Docs

Quickstart

Build your first integration

Set up a sandbox API key, make your first request, and follow the REST and MCP workflows.

Production and sandbox

Organization API keys are bound to one environment. Sandbox keys use the operations marked “Production and sandbox” in the API reference against isolated test data. Production-only operations and MCP remain unavailable in sandbox. Credentials are rejected outside their assigned environment.

Make your first authenticated request

Start with an isolated sandbox organization and a sandbox API key.

Open the developer console

Open /consola from Exac, select Test, and open API keys for your current workspace.

Create a sandbox API key

Create a key for Test and copy it once. Exac prepares the isolated environment automatically.

Verify the sandbox organization

Call GET /v1/organization with the sandbox key against the sandbox server shown in OpenAPI.

Run a Test workflow

Create a contact and CFDI draft, then create, retrieve, and cancel a test stamp. Sandbox artifacts are not submitted to SAT and have no fiscal validity.

curl "https://grateful-squid-667.convex.site/v1/organization" \  --header "Authorization: Bearer <EXAC_API_KEY>"

Request, response, and retry conventions

Send Authorization: Bearer <credential> on every API request and Content-Type: application/json when sending a JSON body. JSON successes use { data }; paginated responses also include pagination. Failures use { error: { code, message, status, details? } }. Branch on error.code, not the human message, and retain the Request-Id response header for diagnostics. File downloads return bytes instead of a JSON envelope.

Canonical workflows

Use the same domain intent through REST or MCP. These examples are validated against the runtime contracts; replace example identifiers and credentials with values from your organization.