Machine translation, not yet reviewed.
REST API conventions
The Tax360 APIs follow the REST architecture and are accessed via the HTTP protocol. All responses, including errors, are returned in JSON format.
Overview
The Tax360 APIs follow the REST architecture and are accessed via the HTTP protocol. All responses, including errors, are returned in JSON format.
Authentication
All requests require a JWT token, obtained from an API key created by an administrator user in the IAM portal.
The token must be sent in the HTTP Authorization header with the Bearer scheme:
Authorization: Bearer <seu_token_jwt>
Internationalization (i18n)
All endpoints accept the Accept-Language header to control the language of the returned messages.
| Value | Language |
|---|---|
pt-BR | Portuguese (Brazil) |
en-US | English (United States) |
Base Domains
| Service | URL |
|---|---|
| IAM | https://<API_HOST>/ |
| DF-e | https://<API_HOST>/ |
Standard Response Format
Except for the token generation endpoint, all endpoints return a JSON in the following format:
{
"code": "SUCCESS",
"message": "Mensagem",
"data": null,
"success": true
}
Fields
| Field | Type | Required | Description |
|---|---|---|---|
success | boolean | Yes | Indicates whether the operation succeeded. Values: true or false. |
code | string | Yes | Operation code. SUCCESS for success; other values depend on the endpoint context. |
message | string | No | Human-readable message that can be displayed directly to the end user. For custom messages, inspect the code field. |
data | object | array | null | No | Response payload. The content varies by endpoint — it can be an object, an array of objects, an ID, or null. |
HTTP Status
Success
| Code | Usage |
|---|---|
200 | Operation completed successfully (default). |
202 | Asynchronous operation started; it will be completed later. |
204 | Deletion completed successfully. |
Error
| Code | Meaning | Recommended action |
|---|---|---|
400 | Data validation or business rule error. | Display message to the user or inspect code for a custom message. |
401 | Invalid or expired token. | Generate a new token via IAM. |
403 | Permission denied. | Check whether the API key has the permissions required for the operation. |
500 | Internal server error. | Retry the request. If it persists, display a message to the user and contact support. |