Skip to main content
Documentation

Invoices

invoices.internal_notes

Read the shop's private working notes on one invoice
Read-onlyRead budget

REST

Shipping
POST /api/v1/invoices/internal_notes

MCP tool

Live
invoices.internal_notes

Exposed on: REST API · Shop MCP server · Claude connector · Dash (in-app copilot) · Zapier. Part of the Invoices domain.

Operating contract

The shop's OWN notes on a bill — why it was discounted, who authorised the credit, what the customer said on the phone about paying late.

THESE ARE NOT ON THE CUSTOMER'S COPY AND MUST NEVER BE READ BACK TO THEM. That is the entire point of the field: it is what one member of staff writes for another about somebody who is not in the room. notes on invoices.get is the customer-facing text; this is not.

USE IT TO ANSWER A COLLEAGUE, NOT A CUSTOMER. 'Why is this one still open' is very often answered here and nowhere else, and quoting the answer into a chase message is how a shop's private assessment reaches the person it is about.

An empty string means nobody has written anything, which is the common case.

One invoice's notes, entirely returned, so nothing is truncated.

Who may call it

Permission
invoices.accessThe caller must hold Invoices at the ACT level. A read-only dashboard grant on the same section is refused.
Plan
Every planNo plan gate. Available on every Service VIN plan.
Retries
naturalNaturally idempotent — running it twice leaves the same world as running it once. A retrying integration needs no key.
Rate class
readCounted against the read budget — the widest of the four.

Input

FieldTypeDescription
invoice_idrequiredstringuuid

The invoice whose private notes to read, as returned by invoices.list.

Output

FieldTypeDescription
invoice_idstring

notesstring

has_notesboolean

Examples

Built from this capability's own schema — required fields and the ones carrying a default, and nothing invented. Paste one and it validates.

curl
export SERVICEVIN_API_KEY=svk_live_…

curl -X POST https://www.servicevin.com/api/v1/invoices/internal_notes \
  -H "Authorization: Bearer $SERVICEVIN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"invoice_id":"9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"}'

TypeScript (fetch)
const res = await fetch("https://www.servicevin.com/api/v1/invoices/internal_notes", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.SERVICEVIN_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "invoice_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"
  }),
});

// Success and failure are both envelopes. Switch on error.code, never
// on error.message — the codes are stable, the messages are for people.
const payload = await res.json();
if (!res.ok) throw new Error(payload.error.code);
const data = payload.data;

Python (requests)
import os, requests

res = requests.post(
    "https://www.servicevin.com/api/v1/invoices/internal_notes",
    headers={"Authorization": f"Bearer {os.environ['SERVICEVIN_API_KEY']}"},
    json={
    "invoice_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"
},
    timeout=30,
)
payload = res.json()
if not res.ok:
    raise RuntimeError(payload["error"]["code"])
data = payload["data"]

MCP tools/call — https://www.servicevin.com/api/mcp
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "invoices.internal_notes",
    "arguments": {
      "invoice_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"
    }
  }
}

Refusals

The four gates run in this order on every surface, and the order is not arbitrary — see Authentication.

StatusCodeWhen
404not_foundThe id is unknown, or the feature is not enabled for this account. Deliberately the same answer for both.
403forbiddenThis login does not hold invoices.access.
422validation_errorAn argument was wrong. The message names the field.
429rate_limitedToo many read calls. Back off and retry.
500internal_errorSomething failed on our side. Nothing was changed.