Documentation
Invoices
invoices.internal_notes
REST
ShippingPOST /api/v1/invoices/internal_notesMCP tool
Liveinvoices.internal_notesExposed on: REST API · Shop MCP server · Claude connector · Dash (in-app copilot) · Zapier. Part of the Invoices domain.
Operating contract
The shop's OWN notes on a bill — why it was discounted, who authorised the credit, what the customer said on the phone about paying late.
THESE ARE NOT ON THE CUSTOMER'S COPY AND MUST NEVER BE READ BACK TO THEM. That is the entire point of the field: it is what one member of staff writes for another about somebody who is not in the room. notes on invoices.get is the customer-facing text; this is not.
USE IT TO ANSWER A COLLEAGUE, NOT A CUSTOMER. 'Why is this one still open' is very often answered here and nowhere else, and quoting the answer into a chase message is how a shop's private assessment reaches the person it is about.
An empty string means nobody has written anything, which is the common case.
One invoice's notes, entirely returned, so nothing is truncated.
Who may call it
- Permission
invoices.accessThe caller must hold Invoices at the ACT level. A read-only dashboard grant on the same section is refused.- Plan
- Every planNo plan gate. Available on every Service VIN plan.
- Retries
naturalNaturally idempotent — running it twice leaves the same world as running it once. A retrying integration needs no key.- Rate class
readCounted against the read budget — the widest of the four.
Input
| Field | Type | Description |
|---|---|---|
| invoice_idrequired | stringuuid | The invoice whose private notes to read, as returned by invoices.list. |
Output
| Field | Type | Description |
|---|---|---|
| invoice_id | string | — |
| notes | string | — |
| has_notes | boolean | — |
Examples
Built from this capability's own schema — required fields and the ones carrying a default, and nothing invented. Paste one and it validates.
export SERVICEVIN_API_KEY=svk_live_…
curl -X POST https://www.servicevin.com/api/v1/invoices/internal_notes \
-H "Authorization: Bearer $SERVICEVIN_API_KEY" \
-H "Content-Type: application/json" \
-d '{"invoice_id":"9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"}'const res = await fetch("https://www.servicevin.com/api/v1/invoices/internal_notes", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.SERVICEVIN_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"invoice_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"
}),
});
// Success and failure are both envelopes. Switch on error.code, never
// on error.message — the codes are stable, the messages are for people.
const payload = await res.json();
if (!res.ok) throw new Error(payload.error.code);
const data = payload.data;import os, requests
res = requests.post(
"https://www.servicevin.com/api/v1/invoices/internal_notes",
headers={"Authorization": f"Bearer {os.environ['SERVICEVIN_API_KEY']}"},
json={
"invoice_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"
},
timeout=30,
)
payload = res.json()
if not res.ok:
raise RuntimeError(payload["error"]["code"])
data = payload["data"]{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "invoices.internal_notes",
"arguments": {
"invoice_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"
}
}
}Refusals
The four gates run in this order on every surface, and the order is not arbitrary — see Authentication.
| Status | Code | When |
|---|---|---|
| 404 | not_found | The id is unknown, or the feature is not enabled for this account. Deliberately the same answer for both. |
| 403 | forbidden | This login does not hold invoices.access. |
| 422 | validation_error | An argument was wrong. The message names the field. |
| 429 | rate_limited | Too many read calls. Back off and retry. |
| 500 | internal_error | Something failed on our side. Nothing was changed. |