Download the stamped CFDI XML
curl --request GET \
--url https://api.example.com/invoices/{uuid}/xml \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.example.com/invoices/{uuid}/xml"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.example.com/invoices/{uuid}/xml', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/invoices/{uuid}/xml",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/invoices/{uuid}/xml"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.example.com/invoices/{uuid}/xml")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/invoices/{uuid}/xml")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_bodyInvoices
Download Invoice XML
Authenticate with either a Supabase session (member of the invoice’s organization) or an API key belonging to that same organization. Streams back the exact XML returned by the PAC at stamping time, as stored in invoices.xml.
GET
/
invoices
/
{uuid}
/
xml
Download the stamped CFDI XML
curl --request GET \
--url https://api.example.com/invoices/{uuid}/xml \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.example.com/invoices/{uuid}/xml"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.example.com/invoices/{uuid}/xml', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/invoices/{uuid}/xml",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/invoices/{uuid}/xml"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.example.com/invoices/{uuid}/xml")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/invoices/{uuid}/xml")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_bodyReturns the raw CFDI XML file for a stamped invoice as a downloadable attachment, rather than embedding it in a JSON response like Get Invoice does. Like Cancel Invoice, this is a flat route — it does not carry
/organizations/{organizationId}/ in the URL. The invoice’s uuid (its folio fiscal, globally unique across all organizations) is enough to resolve the owning organization server-side, combined with the caller’s own auth context (session or API key).
Authentication
Accepts either:- A Supabase Bearer session (
Authorization: Bearer <token>) — the authenticated user must be a member of the invoice’s organization. - An API key (
X-API-Key: sk_...) with theread:invoicesscope — the key’s own organization must match the invoice’s organization, or the request is rejected with403 Forbidden.
Path Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
uuid | string (UUID) | Yes | Folio fiscal UUID (uuidFiscal) of the invoice to fetch — globally unique, not scoped to an organization |
Example Request
cURL
curl -X GET https://api.timbrix.mx/invoices/d3bfbc57-44af-4390-a064-f0afab85e5df/xml \
-H "Authorization: Bearer <your_token>" \
-o invoice.xml
TypeScript SDK
// Returns a Blob — write it to disk or hand it to the browser as a download.
const xml = await timbrix.invoices.getXml(
"d3bfbc57-44af-4390-a064-f0afab85e5df"
)
Example Response
This endpoint does not return a JSON body — it streams the raw XML file with:| Header | Value |
|---|---|
Content-Type | application/xml |
Content-Disposition | attachment; filename="<uuid>.xml" |
If you need the XML alongside other invoice metadata (
type, series,
total, etc.) in a single JSON payload, use Get
Invoice instead — it returns the same XML
content inline as the xml field.Common Errors
401 Unauthorized
Missing or invalid Bearer token / API key.403 Forbidden
The authenticated user is not a member of the invoice’s organization, or the API key does not have theread:invoices scope / belongs to a different organization than the one that owns the invoice.
404 Not Found
uuid does not match any invoice.