The Transactions panel tabs (TXN-8, TXN-2a, TXN-4a)
Required scope: `transactions:read` (personal access tokens; sessions have every scope).
Required scope: transactions:read (personal access tokens; sessions have every scope).
Authorization
bearerAuth Authorization: Bearer <token>: a mobile session token, or a personal access token
(srp_…) created in Account → API tokens (DEV-1).
Personal access tokens:
- Act as their user. The household comes from
X-SpendRock-Household, else the user's default. - Carry scopes (DEV-2), and each operation's description names the one it needs:
budget:read/budget:write(months, groups, items, funds, favorites, harvest),transactions:read/transactions:write(transactions, merchant suggestions),households:read/households:manage(households, members, invites),account:read/account:write(me, settings). A write scope includes its read scope. A call outside the token's scopes gets 403insufficient_scope, with the needed scope indetails.required_scope. - Can't manage tokens or passwords (403
session_required). - May expire (401
unauthenticatedafterwards). - Are rate-limited (DEV-3): 120 requests/minute per token with bursts up to 120. Every
response carries
X-RateLimit-Limit,X-RateLimit-Remaining, andX-RateLimit-Reset(seconds until the bucket is full again); over the limit the answer is 429rate_limitedwithRetry-After(seconds). Limits are kept per server instance, so they're approximate.
Sessions (web cookie or mobile bearer) have every scope and aren't limited this way. Cross-origin browser calls (CORS, for the API docs playground) must use a bearer token; cookies are never accepted cross-origin.
In: header
Query Parameters
Value in
- "untracked"
- "tracked"
- "deleted"
For tracked: limit to this budget month.
^[0-9]{4}-(0[1-9]|1[0-2])$Search by merchant (case-insensitive substring) or exact amount (e.g. 54.20).
length <= 1001 <= value <= 200100Header Parameters
The household to act on (HH-12). Defaults to the user's default household. 403 not_a_member if the caller isn't a current member (HH-16).
^[0-9A-HJKMNP-TV-Z]{26}$Response Body
application/json
application/json
application/json
curl -X GET "https://example.com/transactions?view=untracked"{ "transactions": [ { "id": "01J8Z3N4Q5R6S7T8V9W0X1Y2Z3", "type": "expense", "amount": 1234, "date": "2019-08-24", "merchant": "string", "note": "string", "budget_month": "2026-12", "splits": [ { "item_id": "01J8Z3N4Q5R6S7T8V9W0X1Y2Z3", "amount": 1234, "item_name": "string" } ], "status": "tracked", "deleted_at": "2019-08-24T14:15:22Z", "location": { "lat": -90, "lng": -180, "accuracy_m": 0 }, "created_by": "string", "created_by_name": "string", "updated_by": "string", "updated_by_name": "string", "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z" } ], "next_cursor": "string", "untracked_count": 0}Reorder the Favorites section (FAV-1). Independent of each item's order within its group. PUT
`item_ids` may list all favorites or only some (e.g. the favorites in the month being viewed). The listed favorites are placed, in the given order, into the positions they held between them in the household's current Favorites order; favorites that are not listed keep their positions. For example, with Favorites `[A, B, C, D]`, sending `[D, B]` gives `[A, D, C, B]`. Every id must be a current favorite, listed once; otherwise the request fails with `invalid`. Required scope: `budget:write` (personal access tokens; sessions have every scope).
Add an expense or income (TXN-1). Idempotent on the client-generated id (SYNC-1). POST
Required scope: `transactions:write` (personal access tokens; sessions have every scope).