> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fintoro.sk/llms.txt
> Use this file to discover all available pages before exploring further.

# List orders

> Returns a paginated list of orders in a lightweight preview shape. Use this endpoint for lists, synchronization, and quick overview use cases; use the order detail endpoint for the full document.



## OpenAPI

````yaml /en/openapi.yaml get /orders
openapi: 3.1.0
info:
  title: Fintoro API v1
  version: 1.0.0
  description: >
    Fintoro API v1 is a REST API for integrating Fintoro invoicing, CRM, and
    warehouse workflows into third-party systems.


    Production and sandbox companies use the same base URL
    `https://app.fintoro.sk/api/public/v1`. The bearer token decides which
    company you work with.


    The optional `Accept-Language` request header localizes system-owned labels
    in lookups, in related response objects, and in validation errors. The
    `Content-Language` response header returns the language used in the
    response.


    For onboarding and operational guidance, also see:

    - [Getting started](/en/getting-started)

    - [Authentication](/en/authentication)

    - [Webhooks](/en/webhooks)

    - [Sandbox testing](/en/sandbox-testing)

    - [API conventions](/en/conventions)

    - [Errors and idempotency](/en/errors-and-idempotency)
servers:
  - url: https://app.fintoro.sk/api/public/v1
    description: Production Fintoro API.
security:
  - bearerAuth: []
tags:
  - name: Token identity
    description: >-
      Technical read-only endpoint that confirms which company the current
      bearer token belongs to.
  - name: Lookups
    description: >-
      Read-only lookup endpoints for integration data. These endpoints return
      lookup datasets with stable IDs that are safe to cache on your side. When
      new lookup values are added, existing IDs do not change or get reassigned.
  - name: Numerical Series
    description: >-
      Read-only endpoints for numerical series. They return the live
      configuration used when creating documents, including the next generated
      document number and variable symbol.
  - name: Subjects
    description: Look up and verify subject details before creating a client.
  - name: Clients
    description: >-
      Manage clients, including billing address, delivery address, and
      client-scoped default values that can be reused when building payloads for
      new documents. Create, update, and delete operations can emit
      `clients.created`, `clients.updated`, and `clients.deleted` webhook
      events.
  - name: Suppliers
    description: >-
      Manage suppliers, including billing address and identifier data used by
      the warehouse inbound resolve-or-create flow. Create, update, and delete
      operations can emit `suppliers.created`, `suppliers.updated`, and
      `suppliers.deleted` webhook events.
  - name: Business Case Statuses
    description: >-
      Manage business-case statuses. Statuses represent pipeline columns. In
      this API version, a reorder endpoint is not available; when a status is
      deleted, linked business cases are detached to `null`. Create, update, and
      delete operations can emit `business-case-statuses.created`,
      `business-case-statuses.updated`, and `business-case-statuses.deleted`
      webhook events.
  - name: Business Cases
    description: >-
      Manage business cases, including the nested client or supplier and an
      optional status. Reorder flows and changing the linked contact through
      update are not available in this API version. Create, update, and delete
      operations can emit `business-cases.created`, `business-cases.updated`,
      and `business-cases.deleted` webhook events.
  - name: CRM Events
    description: >-
      Manage CRM events for `note`, `email`, `phone_call`, and
      `document_linked`. Attachments use a separate two-step upload endpoint.
      Create, update, and delete operations can emit
      `contact-activity-logs.created`, `contact-activity-logs.updated`, and
      `contact-activity-logs.deleted` webhook events.
  - name: Bank Accounts
    description: >-
      Manage bank accounts, including bank details, primary account state, and
      open banking metadata. Create, update, and delete operations can emit
      `bank-accounts.created`, `bank-accounts.updated`, and
      `bank-accounts.deleted` webhook events.
  - name: Webhooks
    description: >-
      Manage outbound webhook subscriptions for Fintoro API. This section covers
      subscription CRUD, manual secret rotation, and the delivery payload
      contract for event-driven integrations. The delivery contract, signature
      verification, retry behavior, and full event catalog are documented in the
      [Webhooks guide](/en/webhooks).
  - name: Warehouses
    description: >-
      CRUD operations for warehouses, including inbound and outbound numbering
      series. Create, update, and delete operations can emit
      `warehouses.created`, `warehouses.updated`, and `warehouses.deleted`
      webhook events.
  - name: Warehouse Inbound Receipts
    description: >-
      CRUD operations for warehouse inbound receipts, including warehouse
      detail, supplier snapshot, receipt items, and `pdfDownloadUrl`. Create,
      update, and delete operations can emit
      `warehouse-inbound-receipts.created`,
      `warehouse-inbound-receipts.updated`, and
      `warehouse-inbound-receipts.deleted` webhook events.
  - name: Warehouse Outbound Receipts
    description: >-
      CRUD operations for warehouse outbound receipts, including warehouse
      detail, client snapshot, receipt items, and `pdfDownloadUrl`. Create and
      update use the same stock-availability validation as the web. Create,
      update, and delete operations can emit
      `warehouse-outbound-receipts.created`,
      `warehouse-outbound-receipts.updated`, and
      `warehouse-outbound-receipts.deleted` webhook events.
  - name: Price List Items
    description: >-
      CRUD operations for price list and warehouse items. These endpoints return
      the unit as a nested object, support filtering by name, EAN, warehouse
      code, price, and stock, and expose the same business contract that Fintoro
      uses for warehouse tracking, EANs, and purchase prices. Create, update,
      and delete operations can emit `price-list-items.created`,
      `price-list-items.updated`, and `price-list-items.deleted` webhook events.
      Stock changes caused by warehouse inbound and outbound receipts can emit
      the `price-list-items.stock-updated` webhook event.
  - name: Document Payments
    description: >-
      Payment records for public documents. This section covers listing payments
      of one document, creating a new payment, showing one payment, and deleting
      it. Supported document types are `invoice`, `proforma`, `credit-note`,
      `received-invoice`, and `received-receipt`. Create and delete operations
      can emit `document-payments.created` and `document-payments.deleted`
      webhook events. When a newly recorded payment makes a supported document
      fully paid, Fintoro can also emit the matching `*.paid` event for that
      document resource.
  - name: Document Emails
    description: >-
      Send supported public documents by email. The endpoint uses a single
      contract around `documentType` + `documentId`, validates document
      ownership, and supports `invoice`, `proforma`, `order`, `credit-note`, and
      `quotation`.
  - name: Invoices
    description: >-
      CRUD operations for invoices. Create, update, and delete operations can
      emit `invoices.created`, `invoices.updated`, and `invoices.deleted`
      webhook events. When a recorded payment makes the invoice fully paid,
      Fintoro can also emit `invoices.paid`.
  - name: Credit Notes
    description: >-
      CRUD operations for credit notes. The contract uses camelCase payloads, a
      full `PUT` update flow, and an explicit link to the original invoice
      through `invoiceId`. The credit-note client is always derived from the
      selected source invoice; `clientId` is not part of the request contract,
      and inline client resolution or create behavior is not supported here.
      Create, update, and delete operations can emit `credit-notes.created`,
      `credit-notes.updated`, and `credit-notes.deleted` webhook events. When a
      recorded payment makes the credit note fully paid, Fintoro can also emit
      `credit-notes.paid`.
  - name: Proformas
    description: >-
      CRUD operations for proformas. The contract follows the same philosophy as
      the public invoice API: camelCase payloads, deterministic client
      resolve/create behavior, create-like defaults, and a full `PUT` update
      flow with no patch fallback to the previous persisted document state.
      Create, update, and delete operations can emit `proformas.created`,
      `proformas.updated`, `proformas.deleted`, and, when a recorded payment
      makes the document fully paid, `proformas.paid`.
  - name: Orders
    description: >-
      CRUD operations for orders. The contract uses camelCase payloads,
      deterministic client resolve/create behavior, create-like defaults, and a
      full `PUT` update flow with no patch fallback to the previous persisted
      document state. Create, update, and delete operations can emit
      `orders.created`, `orders.updated`, and `orders.deleted` webhook events.
  - name: Quotations
    description: >-
      CRUD operations for quotations. The contract uses camelCase payloads,
      deterministic client resolve/create behavior, create-like defaults, and a
      full `PUT` update flow with no patch fallback to the previous persisted
      document state. Create, update, and delete operations can emit
      `quotations.created`, `quotations.updated`, and `quotations.deleted`
      webhook events.
paths:
  /orders:
    get:
      tags:
        - Orders
      summary: List orders
      description: >-
        Returns a paginated list of orders in a lightweight preview shape. Use
        this endpoint for lists, synchronization, and quick overview use cases;
        use the order detail endpoint for the full document.
      operationId: listOrders
      parameters:
        - in: query
          name: number
          required: false
          description: >-
            Filter by document number prefix. The backend uses prefix matching,
            not full-text or contains search.
          schema:
            type: string
          example: 2026
        - in: query
          name: clientId
          required: false
          description: Filter by client.
          schema:
            type: integer
          example: 101
        - in: query
          name: issueDateFrom
          required: false
          description: Issue date from.
          schema:
            type: string
            format: date
          example: '2026-02-01'
        - in: query
          name: issueDateTo
          required: false
          description: Issue date to.
          schema:
            type: string
            format: date
          example: '2026-02-28'
        - in: query
          name: totalFrom
          required: false
          description: Minimum total amount excluding VAT after discounts.
          schema:
            type: number
            format: float
          example: 100
        - in: query
          name: totalTo
          required: false
          description: Maximum total amount excluding VAT after discounts.
          schema:
            type: number
            format: float
          example: 1000
        - in: query
          name: withoutInvoice
          required: false
          description: >-
            When `true`, only returns orders that do not yet have a linked final
            invoice.
          schema:
            type: boolean
          example: true
        - in: query
          name: withoutProforma
          required: false
          description: >-
            When `true`, only returns orders that do not yet have a linked
            proforma.
          schema:
            type: boolean
          example: true
        - in: query
          name: sortBy
          required: false
          description: Sort field.
          schema:
            type: string
            enum:
              - number
              - issueDate
              - total
              - totalWithVat
            default: issueDate
          example: issueDate
        - in: query
          name: sortDirection
          required: false
          description: Sort direction.
          schema:
            type: string
            enum:
              - asc
              - desc
            default: desc
          example: desc
        - in: query
          name: perPage
          required: false
          description: Number of results per page.
          schema:
            type: integer
            minimum: 1
            maximum: 500
            default: 10
          example: 10
        - in: query
          name: page
          required: false
          description: Page number.
          schema:
            type: integer
            minimum: 1
            default: 1
          example: 2
      responses:
        '200':
          description: Paginated order list in preview shape.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    description: Order preview objects for the current page.
                    type: array
                    items:
                      $ref: '#/components/schemas/OrderPreview'
                  paginator:
                    $ref: '#/components/schemas/Paginator'
                    description: Pagination metadata for the current result.
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '500':
          $ref: '#/components/responses/InternalServerError'
        '503':
          $ref: '#/components/responses/ServiceUnavailable'
components:
  headers:
    XRequestId:
      description: >-
        Unique request identifier used for tracing, audit logs, and support
        diagnostics.
      schema:
        type: string
        example: req_public_api_01
    ContentLanguage:
      description: Language selected for the request based on `Accept-Language`.
      schema:
        type: string
        example: en
  schemas:
    OrderPreview:
      description: >-
        Simplified order preview object returned by the list endpoint. It does
        not include line items, but it does include the full historical client
        snapshot in `client`; use the order detail endpoint for the complete
        document.
      type: object
      properties:
        id:
          description: Internal order ID in Fintoro.
          type: integer
          example: 501
        uuid:
          description: Stable UUID of the order.
          type: string
          example: 6b1b8c9e-66e6-4fb5-b2db-6d7c7f0f8f19
        type:
          description: Document type.
          type: string
          example: order
        number:
          description: Order number.
          type: string
          example: '20260001'
        clientId:
          description: Live ID of the client linked to the order.
          type: integer
          example: 101
        client:
          $ref: '#/components/schemas/InvoicePreviewClient'
          description: >-
            Historical client snapshot stored directly on the order without the
            live client ID. The live ID is available separately in `clientId`.
        issueDate:
          description: Order issue date.
          type: string
          format: date
          example: '2026-03-03'
        currency:
          $ref: '#/components/schemas/Currency'
          description: Order currency as a nested object.
        total:
          description: Total amount excluding VAT after discounts.
          type: number
          format: float
          example: 200
        totalWithVat:
          description: Total amount including VAT after discounts.
          type: number
          format: float
          example: 240
        hasVat:
          description: Indicates whether the order contains any VAT-bearing items.
          type: boolean
          example: true
    Paginator:
      description: Pagination metadata returned by paginated list endpoints.
      type: object
      properties:
        currentPage:
          description: Current page number.
          type: integer
          example: 2
        perPage:
          description: Number of results per page.
          type: integer
          example: 10
        totalPages:
          description: Total number of available pages.
          type: integer
          example: 5
        totalResults:
          description: Total number of matching records across all pages.
          type: integer
          example: 42
        currentFrom:
          description: Ordinal number of the first record on the current page.
          type: integer
          example: 11
        currentTo:
          description: Ordinal number of the last record on the current page.
          type: integer
          example: 20
        firstPageUrl:
          description: URL of the first page.
          type: string
          example: https://app.fintoro.sk/api/public/v1/invoices?page=1
        lastPageUrl:
          description: URL of the last page.
          type: string
          example: https://app.fintoro.sk/api/public/v1/invoices?page=5
        nextPageUrl:
          description: URL of the next page or `null` when there is no next page.
          type:
            - string
            - 'null'
          example: https://app.fintoro.sk/api/public/v1/invoices?page=3
        previousPageUrl:
          description: URL of the previous page or `null` when there is no previous page.
          type:
            - string
            - 'null'
          example: https://app.fintoro.sk/api/public/v1/invoices?page=1
        links:
          description: >-
            Full list of paginator links in the same order as returned by the
            backend.
          type: array
          items:
            $ref: '#/components/schemas/PaginatorLink'
    InvoicePreviewClient:
      description: >-
        Historical client snapshot embedded directly in a document preview
        response. The live client ID is exposed separately through `clientId`.
      allOf:
        - $ref: '#/components/schemas/ClientSnapshot'
    Currency:
      description: Currency available in Fintoro API lookup endpoints.
      type: object
      properties:
        id:
          description: Stable currency ID used across the API.
          type: integer
          example: 1
        symbol:
          description: ISO or internal currency symbol.
          type: string
          example: EUR
        name:
          description: >-
            Localized currency label. When you send `Accept-Language`, the
            backend translates this system-owned label accordingly.
          type: string
          example: Euro
        mark:
          description: Short currency mark displayed in Fintoro.
          type: string
          example: €
    PaginatorLink:
      description: Single paginator link entry.
      type: object
      properties:
        url:
          description: Target page URL or `null` when the link is not available.
          type:
            - string
            - 'null'
          example: https://app.fintoro.sk/api/public/v1/invoices?page=2
        label:
          description: Human-readable link label.
          type: string
          example: '2'
        active:
          description: Indicates whether this link points to the current page.
          type: boolean
          example: false
    ClientSnapshot:
      description: >-
        Historical client snapshot stored directly on the document. This object
        represents the client data exactly as it existed when the document was
        issued or last re-saved. If the client changes later, for example the
        name or billing address, the document keeps this historical value for
        auditability and long-term data persistence. Example: a document issued
        to `Main Street 1, Bratislava` remains historically correct even if the
        client profile now contains a different billing address.
      type: object
      properties:
        name:
          description: >-
            Person name or company name stored on the invoice at that moment in
            time.
          type: string
          example: Acme s.r.o.
        type:
          description: Client type stored on the invoice.
          type: string
          example: company
        subjectId:
          type:
            - string
            - 'null'
          description: >-
            Business ID of the client or company. For Slovak entities, you can
            typically also find this value through the [subject registry
            lookup](#operation/searchSubjects).
          example: '12345678'
        taxId:
          description: Tax ID stored on the invoice when it was available.
          type:
            - string
            - 'null'
          example: '2020123456'
        vatId:
          description: VAT ID stored on the invoice when it was available.
          type:
            - string
            - 'null'
          example: SK2020123456
        isVatPayer:
          description: >-
            Indicates whether the client was marked as a VAT payer when this
            snapshot was stored.
          type: boolean
          example: true
        email:
          description: Client contact email stored on the invoice.
          type:
            - string
            - 'null'
          example: billing@acme.test
        street:
          description: Billing street and house number stored on the invoice.
          type:
            - string
            - 'null'
          example: Main Street 1
        city:
          description: Billing city stored on the invoice.
          type:
            - string
            - 'null'
          example: Bratislava
        zip:
          description: Billing ZIP or postal code stored on the invoice.
          type:
            - string
            - 'null'
          example: '81101'
        countryId:
          description: >-
            Country ID from the [country reference
            table](/en/reference-tables#countries).
          type:
            - integer
            - 'null'
          example: 703
        country:
          description: Billing country stored on the invoice as a nested object.
          anyOf:
            - $ref: '#/components/schemas/Country'
            - type: 'null'
        hasDeliveryAddress:
          description: >-
            Indicates whether this snapshot contains a separate delivery
            address.
          type: boolean
          example: true
        deliveryStreet:
          description: Delivery street and house number stored on the invoice.
          type:
            - string
            - 'null'
          example: Warehouse 9
        deliveryCity:
          description: Delivery city stored on the invoice.
          type:
            - string
            - 'null'
          example: Kosice
        deliveryZip:
          description: Delivery ZIP or postal code stored on the invoice.
          type:
            - string
            - 'null'
          example: '04001'
        deliveryCountryId:
          description: >-
            Country ID from the [country reference
            table](/en/reference-tables#countries).
          type:
            - integer
            - 'null'
          example: 703
        deliveryCountry:
          description: Delivery country stored on the invoice as a nested object.
          anyOf:
            - $ref: '#/components/schemas/Country'
            - type: 'null'
    Country:
      description: >-
        Country available in Fintoro API lookup endpoints and in nested objects
        where the country is returned directly in the response.
      type: object
      properties:
        id:
          description: Stable country ID used across the API.
          type: integer
          example: 703
        name:
          description: >-
            Localized country label. When you send `Accept-Language`, the
            backend translates this system-owned label accordingly.
          type: string
          example: Slovakia
        code:
          description: Two-letter ISO country code.
          type: string
          example: SK
        eu:
          description: Indicates whether the country is part of the European Union.
          type: boolean
          example: true
  responses:
    TooManyRequests:
      description: >-
        The company exceeded the Fintoro API rate limit. This 429 response
        includes the same `X-RateLimit-Limit` and `X-RateLimit-Remaining`
        headers as other throttled responses and additionally adds `Retry-After`
        and `X-RateLimit-Reset`. If you need a higher limit, contact
        info@fintoro.sk for custom enterprise terms.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
        X-RateLimit-Limit:
          description: >-
            Maximum number of requests allowed for the company in the current
            60-second window. This header is returned on all throttled
            responses, not only on 429.
          schema:
            type: integer
            example: 120
        X-RateLimit-Remaining:
          description: >-
            Number of requests remaining for the company in the current
            60-second window. This header is returned on all throttled
            responses, not only on 429.
          schema:
            type: integer
            example: 0
        Retry-After:
          description: >-
            Number of seconds after which you can safely retry the request. This
            header is sent only on 429 responses.
          schema:
            type: integer
            example: 60
        X-RateLimit-Reset:
          description: >-
            Unix timestamp when the current rate-limit window resets. This
            header is sent only on 429 responses.
          schema:
            type: integer
            example: 1774810800
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
                example: Too Many Attempts.
    InternalServerError:
      description: >-
        An unexpected internal error occurred. This should not happen in normal
        operation and is automatically reported to us.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
        Content-Language:
          $ref: '#/components/headers/ContentLanguage'
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
                example: Server Error
    ServiceUnavailable:
      description: >-
        The API is temporarily unavailable during scheduled maintenance. We
        announce planned downtime at least 24 hours in advance.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
        Content-Language:
          $ref: '#/components/headers/ContentLanguage'
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
                example: Service Unavailable
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: Bearer token created for a specific company in Integrations → API.

````