Administration
GET /v1/subscription-package
Section titled “GET /v1/subscription-package”Request exampleNo request body
curl https://api.rieckflow.com/v1/subscription-package \ -H "Authorization: Bearer $RIECK_API_KEY"const svar = await rieck.request("GET", "/v1/subscription-package");{ "data": {}}200
packageKey, whether your terms were negotiated individually, validFrom, and any trial. ⚠️ Read-only: changing package cannot be done with an API key. The package gate applies to itself — only the advanced package includes api, so a key on a lower package gets 403 on every /v1 route including this one’s would-be upgrade path.application/jsonPossible errors 4
| HTTP | Code | Meaning |
|---|---|---|
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
GET /v1/mandates
Section titled “GET /v1/mandates”Request exampleNo request body
curl https://api.rieckflow.com/v1/mandates \ -H "Authorization: Bearer $RIECK_API_KEY"const svar = await rieck.request("GET", "/v1/mandates");{ "data": {}}200 The three yeses you give in advance so a case handler need not ask each time:
autoCollections (hand an overdue invoice to collection automatically), autoBailiff (file a payment order with the court fee on your card) and settlementMandate (how much may be written off on your behalf — both fields null means no mandate at all, not a milder default). ⚠️ autoCollections can be CHANGED with PUT /v1/reminder-settings; the other two cannot be set by a key.application/jsonPossible errors 4
| HTTP | Code | Meaning |
|---|---|---|
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
GET /v1/credit-limits
Section titled “GET /v1/credit-limits”Request exampleNo request body
curl https://api.rieckflow.com/v1/credit-limits \ -H "Authorization: Bearer $RIECK_API_KEY"const svar = await rieck.request("GET", "/v1/credit-limits");{ "data": {}}200 Your default limit and its append-only history. ⚠️ A limit applies LIVE: it gates new issuing only, but is measured against the exposure you have already accumulated — so lowering it can block a customer whose whole debt predates the change, without altering a single existing invoice.application/json
Possible errors 4
| HTTP | Code | Meaning |
|---|---|---|
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
GET /v1/customers/{customerId}/credit-limit
Section titled “GET /v1/customers/{customerId}/credit-limit”| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
customerId | path | string | Yes |
Request exampleNo request body
curl https://api.rieckflow.com/v1/customers/9b2f1c1e-…/credit-limit \ -H "Authorization: Bearer $RIECK_API_KEY"const svar = await rieck.request("GET", "/v1/customers/9b2f1c1e-…/credit-limit");{ "data": {}}200
limitOere (null = none, 0 = fully stopped — the difference is deliberate), source (own / organisation_default / none), the organisation default alongside, the current exposure broken down, and the history. Issuing over the limit fails with RI053; credit notes are never gated, and collections are not counted against it.application/jsonPossible errors 5
| HTTP | Code | Meaning |
|---|---|---|
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 404 | customer_not_found | The customer does not exist or belongs to another organisation. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
GET /v1/price-rules
Section titled “GET /v1/price-rules”| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
campaignId | query | string | No | Rules anchored to this campaign |
customerId | query | string | No | Rules anchored to this customer |
priceListId | query | string | No | Rules anchored to this price list |
limit | query | integer | No | Page size, 1-200 (default 50) |
cursor | query | string | No | Opaque cursor from meta.nextCursor |
Request exampleNo request body
curl https://api.rieckflow.com/v1/price-rules \ -H "Authorization: Bearer $RIECK_API_KEY"const svar = await rieck.request("GET", "/v1/price-rules");{ "data": [ {} ], "meta": { "nextCursor": null }}200 ⚠️ Returned in the ENGINE’s order, not alphabetically: a rule that can never win because a more specific one always beats it must be visible as such — and the cursor pages ON that order, so page 2 continues where the engine left off rather than restarting in date order. Give at most one anchor; none returns the unanchored rules. A rule targets one product OR a category, never both.application/json
Possible errors 5
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_cursor | The cursor is malformed, expired or belongs to another list shape. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
POST /v1/price-rules
Section titled “POST /v1/price-rules”Set id to update, omit it to create. Exactly one anchor (campaignId, customerId, priceListId). basis: FAST needs priceOere and forbids a percentage or surcharge; KOST/KATALOG need percentBasisPoints (basis points — 12.5 % is 1250) and forbid priceOere. noticeDays requires a validTo.
Request exampleNo request body
curl -X POST https://api.rieckflow.com/v1/price-rules \ -H "Authorization: Bearer $RIECK_API_KEY" \ -H "Idempotency-Key: order-2041"const svar = await rieck.request("POST", "/v1/price-rules");{ "data": {}}201 The saved rule. ⚠️ The price floor is checked HERE, not at invoicing: a rule that only fails on a document weeks later is a trap. If your floor is set to reject, you get 422
price_floor_breached with the NUMBER of products affected — never their cost prices.application/jsonPossible errors 7
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_idempotency_key | Idempotency-Key is missing or malformed. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 409 | idempotency_conflict | The same key was used with a different request. |
| 409 | idempotency_in_progress | The same operation is currently being processed. Retry later. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |
DELETE /v1/price-rules/{priceRuleId}
Section titled “DELETE /v1/price-rules/{priceRuleId}”Removes the rule outright. A rule that merely should not apply right now is deactivated in the portal instead — the difference matters when someone later asks why an invoice got the price it did.
| Parameter | In | Type | Required | Description |
|---|---|---|---|---|
priceRuleId | path | string | Yes |
Request exampleNo request body
curl -X DELETE https://api.rieckflow.com/v1/price-rules/9b2f1c1e-… \ -H "Authorization: Bearer $RIECK_API_KEY" \ -H "Idempotency-Key: order-2041"const svar = await rieck.request("DELETE", "/v1/price-rules/9b2f1c1e-…");204 No contentNo response body
Possible errors 7
| HTTP | Code | Meaning |
|---|---|---|
| 400 | invalid_idempotency_key | Idempotency-Key is missing or malformed. |
| 401 | invalid_api_key | The API key is missing, invalid, expired or revoked. |
| 403 | api_not_included | The organisation’s plan does not include API access. |
| 403 | insufficient_scope | The key does not have the required scope. |
| 409 | idempotency_conflict | The same key was used with a different request. |
| 409 | idempotency_in_progress | The same operation is currently being processed. Retry later. |
| 429 | rate_limited | The organisation’s rate budget is exhausted. |