOT_AVAILABLE(403) — the path exists and your key is valid, but that operation is not served for your kind of key. The balance sheet and cash flow families are provider-only. Your URL is not wrong; do not rotate the key.PROVIDER_NOT_IN_PARTNER_SCOPE(403) — the provider exists but is not in your relationship, including one that has left it.BUSINESS_ENTITY_NOT_IN_PARTNER_SCOPE(403) — the entity exists but does not belong to theprovider_idin the path.PROVIDER_NOT_FOUND(404) — no provider with that id.BUSINESS_ENTITY_NOT_FOUND(404) — no business entity with that id.ENDPOINT_NOT_FOUND(404) — the URL itself is not one we serve, as opposed to a record we do not have. Check the path against the operations below.METHOD_NOT_ALLOWED(405) — the path exists but not with that method; theAllowresponse header lists the ones it takes. Every operation here is aGET.BOOKS_NOT_AVAILABLE(409) — the entity has no reportable books.INTERNAL_ERROR(500) — ours; retry with backoff.AUTH_SERVICE_UNAVAILABLE(503) — we could not verify your key; retry with backoff, and do not treat it as an authentication failure.
Human-readable detail. Do not match on it.
Examples
{ "error": { "code": "BOOKS_NOT_AVAILABLE", "message": "This business entity does not currently have reportable books. GET /business_entities lists it with reporting_available: false." }}Our side. Safe to retry with backoff.
The failure shape for every error — validation, authorization, ours — so a client needs a single error path.
Match on code, not on message: the code set below is the contract and is
stable, while wording may be clarified. New codes may be added within v1 (see
guides/versioning), so treat an unrecognised code as “the HTTP status is
authoritative”.
This includes a request that never reaches a documented operation at all — an
unrouted path or a method we do not serve on that path, which is the failure you
are most likely to meet while integrating. Those are answered before any operation
runs, so no operation below lists them, but they arrive in this same shape, as
ENDPOINT_NOT_FOUND (404) and METHOD_NOT_ALLOWED (405). Either one means
check the URL rather than your credentials: the operations below are the whole
surface.
object
object
Machine-readable cause.
INVALID_REQUEST(400) — malformed dates, a non-UUID path id, an inverted range, or a range with no reportable books behind it.INSECURE_TRANSPORT(400) — the request was sent over plaintexthttp, so the key crossed the network in the clear. Rotate the key, then fix the URL; we refuse rather than redirect so this cannot pass unnoticed.INVALID_API_KEY(401) — missing, invalid, expired or revoked key.PARTNER_API_NOT_ENABLED(403) — your key is valid, but your organization is not enrolled in the API programme. Contact us; do not rotate the key.PROVIDER_NOT_ACTIVE(403) — a provider key whose Flychain account is not active. Contact us; do not rotate the key.PROVIDER_API_NOT_ENABLED(403) — a provider key on an account that is not enrolled in the API programme. Contact us; do not rotate the key.ENDPOINT_NOT_AVAILABLE(403) — the path exists and your key is valid, but that operation is not served for your kind of key. The balance sheet and cash flow families are provider-only. Your URL is not wrong; do not rotate the key.PROVIDER_NOT_IN_PARTNER_SCOPE(403) — the provider exists but is not in your relationship, including one that has left it.BUSINESS_ENTITY_NOT_IN_PARTNER_SCOPE(403) — the entity exists but does not belong to theprovider_idin the path.PROVIDER_NOT_FOUND(404) — no provider with that id.BUSINESS_ENTITY_NOT_FOUND(404) — no business entity with that id.ENDPOINT_NOT_FOUND(404) — the URL itself is not one we serve, as opposed to a record we do not have. Check the path against the operations below.METHOD_NOT_ALLOWED(405) — the path exists but not with that method; theAllowresponse header lists the ones it takes. Every operation here is aGET.BOOKS_NOT_AVAILABLE(409) — the entity has no reportable books.INTERNAL_ERROR(500) — ours; retry with backoff.AUTH_SERVICE_UNAVAILABLE(503) — we could not verify your key; retry with backoff, and do not treat it as an authentication failure.
Human-readable detail. Do not match on it.
Examples
{ "error": { "code": "INTERNAL_ERROR", "message": "An unexpected error occurred. Retry with backoff." }}We could not verify your API key right now — our identity provider was
unreachable or rate-limited. This is not an authentication failure: the key
may well be valid. Retry with backoff rather than treating it as a 401.
The failure shape for every error — validation, authorization, ours — so a client needs a single error path.
Match on code, not on message: the code set below is the contract and is
stable, while wording may be clarified. New codes may be added within v1 (see
guides/versioning), so treat an unrecognised code as “the HTTP status is
authoritative”.
This includes a request that never reaches a documented operation at all — an
unrouted path or a method we do not serve on that path, which is the failure you
are most likely to meet while integrating. Those are answered before any operation
runs, so no operation below lists them, but they arrive in this same shape, as
ENDPOINT_NOT_FOUND (404) and METHOD_NOT_ALLOWED (405). Either one means
check the URL rather than your credentials: the operations below are the whole
surface.
object
object
Machine-readable cause.
INVALID_REQUEST(400) — malformed dates, a non-UUID path id, an inverted range, or a range with no reportable books behind it.INSECURE_TRANSPORT(400) — the request was sent over plaintexthttp, so the key crossed the network in the clear. Rotate the key, then fix the URL; we refuse rather than redirect so this cannot pass unnoticed.INVALID_API_KEY(401) — missing, invalid, expired or revoked key.PARTNER_API_NOT_ENABLED(403) — your key is valid, but your organization is not enrolled in the API programme. Contact us; do not rotate the key.PROVIDER_NOT_ACTIVE(403) — a provider key whose Flychain account is not active. Contact us; do not rotate the key.PROVIDER_API_NOT_ENABLED(403) — a provider key on an account that is not enrolled in the API programme. Contact us; do not rotate the key.ENDPOINT_NOT_AVAILABLE(403) — the path exists and your key is valid, but that operation is not served for your kind of key. The balance sheet and cash flow families are provider-only. Your URL is not wrong; do not rotate the key.PROVIDER_NOT_IN_PARTNER_SCOPE(403) — the provider exists but is not in your relationship, including one that has left it.BUSINESS_ENTITY_NOT_IN_PARTNER_SCOPE(403) — the entity exists but does not belong to theprovider_idin the path.PROVIDER_NOT_FOUND(404) — no provider with that id.BUSINESS_ENTITY_NOT_FOUND(404) — no business entity with that id.ENDPOINT_NOT_FOUND(404) — the URL itself is not one we serve, as opposed to a record we do not have. Check the path against the operations below.METHOD_NOT_ALLOWED(405) — the path exists but not with that method; theAllowresponse header lists the ones it takes. Every operation here is aGET.BOOKS_NOT_AVAILABLE(409) — the entity has no reportable books.INTERNAL_ERROR(500) — ours; retry with backoff.AUTH_SERVICE_UNAVAILABLE(503) — we could not verify your key; retry with backoff, and do not treat it as an authentication failure.
Human-readable detail. Do not match on it.
Examples
{ "error": { "code": "AUTH_SERVICE_UNAVAILABLE", "message": "Unable to verify the API key right now. Retry with backoff." }}