Developers

Build an integration that stops at the invoice draft

Use exact monetary strings, scoped HTTP access and retry protection, then hand the draft to a person.

Created Updated

An internal order tool can prepare a Pepper invoice draft for staff to review. MCP and HTTP tools support permitted reads, exact previews, draft creation and draft updates. This guide covers an integration that stops at the draft. Issuance is a separate prepared request that requires the delegated person's approval; sending is unavailable to clients.

Build the integration around that stopping point. A successful draft response means a draft exists. It does not mean the client received an invoice or that the business received payment.

Request the smallest useful grant

The owner enables access and creates an expiring connection. Calls remain within the granted capabilities and the delegated user's current record permissions. A credential cannot add a permission the user lacks.

Send the bearer credential from a server or command-line client over HTTPS. Keep it out of browser code, URLs and logs. Requests with an Origin header fail. MCP clients can also use browser OAuth sign-in. The connection manual explains both connection methods.

Connections expire after 1 to 30 days. The body limit is 256 KiB, invoices accept 1 to 100 lines, and lists return at most 50 records per page. Both the connection and IP address have a 60-request-per-minute limit. Clients behind one IP share its allowance.

Preview the exact input

Use a permitted customer ID, currency, dates and complete line set. Monetary values use strings of minor units. In EUR, "12500" means EUR 125.00. A quantity of "2" makes EUR 250.00 before tax or discount. In JPY, the same price string means JPY 12,500.

Send that input to POST /api/v1/documents/preview. Let the server calculate the total. Do not calculate a floating-point total and ask Pepper to trust it. The client must also use an existing tax rate chosen for the transaction; the pilot cannot create one or decide the treatment.

Then send the same input to POST /api/v1/drafts with an Idempotency-Key. Open the returned document link for a human review of the customer, lines, dates and total.

Make retries preserve one operation

Keep the key and payload for an uncertain write. An identical retry returns the original result without creating a second draft. Reusing that key with another payload or target returns a conflict.

An update needs the draft's current lock_version and the full header and line set. A stale version changes nothing. Read the current record, compare it with the intended change and use a new operation key after review. A stored retry result describes the original write, so read again when you need the draft's present state.

Leave consequential actions with staff

Staff can issue through the application, or approve one client-prepared issue request. Approval applies only to the reviewed invoice and expires 10 minutes after preparation. Only successful execution confirms issuance. Clients cannot send, settle, export files, change bank or tax settings, or access every application record. No AI account is required; an ordinary integration can use the same HTTP calls.

The client guide explains access and review. The API reference contains field details, MCP tool names and the separate prepared-request workflow. Use the changelog when choosing an integration target.