Payments, credit notes, services & invoices

The money side, read-only: credit notes, payments received, services and subscriptions, a paid/unpaid summary, and invoices.

credit_notes_get

Who may call it: admin, reseller or accountant.

ParameterRequiredIn hashMeaning
uYes—Caller's username.
credit_note_idNoneverOne specific credit note by id. Takes priority over user_id if both are sent.
user_idNo1stRestrict to one customer's credit notes.

Hash parameter order: user_id only — credit_note_id is read by the handler but never enters the hash.

curl -X POST https://api.example.com/api/credit_notes_get \
  -d "u=admin" \
  -d "user_id=3031" \
  -d "hash=PLACEHOLDER_HASH"
<page>
  <credit_notes>
    <credit_note>
      <user_id>3031</user_id>
      <issue_date>2026-09-01</issue_date>
      <number>CN-2026-0007</number>
      <comment></comment>
      <price>10.00</price>
      <price_with_vat>12.00</price_with_vat>
      <pay_date></pay_date>
    </credit_note>
  </credit_notes>
</page>

Errors: Bad login (wrong account type), Credit note was not found (nothing matched — the same message whether you asked for one note or a list).

payments_get

Who may call it: any account type. A plain user always sees only their own payments.

ParameterRequiredIn hashMeaning
uYes—Caller's username.
s_user_idNo1stRestrict to one customer. A reseller naming their own id instead sees every customer they own.
s_from / s_tillNo2nd, 3rdUnix timestamps; default to today.
s_completedNo4th1/0.
s_paymenttypeNo5thExact match on the payment type.
s_currencyNo6thExact match on the currency code.

Hash parameter order: s_user_id, s_from, s_till, s_completed, s_paymenttype, s_currency.

curl -X POST https://api.example.com/api/payments_get \
  -d "u=admin" \
  -d "s_user_id=3031" \
  -d "hash=PLACEHOLDER_HASH"
<page>
  <pagename>Payments_list</pagename>
  <payments>
    <payment>
      <user>Demo Company</user>
      <transaction_id>...</transaction_id>
      <date>2026-09-20 11:02:00</date>
      <confirm_date>2026-09-20 11:02:05</confirm_date>
      <type>Bank</type>
      <amount>25.00</amount>
      <fee>0.00</fee>
      <currency>EUR</currency>
      <completed>Completed</completed>
      <comments_for_user></comments_for_user>
    </payment>
  </payments>
</page>

<pagename> is the literal, untranslated string Payments_list. An uncompleted payment shows <completed>No (reason)</completed> instead. Error (anonymous caller only): <page><status><error>Bad login</error></status></page> — note this one failure case is nested in <status>, unlike the success body above.

Also reachable as: /api/payments_list.

The Payments list — the same records payments_get returns.

services_get

The service catalogue (subscription-style products), not individual customer subscriptions — see subscriptions_get below for those.

Who may call it: admin, reseller, accountant or partner — not a plain user.

ParameterRequiredMeaning
uYesCaller's username. This method reads no other parameters, so the hash is SHA1(secret key) alone.
curl -X POST https://api.example.com/api/services_get \
  -d "u=admin" \
  -d "hash=PLACEHOLDER_HASH"
<page>
  <services>
    <service>
      <id>4</id>
      <name>Demo Voicemail Plan</name>
      <memo></memo>
      <type>...</type>
      <period>monthly</period>
      <price>2.00</price>
      <self_cost>0.00</self_cost>
      <currency>EUR</currency>
      <quantity>1</quantity>
    </service>
  </services>
</page>

Errors (nested in <status>): Access Denied, No Services found.

subscriptions_get

Which customers are subscribed to which service.

Who may call it: admin, reseller, accountant or partner — not a plain user (answers You are not authorized to manage Subscriptions).

ParameterRequiredMeaning
uYesCaller's username.
s_user_idNoRestrict to one customer.
service_idNoRestrict to one service.

Hash parameter order: deliberately empty, by design — this method is explicitly declared with no hash parameters at all in the code (not just "nothing matched"), so the hash is always SHA1(secret key) alone, whatever you send.

curl -X POST https://api.example.com/api/subscriptions_get \
  -d "u=admin" \
  -d "hash=PLACEHOLDER_HASH"
<page>
  <status>
    <subscriptions>
      <subscription>
        <id>9</id>
        <user>Demo Company</user>
        <device>SIP/1010</device>
        <service>Demo Voicemail Plan</service>
        <from>2026-09-01 00:00:00</from>
        <till></till>
        <memo></memo>
        <type>...</type>
        <price>2.00</price>
        <user_id>3031</user_id>
      </subscription>
    </subscriptions>
  </status>
</page>

Errors (same nesting): Access Denied, You are not authorized to manage Subscriptions, No Subscriptions found.

financial_statements_get

A paid/unpaid summary — count and total for invoices, credit notes and completed payments over a period, grouped by status.

Who may call it: any account type. A plain user always gets their own totals.

ParameterRequiredIn hashMeaning
uYes—Caller's username.
user_idNo1stRestrict to one customer, must be owned by the caller.
statusNo2ndpaid, unpaid or all (default).
date_from / date_tillNo3rd, 4thUnix timestamps; default to today through tomorrow.

Hash parameter order: user_id, status, date_from, date_till.

curl -X POST https://api.example.com/api/financial_statements_get \
  -d "u=admin" \
  -d "hash=PLACEHOLDER_HASH"
<page>
  <financial_statement currency="EUR">
    <statement type="invoices">
      <status>paid</status>
      <count>4</count>
      <price>120.00</price>
      <price_with_vat>144.00</price_with_vat>
    </statement>
    <statement type="payments">
      <status>paid</status>
      <count>3</count>
      <price>90.00</price>
      <price_with_vat>90.00</price_with_vat>
    </statement>
  </financial_statement>
</page>

Errors: Bad login, Dont_be_so_smart (user_id not owned by the caller).

Also reachable as: /api/financial_statements.

invoices_get

Warning

This method is the one exception to the response shape described on the reference index. A successful call does not return a <page> root at all — the document root is <Invoices> (capital I), and each invoice is <Invoice> (also capital), with attributes instead of child tags for some fields. A failed call still uses <page><error>...</error></page> as usual — only success looks different.

Who may call it: any account type. A plain user always gets their own invoices.

ParameterRequiredIn hashMeaning
uYes—Caller's username.
from / tillNoneverUnix timestamps for the invoice's issue date; left out, matches everything (the epoch). Not part of the hash — these are plain from/till, not the s_from/date_from names other methods use, so they don't hit the shared list.

Hash parameter order: none — a normal call hashes to SHA1(secret key) alone.

curl -X POST https://api.example.com/api/invoices_get \
  -d "u=admin" \
  -d "hash=PLACEHOLDER_HASH"
<Invoices from="2026-01-01" till="2026-09-24">
  <Invoice user_id="3031" agreementnumber="" clientid="" number="INV-2026-0044">
    <paid>1</paid>
    <Product>
      <Name>...</Name>
      <Quantity>1</Quantity>
      <Price>25.00</Price>
      <Discount>0.00</Discount>
      <Sum>25.00</Sum>
      <Date_added></Date_added>
      <Issue_date>2026-09-01</Issue_date>
      <Time>0</Time>
      <Service_id></Service_id>
      <Prefix></Prefix>
    </Product>
    <Total_time>0</Total_time>
  </Invoice>
</Invoices>

Errors: <page><error>User_Not_Found</error></page> (no caller) or <page><error>No_invoices_found</error></page> (nothing in range) — both literal, untranslated keys.

Also reachable as: /api/invoices.

The Invoices list — the same invoices invoices_get returns, as <Invoice> elements.

Check

Call payments_get for demo user 3031 and compare the totals against the Billing pages for the same customer in the product.