List the authenticated customer's invoices

Returns invoices owned by the authenticated customer, reverse-chronological by `invoice_date`. Use the same `starting_after`/`ending_before` cursor pattern as subscriptions. --- **Related endpoints** - `POST /customer-portal/sessions` — Create a customer-portal session - `GET /customer-portal/customer` — Retrieve the authenticated customer - `GET /customer-portal/subscriptions` — List the authenticated customer's subscriptions - `GET /customer-portal/subscriptions/{id}` — Retrieve a subscription - `POST /customer-portal/subscriptions/{id}/cancel` — Cancel a subscription - `GET /customer-portal/invoices/{id}` — Retrieve an invoice - `GET /customer-portal/mandates` — List the authenticated customer's Direct Debit mandates - `POST /customer-portal/mandates/{id}/re-authorize` — Re-authorise a Direct Debit mandate with new bank details **Common errors** - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. **Pagination** Offset-based with `limit` (default 25, max 100) and `offset`. The response `pagination` block includes `total` and `hasMore`. See [the pagination guide](/docs/fundamentals/pagination) for SDK auto-paging helpers.

GET
/customer-portal/invoices

Returns invoices owned by the authenticated customer, reverse-chronological by invoice_date. Use the same starting_after/ending_before cursor pattern as subscriptions.


Related endpoints

  • POST /customer-portal/sessions — Create a customer-portal session
  • GET /customer-portal/customer — Retrieve the authenticated customer
  • GET /customer-portal/subscriptions — List the authenticated customer's subscriptions
  • GET /customer-portal/subscriptions/{id} — Retrieve a subscription
  • POST /customer-portal/subscriptions/{id}/cancel — Cancel a subscription
  • GET /customer-portal/invoices/{id} — Retrieve an invoice
  • GET /customer-portal/mandates — List the authenticated customer's Direct Debit mandates
  • POST /customer-portal/mandates/{id}/re-authorize — Re-authorise a Direct Debit mandate with new bank details

Common errors

  • 401 authentication_error — missing, invalid, expired, or revoked credential. Codes: authentication_failed, invalid_api_key, expired_api_key, api_key_revoked, session_invalid, merchant_required. Carries a WWW-Authenticate: Bearer challenge.

Pagination

Offset-based with limit (default 25, max 100) and offset. The response pagination block includes total and hasMore. See the pagination guide for SDK auto-paging helpers.

x-api-key<token>

Your RevKeen merchant API key. Create and manage keys in Dashboard → Settings → Developer. Use rk_sandbox_* for staging/test and rk_live_* for production. The same key may be sent as Authorization: Bearer <key> if that suits your HTTP client better. A missing, invalid, expired, or revoked key returns 401 with a WWW-Authenticate: Bearer challenge; a valid key without the required scope returns 403.

In: header

Query Parameters

limit?integer

Maximum number of results to return (1-100, default 20).

Range1 <= value <= 100
Default20
starting_after?string

Cursor — return results created before the row with this ID.

Formatuuid
ending_before?string

Cursor — return results created after the row with this ID.

Formatuuid

Response Body

application/json

application/json

application/json

Stuck on an error response? Ask the RevKeen assistant to explain it.
curl "https://api.revkeen.com/v2/customer-portal/invoices" \
  -H "x-api-key: $REVKEEN_API_KEY"
{  "object": "list",  "data": [    {      "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",      "object": "invoice",      "invoice_number": "string",      "status": "string",      "currency": "string",      "subtotal": 0,      "tax_amount": 0,      "discount_amount": 0,      "total": 0,      "amount_paid": 0,      "amount_due": 0,      "invoice_date": "2019-08-24T14:15:22Z",      "due_date": "2019-08-24T14:15:22Z",      "paid_at": "2019-08-24T14:15:22Z",      "created_at": "2019-08-24T14:15:22Z"    }  ],  "has_more": true,  "url": "string"}

Retrieve an invoice GET

Returns an invoice owned by the authenticated customer. --- **Related endpoints** - `POST /customer-portal/sessions` — Create a customer-portal session - `GET /customer-portal/customer` — Retrieve the authenticated customer - `GET /customer-portal/subscriptions` — List the authenticated customer's subscriptions - `GET /customer-portal/subscriptions/{id}` — Retrieve a subscription - `POST /customer-portal/subscriptions/{id}/cancel` — Cancel a subscription - `GET /customer-portal/invoices` — List the authenticated customer's invoices - `GET /customer-portal/mandates` — List the authenticated customer's Direct Debit mandates - `POST /customer-portal/mandates/{id}/re-authorize` — Re-authorise a Direct Debit mandate with new bank details **Common errors** - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key.

Cancel a Direct Debit mandate POST

Cancels the mandate for future collections only. Requires portal DD self-service. Bank changes affect future only (per approved V13 mockup). --- **Related endpoints** - `POST /customer-portal/sessions` — Create a customer-portal session - `GET /customer-portal/customer` — Retrieve the authenticated customer - `GET /customer-portal/subscriptions` — List the authenticated customer's subscriptions - `GET /customer-portal/subscriptions/{id}` — Retrieve a subscription - `POST /customer-portal/subscriptions/{id}/cancel` — Cancel a subscription - `GET /customer-portal/invoices` — List the authenticated customer's invoices - `GET /customer-portal/invoices/{id}` — Retrieve an invoice - `GET /customer-portal/mandates` — List the authenticated customer's Direct Debit mandates **Common errors** - `400 invalid_request` — malformed payload or failed validation. - `403 authorization_error` — the caller is identified but the action is denied. Codes include `insufficient_permissions`, `ip_not_allowed`, `merchant_mismatch`, and `origin_not_allowed`. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key. **Idempotency** Pass an `Idempotency-Key` header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see [the idempotency guide](/docs/fundamentals/idempotency).