
The customer system sends a POST to an import endpoint of VAT and transmits the API token in the header.x-api-keyThe token check of the platform has validate the API token.Tax Administration checks the token and its expiration date and confirms the associated user. If the token is invalid,Tax Administration rejects the request withTax Administration .401The token check forwards the request with the confirmed identity to VAT. VAT checks the interface configuration, validates the data, and stores the data in the Pre-Import. VAT responds to the customer system, with on success.200
: A system or middleware can send an HTTPS POST with a JSON body.Customer system : Firewall and proxy allow outbound HTTPS connections via TCP 443 to the host name of your VAT environment.Network : A secret store or password manager holds the API token. The token does not belong in source code or transport requests.Secret store : A mapping assigns the company numbers of your customer system to the company numbers created in VAT.Company numbers
the base URL of your VAT environment, for example https://<customer>.gtc-vat.api.<environment>.lucanet.cloudthe list of company numbers created in VAT, against which your customer system matches its data
401



401
Store the API token in the secret store – not in source code, not in a log, and not in a URL. Allow outbound connections via TCP 443 to the host name of your VAT environment. If the traffic passes through a proxy, the proxy must let the host through and forward the headers unchanged. Note the expiration date of the API token and set a reminder before it expires.
POST /-/api/v1/import/vat-total-data | ||
POST /-/api/v1/import/vat-validation-data | ||
POST /-/api/v1/import/total-balances | ||
POST /-/api/v1/import/esl-data |
/-/
/-/api/import//-/api/v1/import/
x-api-key | Bearer |
Content-Type | application/json |
/vat-total-data
/esl-data | |||
: A period separates the decimal places, and a maximum of two decimal places is allowed. Valid values are, for example,Decimal separator ,1900.00 , and-500.50 . A comma as the decimal separator results in0.00 .400 : Thousands separators are not allowed.Thousands separator and10.000,00 are both invalid amounts.10,000.00 : The customer system transmits amounts as JSON strings and not as numbers, for exampleAmounts as strings ."taxBaseAmount": "10000.00" : TheCurrency field contains the three-letter ISO 4217 code.currencyKey : TheDate andperiodFrom fields strictly use the dd.MM.yyyy format with leading zeros, for exampleperiodTo .01.01.2026 : TheTax type field containstaxType for input tax orINPUT for output tax. The field is not case-sensitive.OUTPUT : The request uses UTF-8.Character encoding
/vat-total-data
/vat-total-data
/vat-total-data
/vat-validation-data
/vat-validation-data
/vat-validation-data
/total-balances
/total-balances
/total-balances
/esl-data
/esl-data
/esl-data
401
200
401 | x-api-key | ||
500 | |||
401 | |||
401 | |||
400 | |||
400565 | |||
400562563 | |||
500567 |
401
: UseHTTP client or an RFC destination of type G that you maintain in transactioncl_http_client=>create_by_url . The RFC destination is the cleaner option because the host, path prefix, and proxy are then part of the system configuration and not of the code.SM59 : SetHeaders with the token value andx-api-key .Content-Type: application/json : Serialize the data, for example withJSON and amounts or a custom class. Create amounts as strings with a period as the decimal separator. Depending on the user settings, the ABAP standard output of a/ui2/cl_json field contains a comma and thousands separators, so you cannot use the output without conversion.CURR : Convert the trailing minus sign of the report output into a leading minus sign.Sign : Store the certificate of the remote server in transactionCertificate in the SSL client PSE of the application. Otherwise, the call aborts withSTRUST .SSSLERR_PEER_CERT_UNTRUSTED : Do not store the API token in the report, but in the secure store, inToken storage , or in a table with strict authorization protection. Never include the API token in a transport request.SSF
: TheCompany number and company code field contains the company number in VAT, theunitNo field contains the company code in the customer system. Both values can match, but they do not have to. You define the assignment once in the mapping.companyCode : Several company codes of one company belong in the sameSeveral company codes list, and several companies belong in several elements inentries .items : Send one period per request at first and not a whole year. Before going live, clarify with Lucanet which payload size your runs reach.Payload size
401
timestamp and called endpoint , period, andunitNo uuid HTTP status, , andstatusCode statusMessage
: Repeat the request with increasing intervals and a limited number of attempts. from the token check500 : A repetition is pointless because the payload is incorrect. Correct the data first.400 : A repetition is also pointless. Clarify the API token or the interface configuration first.401
[ ] API token generated with the technical user and copied during creation [ ] API token stored in the secret store, not in source code [ ] Expiration date noted and renewal scheduled [ ] Outbound connections via TCP 443 allowed, proxy forwards headers unchanged [ ] Company numbers matched against VAT [ ] Amounts with a period as the decimal separator, without thousands separators, and with a maximum of two decimal places [ ] Date fields in the dd.MM.yyyy format [ ] One successful test request per used endpoint, totals checked against the source report [ ] Logging of endpoint, , HTTP status, anduuid set upstatusCode [ ] Alerting on error responses set up
This content was generated using AI and reviewed by Lucanet subject matter experts before publication.
Last updated on Oct 6, 2026