Fortnox APIFortnox API — a practical guide from a team running it in production
The Fortnox API (api.fortnox.se) is Fortnox's REST interface for invoices, customers, bookkeeping, and supplier invoices. This guide covers how to get started, which limits you need to plan for, and where the common errors come from — written by the team behind Nordsynk, who run a Fortnox integration handling thousands of calls a day.
This page complements Fortnox's own developer documentation at api.fortnox.se. It doesn't replace it — every section links back to the original source.
Fortnox API
Does Fortnox have an API?
Yes, Fortnox has a REST API (api.fortnox.se) with OAuth 2.0; integrations are registered in the Fortnox Developer Portal and activated by the customer in their own Fortnox portal. The API is organized around resource URLs under /3/ — invoices, customers, supplier invoices, bookkeeping, payroll, and more — and responds in JSON by default.
The surface is large: 233 paths across 377 operations, grouped into named scopes that control what a given integration can read and write. A customer only sees the data tied to the scopes the integration requested at activation, not the entire Fortnox API automatically.
Getting started
Building against the Fortnox API takes five steps before you can fetch your first invoice. Fortnox's own documentation covers every part in detail — here's the order in short.
- 1
Create an account in the Fortnox Developer Portal
You need a Fortnox user with a developer license, which new accounts get automatically. The portal is reached via Menu → Developer Portal in your Fortnox login.
- 2
Register an integration
Name the integration and choose which scopes it should request access to, for example bookkeeping, invoices, or supplier invoices. This is also where you set your redirect URI, the page the customer is sent to after approving.
- 3
Implement the OAuth 2.0 flow
Send the user to the Fortnox login, receive the authorization code — valid for ten minutes — and exchange it for an access token and a refresh token using your Client ID and Client Secret as credentials.
- 4
Let the customer activate the integration
The customer approves the integration in their own Fortnox portal or via the Fortnox Integrations marketplace. Activation locks in which scopes you can actually use against that specific company.
- 5
Make your first request
Send a GET request to a resource, for example /3/invoices, with the access token as a Bearer token in the Authorization header. If that works, you're up and running.
Rate limits and pagination
The Fortnox API allows 25 calls per 5 seconds per access token, which works out to 300 calls per minute. Fortnox's own OpenAPI specification states this exactly, and Nordsynk's resilience middleware is configured with the same limits as its defaults — 25 per 5 seconds and 300 per minute — so we never quote a number we can't verify in code.
The limit is a sliding window: overuse it during one period and throttling continues until the average drops back to 25 calls per 5 seconds. Fortnox responds with HTTP 429 when the limit is hit, and a resilient client waits and retries instead of just giving up.
Pagination uses the page query parameter, for example /3/invoices?page=3. Many classic list response models include MetaInformation with @CurrentPage, @TotalPages, and @TotalResources, but this is resource dependent: inspect the response model and read those exact fields only where they are present.
The full breakdown of rate limits and pagination →Authentication: OAuth 2.0, no API keys
The Fortnox API uses OAuth 2.0. Human connections exchange an authorization code for an access token and refresh token; Fortnox also documents a service-account client-credentials grant for pre-authorized, tenant-scoped access. Both use the integration's Client ID and Client Secret at the token endpoint.
Every call to a resource sends the access token as a Bearer token in the Authorization header. The scopes you requested when the integration was created determine which resources the token can actually reach, so a 403 response usually means a scope or license problem rather than a mistake in the request itself.
The full OAuth flow, step by step →Code example
A minimal GET request for invoices via curl:
curl https://api.fortnox.se/3/invoices \
-H "Authorization: Bearer $ACCESS_TOKEN"The response wraps the list in an Invoices array. Write operations, more languages, and complete examples in Python and TypeScript are on the examples page.
More code examples in Python and TypeScript →Common errors
Most Fortnox API debugging sessions land on one of these four.
401 Unauthorized
The access token is missing, malformed, or expired. Tokens are only valid for one hour, so an integration that doesn't refresh automatically with its refresh token hits this regularly.
403 Forbidden
Usually a scope, license, or permission problem — for example error_missing_app_license when the company lacks a license for the integration, or a scope that was never requested at activation.
429 Too Many Requests
The rate limit of 25 calls per 5 seconds has been hit. Wait and retry with backoff — retrying immediately only extends the throttling.
400 Bad Request
Field validation failed. Fortnox responds with a numeric ErrorInformation object (Code and Message), for example code 2000106 when a field must be alphanumeric but contains other characters.
Skip the glue code: talk to Fortnox through MCP instead
Everything above — the OAuth flow, token refresh, rate limits, pagination, and error normalization — is infrastructure you need to build and maintain before you write a single line of business logic. In practice it's often a sprint of glue code for a team that just wants to ask which invoices are unpaid this month.
Nordsynk exposes the entire Fortnox surface — 233 paths, 377 operations — through a single MCP endpoint. Paste https://mcp.nordsynk.se/mcp into Claude, ChatGPT, or Cursor and Nordsynk handles OAuth, token refresh, and rate limits for you; you ask the question in plain language instead of writing the client.
Frequently asked questions about the Fortnox API
Does Fortnox have an API?
Yes, Fortnox has a REST API at api.fortnox.se with OAuth 2.0. You register an integration in the Fortnox Developer Portal, but each customer has to activate it in their own Fortnox portal before it can be used against their company data.
How do I get started with the Fortnox API?
Create an account in the Fortnox Developer Portal, register an integration with the right scopes, and implement the OAuth 2.0 flow to obtain an access token. The customer then activates the integration in their own Fortnox portal before you can call the API against their company data.
What are the Fortnox API rate limits?
The Fortnox API allows 25 calls per 5 seconds per access token, which works out to 300 calls per minute. Exceed the limit and the API responds with HTTP 429 until your call rate has dropped back down.
How do I authenticate with the Fortnox API?
The Fortnox API uses OAuth 2.0. Use the authorization-code grant for a human/user connection, or the client-credentials grant for a pre-authorized service account. Send the resulting access token as a Bearer token in the Authorization header.
Read more
Ready to stop building infrastructure and start asking questions?
Activate Nordsynk in the Fortnox portal. Under a minute.