Factuarea APIDevelopers

Register a representation

Register the representation that lets Factuarea remit your VeriFactu records to AEAT with its own certificate.

  • Send multipart/form-data with kind (social_collaboration_annex_i or aeat_power_of_attorney), signer_name, signer_tax_id, granted_on and the evidence: the signed annex I as document (PDF, up to 5 MB, validated by magic bytes) for social collaboration, and the proof of the power of attorney as document or its reference in power_of_attorney_reference for a power of attorney.
  • The document is custodied encrypted and counts against your storage quota (402 storage_quota_exceeded).
  • If a representation was already active it is revoked and kept in the history, and the new one becomes the active one.
  • The optional valid_until sets the last day of validity (not before granted_on, at most 5 years after it); without it the representation does not expire, and once the day has passed it stops enabling third-party remission (you are warned 30 and 7 days ahead and when it expires).
  • If your company already remits through a third-party mode, registering a representation of the OTHER kind moves the mode to the one that kind asks for (annex I → social_collaborator, power of attorney → power_of_attorney) — or back to own_certificate when that mode cannot be used, because this instance does not offer the social collaborator or the new representation is already expired — and the records that were blocked waiting for it are reactivated.
  • With own_certificate nothing changes: switch explicitly with PUT /v1/verifactu/settings, which requires this representation.
  • Returns 201 with data (the new representation) and remission_mode, the remission mode that results, plus a Location header; an invalid payload returns 422 (param names the field; the evidence that is missing or not a valid PDF is business_rule_violation / invalid_representation).
POST
/verifactu/representation
AuthorizationBearer <token>

In: header

Headers

Idempotency-Key*string

Client-generated opaque key (up to 255 characters; UUID v7 recommended) that makes retries safe: the first response is cached and replayed for repeats without re-executing the mutation. Reusing a key with a different body returns 409 idempotency_key_reused. See the Idempotency guide. Required on this operation: repeating it delivers an effect that cannot be taken back (an email sent, a file generated, a third-party call, a charge), so a request without this header is rejected with 422 idempotency_key_required before any business logic runs.

Length1 <= length <= 255
Factuarea-Version?string

Pin the API version (YYYY-MM-DD, Stripe-style date versioning) for this request; omit to use the key's pinned version, or the latest if none. Unsupported version → 400 unsupported_api_version; malformed → 400 parameter_invalid_format. The effective version is echoed in the Factuarea-Version response header. See the Versioning guide.

Formatdate
X-Active-Profile?string

Operate on behalf of a child company (gestoría master key): pass its public id (UUID v7) and the request runs against that child's data without changing the key's scope, tier or environment (omit to use the key's own company). Invalid UUID → 400 parameter_invalid_uuid; unknown or non-owned id → 404 profile_not_found. See the Acting on behalf guide.

Formatuuid

Request Body

multipart/form-data

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json