Endpoints
GET/api/partner/v1/me
The key's partner, its limits and the key itself.
Useful to check the connection and how many invites still fit in the last 24 hours.
Example
curl https://rioko.online/api/partner/v1/me \
-H "Authorization: Bearer rkp_live_3f9c…"
Response · 200
{
"partner": { "id": "exemplo", "name": "Exemplo Lda", "status": "active" },
"landing_url": "https://rioko.online/pt/p/exemplo",
"limits": {
"invites_per_request": 50,
"invites_per_24h": 200,
"invites_left_24h": 187,
"page_max": 100
},
"key": { "label": "Plataforma produção", "expires_at": "2027-09-17T10:00:00.000Z" }
}
Possible errors
missing_keyinvalid_keypartner_inactivemethod_not_allowed
POST/api/partner/v1/invites
Invite clients by email.
Each invite is an email with a unique link (valid for 30 days, single use) to the partner's page on Rioko, where the client signs up or signs in, accepts the terms and chooses whether to give the partner access.
If the client accepts from a verified email matching the invite, they are confirmed at once. If they accept from another email, they are pending and the partner confirms them in the portal.
With send_email set to false Rioko sends no email: the response carries invite_url and your platform delivers it. The invite still counts toward the limits.
invite_url is returned only in the response that creates the invite. A repeated request with the same external_ref and email answers exists, with no link and no new email.
An address that is already another partner's client on Rioko answers sent like any other, but receives no email: no API response reveals who already uses Rioko.
Parameters
| Field | Type | Required | Rules |
|---|
| invites | array | yes | 1 to 50 items. |
| invites[].email | string | yes | An email address. Stored lowercased. |
| invites[].external_ref | string | no | The client's id in your platform, up to 128 characters. Unique per partner among links that have not ended. |
| send_email | boolean | no | Defaults to true. |
Example
curl -X POST https://rioko.online/api/partner/v1/invites \
-H "Authorization: Bearer rkp_live_3f9c…" \
-H "Content-Type: application/json" \
-d @invites.json
Request
{
"invites": [
{ "email": "[email protected]", "external_ref": "acad_1042" },
{ "email": "[email protected]", "external_ref": "acad_1043" }
],
"send_email": true
}
Response · 201 when at least one invite was created, 200 otherwise
{
"results": [
{
"email": "[email protected]",
"external_ref": "acad_1042",
"status": "sent",
"id": "6f1c2d0e-8a4b-4f3e-9b8e-2c1d5e7a9b10",
"invite_url": "https://rioko.online/pt/p/exemplo/exemplo-3fa91c0e5b7d2a8f4c6e1b09",
"expires_at": "2026-10-17T10:00:00.000Z"
},
{
"email": "[email protected]",
"external_ref": "acad_1043",
"status": "exists",
"id": "9b2e7a4c-1d3f-4e5a-8b6c-0d9e2f1a3b4c"
}
],
"invites_left_24h": 186
}
Possible errors
invalid_requesttoo_many_invitesmissing_keyinvalid_keypartner_inactive
GET/api/partner/v1/invites
The invites sent, newest first.
Never returns tokens or links. status is open, expired, accepted or revoked.
Parameters
| Parameter | Type | Required | Rules |
|---|
| status | string | no | open, expired, accepted or revoked. |
| limit | integer | no | 1 to 100, default 50. |
| cursor | string | no | The previous page's next_cursor. |
Example
curl "https://rioko.online/api/partner/v1/invites?status=open&limit=50" \
-H "Authorization: Bearer rkp_live_3f9c…"
Response · 200
{
"data": [
{
"id": "6f1c2d0e-8a4b-4f3e-9b8e-2c1d5e7a9b10",
"external_ref": "acad_1042",
"email": "[email protected]",
"status": "open",
"sent_at": "2026-09-17T10:00:00.000Z",
"expires_at": "2026-10-17T10:00:00.000Z",
"accepted_at": null,
"resends": 0
}
],
"next_cursor": null
}
Possible errors
invalid_cursormissing_keyinvalid_keypartner_inactive
DELETE/api/partner/v1/invites/{id}
Revoke an open invite.
The link in the email stops working. Only the partner's own invites that are still open can be revoked.
Example
curl -X DELETE https://rioko.online/api/partner/v1/invites/6f1c2d0e-8a4b-4f3e-9b8e-2c1d5e7a9b10 \
-H "Authorization: Bearer rkp_live_3f9c…"
Response · 200
{ "id": "6f1c2d0e-8a4b-4f3e-9b8e-2c1d5e7a9b10", "status": "revoked" }
Possible errors
not_foundmissing_keyinvalid_keypartner_inactive
GET/api/partner/v1/clients
The partner's clients and where each one stands.
Ordered by updated_at, then id, oldest first, which keeps polling with updated_since stable.
updated_at changes with anything that happens to the link: sign-up, confirmation or rejection, access granted or withdrawn, a managed account handed over, the link ending.
What each client carries depends on where it stands (see States and consent): a pending client shows only company name, VAT number, email and date; without access, only name, code and mode; with access, also its integrations and last document; an ended link, only the end.
state, for clients with access, is live, connecting, signed_up, needs_attention or subscription_inactive.
On each integration, subscription says how the client's Rioko subscription for it stands: active (paid), trial (in a trial period), inactive (ended or suspended: that integration does not invoice) or none (never subscribed). subscription_ending is true when it will not renew.
Parameters
| Parameter | Type | Required | Rules |
|---|
| updated_since | ISO 8601 date | no | Only clients whose updated_at is strictly later. |
| status | string | no | active or ended. |
| validation | string | no | pending or confirmed. |
| limit | integer | no | 1 to 100, default 50. |
| cursor | string | no | The previous page's next_cursor, as received. |
Example
curl "https://rioko.online/api/partner/v1/clients?updated_since=2026-09-18T00:00:00.000Z" \
-H "Authorization: Bearer rkp_live_3f9c…"
Response · 200
{
"data": [
{
"id": "0a7d…",
"external_ref": "acad_1042",
"updated_at": "2026-09-18T09:12:44.000Z",
"status": "active",
"validation": "pending",
"company_name": "Academia Norte, Lda",
"nif": "516000000",
"email": "[email protected]",
"claimed_at": "2026-09-18T09:12:44.000Z"
},
{
"id": "4c1e…",
"external_ref": "acad_0981",
"updated_at": "2026-09-19T15:02:10.000Z",
"status": "active",
"validation": "confirmed",
"client_code": "RIO-7K2M9Q",
"name": "Estúdio Sul",
"mode": "referred",
"since": "2026-09-02T11:40:00.000Z",
"access": false
},
{
"id": "8e33…",
"external_ref": "acad_0770",
"updated_at": "2026-09-20T08:30:00.000Z",
"status": "active",
"validation": "confirmed",
"client_code": "RIO-3H8TQ1",
"name": "Clube Oeste",
"mode": "referred",
"since": "2026-08-21T10:00:00.000Z",
"access": true,
"state": "live",
"connections": [
{ "source": "stripe", "destination": "moloni", "status": "active", "subscription": "active", "subscription_ending": false }
],
"last_document_at": "2026-09-20T08:29:51.000Z"
},
{
"id": "b51f…",
"external_ref": "acad_0655",
"updated_at": "2026-09-21T17:45:00.000Z",
"status": "ended",
"end_reason": "client_left",
"ended_at": "2026-09-21T17:45:00.000Z"
}
],
"next_cursor": "MjAyNi0wOS0yMVQxNzo0NTowMC4wMDBafGI1MWY"
}
Possible errors
invalid_cursormissing_keyinvalid_keypartner_inactive
GET/api/partner/v1/clients/{client_code}
One client, by its Rioko code (RIO-…).
Only confirmed clients have a visible code. Another partner's code answers 404, like one that does not exist.
Example
curl https://rioko.online/api/partner/v1/clients/RIO-3H8TQ1 \
-H "Authorization: Bearer rkp_live_3f9c…"
Response · 200: the same object as in /clients
{
"id": "8e33…",
"client_code": "RIO-3H8TQ1",
"access": true,
"state": "live"
}
Possible errors
not_foundmissing_keyinvalid_keypartner_inactive
GET/api/partner/v1/clients/{client_code}/documents
What happened to a client's documents after they were issued.
So the platform can show the merchant what changed without asking the invoicing software.
It does NOT carry the document number or its link: those live in the invoicing software, and were already returned in the response to the request that issued each document. This is what changed SINCE: a draft closed by hand, a receipt, a credit note.
`state` is the furthest point the document reached: `issued`, `held`, `finalized`, `settled` or `credited`.
`updated_since` returns only what moved since that date, which is how you poll without re-reading everything. The event history is pruned at 90 days (365 for the ones that are evidence), so an old document lists with less of its story.
Needs access granted by the client. Without it, 404, like a code that does not exist.
Example
curl "https://rioko.online/api/partner/v1/clients/RIO-3H8TQ1/documents?updated_since=2026-09-01T00:00:00Z&limit=50" -H "Authorization: Bearer rkp_live_3f9c…"
Response · 200: one page of documents, oldest first
{
"client_code": "RIO-3H8TQ1",
"external_ref": "acad_42",
"data": [
{
"external_id": "mf_acad42_1042",
"document_id": "1025042934",
"state": "settled",
"held": null,
"issued_at": "2026-09-24T09:12:00Z",
"finalized_at": "2026-09-24T09:12:03Z",
"settled_at": "2026-09-30T10:04:00Z",
"credited_at": null,
"updated_at": "2026-09-30T10:04:00Z"
}
],
"next_cursor": null
}
Possible errors
not_foundinvalid_cursormissing_keyinvalid_keypartner_inactive