Skip to main content
POST
Validate a CFDI

Authorizations

Authorization
string
header
required

API key: Authorization: Bearer sk_test_... or sk_live_....

Headers

Invoice-Version
string

Pin a dated API release (Stripe-style). Omit to use the current version. An unknown value returns 400 request.invalid_version. Echoed back on every response.

Example:

"2026-07-10"

Invoice-Account
string

Connect: act on behalf of one of your connected accounts (its acct_…/org_… id). Omit to act as your own organization. Not honored on /v1/api_keys.

Example:

"org_2P9connectedacct"

Idempotency-Key
string

Safely retry any POST. The first response is stored for 24h and replayed byte-for-byte for identical retries (the replay adds an idempotent-replayed: true header). Reusing the key with a different body is 409 idempotency.key_reuse; an in-flight duplicate is 409 idempotency.key_processing. This makes retrying a 502/429 safe — no duplicate stamp.

Example:

"a1b2c3d4-e5f6-4789-8abc-1234567890ab"

Body

application/json
xml_base64
string
required

Base64 of the CFDI XML to validate (Content-Type application/json).

Minimum string length: 1

Response

Default Response

object
enum<string>
required

Always "validation".

Available options:
validation
id
string
required

Validation record id.

valid
boolean
required

True when the CFDI passed all structural/SAT checks.

errors
object[]
required

The validation failures found (empty when valid).

summary
object
required

Parsed summary of the CFDI plus SAT status.

livemode
boolean
required

True if validated with a live-mode key.

created_at
string
required

Creation timestamp, ISO-8601 UTC.