Skip to main content
GET
List all customers for an organization
Returns all customers belonging to an organization.
This endpoint takes no organizationId in the URL. Authenticate with either a Supabase Bearer session (send the X-Organization-Id: <org-id> header — the user must be a member of that organization) or an API key (the organization resolves automatically from the key; any X-Organization-Id header sent alongside an API key is ignored).

Authentication

Accepts either:
  • A Supabase Bearer session (Authorization: Bearer <token>) with the X-Organization-Id: <org-id> header — the authenticated user must be a member of that organization.
  • An API key (X-API-Key: sk_...) with the read:customers scope — the organization is resolved from the key itself.

Example Request

Example Response

Common Errors

400 Bad Request

Missing X-Organization-Id header on a session-authenticated request.

401 Unauthorized

Missing or invalid Bearer token / API key.

403 Forbidden

The authenticated user is not a member of the organization sent in X-Organization-Id, or the API key does not have the read:customers scope.

Authorizations

X-API-Key
string
header
required

API Key for authentication (format: sk_...)

Headers

X-Organization-Id
string

Required for Supabase session auth. Ignored when authenticating with an API key (the organization resolves from the key).

Response

id
string
required
Example:

"590ce6c56d04f840aa8438af"

organizationId
string
required
Example:

"org-uuid"

Example:

"Dunder Mifflin"

taxId
string
required
Example:

"ABC101010111"

taxSystem
string
required
Example:

"601"

email
string
required
Example:

"email@example.com"

defaultInvoiceUse
string
required
Example:

"G01"

address
object
required
createdAt
string<date-time>
required
updatedAt
string<date-time>
required
phone
object
Example:

"6474010101"