> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lastaccountingcompany.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Read the current original review and accounting calculation

> Returns the bill, exact selected original, bill-specific review, current journal calculation and posting history from one read-only snapshot. Customer purchase-invoice roles may inspect it; staff may inspect it within the selected customer workspace. Role eligibility describes actions available after explicit staff confirmation. It grants no write authority. Review and journal posting use the canonical operation plane with their own preview, execute and status requests. Neither action constitutes customer payment approval or bank settlement.



## OpenAPI

````yaml /openapi.yaml get /purchase-bills/{bill_id}/original-review
openapi: 3.1.0
info:
  title: LAC Customer API
  version: 2026-10-06.2
  description: >
    Last Accounting Company (LAC) is an AI-native accounting firm for Finnish
    SMBs:

    continuous reconciliation, daily close, real-time dashboards, and full Vero
    reporting.

    This API is the same surface the LAC customer portal UI uses. It gives you
    programmatic

    access to your books (read-only general-ledger views), financial statements,
    documents,

    invoicing, payroll, source-system connections, and the message channel to
    Björn, the

    accounting agent.


    ## Authentication


    Customer API requests carry `Authorization: Bearer <token>`. Two token kinds
    are accepted:


    - **Portal API key** (`lac_sk_...`) — minted in portal Settings → API
    access. Keys have a
      scope of `read` or `write`. Read-scoped keys are refused on all mutating methods
      (POST/PATCH/DELETE). Write-scoped keys act as the `operator` role: they can never
      use payroll endpoints (reads included), change company settings, grant access,
      approve or return an invoice, or manage API keys. Payroll and company settings
      require an interactive admin or existing broad approver. Invoice decisions require the matching invoice
      review permission. Write-scoped keys can prepare draft partner
      seller profiles. An interactive company admin must review the evidence and activate
      a profile or change an active profile.
    - **Firebase ID token** — the interactive session token used by the portal
    UI itself.


    The Shopify App endpoints are provider-facing exceptions with explicit

    per-operation security: App Home assets are public, App Bridge actions use

    a Shopify session JWT, and privacy webhooks use Shopify's raw-body HMAC.


    API keys are pinned to a single company, so the `customer_id` parameter
    (query string on

    GETs, body field on writes) can always be omitted when authenticating with
    an API key.

    Interactive tokens with access to multiple companies use `customer_id` to
    select one.


    ## Conventions


    - All field names are `snake_case` on the wire.

    - Monetary amounts are **integer cents** (fields suffixed `_cents`).

    - Rates and percentages are **basis points** (fields suffixed
    `_basis_points`;
      10000 = 100%, e.g. Finnish standard VAT 25.5% = 2550).
    - Quantities on invoice lines are decimal strings (e.g. `"1"`, `"2.5"`).

    - Dates are `YYYY-MM-DD`; periods are `YYYY-MM`; ranges accept `YYYY-MM`,
    `YYYY-Qn`,
      `YYYY`, `all`, `this_month`, or `last_6_months`.

    ## Limits


    - Document uploads: at most 20 files and 25 MB per request.

    - Sheet pagination: `limit` is capped at 200 rows per page (0 =
    unpaginated).


    ## Errors


    Errors return a JSON envelope `{"error": "...", "detail": "..."}` with a
    conventional

    HTTP status code (401 missing/invalid token, 403 insufficient scope or role,
    404 not

    found, 422 validation failure).


    More at
    [docs.lastaccountingcompany.com](https://docs.lastaccountingcompany.com).
  contact:
    name: Last Accounting Company
    url: https://docs.lastaccountingcompany.com
servers:
  - url: https://api.app.lastaccountingcompany.com/portal
    description: Production (note the /portal base path).
security:
  - apiKey: []
tags:
  - name: Company
    description: Company profile, identity, overview, and agent status.
  - name: Onboarding
    description: Saved customer onboarding facts, source inventory, and opening statements.
  - name: Books
    description: >-
      Read-only windows into the canonical general ledger: the spreadsheet-style
      Books/VAT sheet, financial statements, and analytics. There is no
      cell-edit or batch-edit API — the books are maintained by LAC. The one
      write here is a row declaration: your answer about a row (no receipt
      exists, private, a split, or a different booking), recorded as evidence
      for Björn.
  - name: Dimensions
    description: >-
      Project, cost-centre, department, and customer-defined reporting lenses
      over posted general-ledger lines. Provider catalogs are read-only; local
      axes and values are available for bank/file-only books.
  - name: Documents
    description: Receipt/invoice/contract uploads and per-file ingest metadata.
  - name: Messages
    description: The chat channel to Björn, the accounting agent.
  - name: Work log
    description: >-
      Append-only work-hours log (date, minutes, note). Hours are records for
      invoicing and payroll evidence; they do not post to the books. Kilometres
      are not logged here — vehicle travel is submitted as an expense claim in
      the portal, where statutory reimbursement rates apply.
  - name: Filings
    description: Filing authorization, review requests, and produced output packages.
  - name: Invoicing
    description: >-
      Sales invoicing — drafts, partner seller profiles, e-invoice sending, PDF
      finalizing, credit notes, reminders, recurring templates, and the
      invoice-customer register. LAC sends buyer invoices on the e-invoice
      network only. A partner-profile invoice also sends its legal seller a
      bookkeeping PDF copy.
  - name: Payroll
    description: >-
      Payroll workspace — employees, tax cards, employer settings, draft runs,
      and payslips. Every payroll operation (reads included) requires an
      interactive admin or existing broad-approver session and is NOT available
      to API keys.
  - name: Payments
    description: >-
      Review and named-human release for source-bound purchase, payroll, and
      reimbursement payments. Direct Open Payments delivery is the only rail:
      there is no manual payment composer and no bank or Wise file. A batch that
      cannot be delivered directly to the bank fails closed rather than becoming
      the customer's manual task.
  - name: Connections
    description: >-
      Source-system connections (bank, settlement providers, commerce,
      accounting systems, inbox/Gmail, Google Sheets) and service-connection
      requests/confirmations. PayPal connects with the company's own PayPal app,
      whose Client ID and Secret this API accepts, or with PayPal partner
      consent, which depends on PayPal approving LAC as a partner and returns a
      URL that a company admin must open. Other browser-interactive consent
      flows remain portal-only.
  - name: Shopify App
    description: >-
      Public Shopify App Home, App Bridge token exchange, installation handoff,
      and mandatory privacy webhooks. Offline access tokens never enter a
      browser.
  - name: Imports
    description: Historical import runs (e.g. migrated books) and their artifacts.
  - name: API keys
    description: >-
      Manage portal API keys. These endpoints require an interactive admin
      session (Firebase token) and are NOT available to API-key bearers, which
      receive 403.
  - name: Lens
    description: >-
      Typed, display-ready read models over the books: the transactions window
      (full row universe, three-state status, keyset pagination), the per-row
      booking view, data coverage, and the connections catalog.
  - name: Accounting
    description: >-
      The accountant's read models: general ledger, journal entries, context
      cards, the filings strip with previews, and the SQL explorer. Every
      endpoint here requires LAC staff access or the company admin role; other
      bearers receive 403.
paths:
  /purchase-bills/{bill_id}/original-review:
    get:
      tags:
        - Invoicing
      summary: Read the current original review and accounting calculation
      description: >-
        Returns the bill, exact selected original, bill-specific review, current
        journal calculation and posting history from one read-only snapshot.
        Customer purchase-invoice roles may inspect it; staff may inspect it
        within the selected customer workspace. Role eligibility describes
        actions available after explicit staff confirmation. It grants no write
        authority. Review and journal posting use the canonical operation plane
        with their own preview, execute and status requests. Neither action
        constitutes customer payment approval or bank settlement.
      operationId: getPurchaseBillOriginalReview
      parameters:
        - $ref: '#/components/parameters/BillIdPath'
        - $ref: '#/components/parameters/CustomerIdQuery'
      responses:
        '200':
          description: Current source, review, calculation and posting state.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PurchaseBillOriginalReview'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          description: Purchase bill not found in this company.
        '503':
          description: The current bill review could not be read.
      security:
        - firebaseToken: []
components:
  parameters:
    BillIdPath:
      name: bill_id
      in: path
      required: true
      description: >-
        Exact opaque purchase-bill entity ID, URL-encoded as one path segment.
        Preserve a literal bill: prefix or whitespace; this parameter is not the
        family-qualified row ID used by the unified invoice record route.
      schema:
        type: string
    CustomerIdQuery:
      name: customer_id
      in: query
      required: false
      description: >-
        Target company. Optional — API keys are pinned to one company, and
        single-company sessions default to it.
      schema:
        type: string
  schemas:
    PurchaseBillOriginalReview:
      type: object
      properties:
        customer_id:
          type: string
        bill:
          type: object
          properties:
            id:
              type: string
            resource:
              type: object
              properties:
                uri:
                  type: string
                revision:
                  type: string
              required:
                - uri
                - revision
              additionalProperties: false
            number:
              type: string
            supplier:
              type: string
            issue_date:
              type: string
            due_date:
              type: string
            currency:
              type: string
            status:
              type: string
            total_cents:
              type: integer
            vat_cents:
              type: integer
            open_cents:
              type: integer
            lines:
              type:
                - 'null'
                - array
              items:
                type: object
                properties:
                  description:
                    type: string
                  expense_account_code:
                    type: string
                  vat_code:
                    type: string
                  vat_rate_basis_points:
                    type: integer
                  net_cents:
                    type: integer
                  vat_cents:
                    type: integer
                  gross_cents:
                    type: integer
                  vat_deduction:
                    type:
                      - 'null'
                      - object
                    properties:
                      basis_points:
                        type: integer
                      review_status:
                        type: string
                      reason:
                        type: string
                    required:
                      - basis_points
                      - review_status
                      - reason
                    additionalProperties: false
                required:
                  - description
                  - expense_account_code
                  - vat_code
                  - vat_rate_basis_points
                  - net_cents
                  - vat_cents
                  - gross_cents
                additionalProperties: false
          required:
            - id
            - resource
            - number
            - supplier
            - issue_date
            - due_date
            - currency
            - status
            - total_cents
            - vat_cents
            - open_cents
            - lines
          additionalProperties: false
        original:
          type:
            - 'null'
            - object
          properties:
            filename:
              type: string
            id:
              type: string
            resource:
              type: object
              properties:
                uri:
                  type: string
                revision:
                  type: string
              required:
                - uri
                - revision
              additionalProperties: false
            sha256:
              type: string
            adequacy:
              type: string
            status:
              type: string
          required:
            - filename
            - id
            - resource
            - sha256
            - adequacy
            - status
          additionalProperties: false
        latest_review:
          type:
            - 'null'
            - object
          properties:
            decided_at:
              type: string
            receipt_uri:
              type: string
            id:
              type: string
            bill_id:
              type: string
            document_id:
              type: string
            bill_revision:
              type: string
            document_revision:
              type: string
            document_sha256:
              type: string
            document_adequacy:
              type: string
            verdict:
              type: string
            reason:
              type: string
            prior_review_id:
              type: string
            draft_contract:
              type: string
            draft:
              type: object
            draft_digest:
              type: string
          required:
            - decided_at
            - receipt_uri
            - id
            - bill_id
            - document_id
            - bill_revision
            - document_revision
            - document_sha256
            - document_adequacy
            - verdict
            - reason
            - prior_review_id
            - draft_contract
            - draft
            - draft_digest
          additionalProperties: false
        review_state:
          type: string
        review_reason:
          type: string
        calculation:
          type:
            - 'null'
            - object
          properties:
            contract:
              type: string
            draft:
              type: object
              properties:
                id:
                  type: string
                customer_id:
                  type: string
                period:
                  type: string
                entry_date:
                  type: string
                description:
                  type: string
                source:
                  type: string
                source_ref:
                  type: string
                lines:
                  type:
                    - 'null'
                    - array
                  items:
                    type: object
                    properties:
                      account_code:
                        type: string
                      debit_cents:
                        type: integer
                      credit_cents:
                        type: integer
                      vat_code:
                        type: string
                      description:
                        type: string
                      dimensions:
                        type: object
                        additionalProperties: true
                      dimension_allocations:
                        type: object
                        additionalProperties:
                          type:
                            - 'null'
                            - array
                          items:
                            type: object
                            properties:
                              value_id:
                                type: string
                              amount_cents:
                                type: integer
                            required:
                              - value_id
                              - amount_cents
                            additionalProperties: false
                    required:
                      - account_code
                    additionalProperties: false
                dimensions_as_stated:
                  type: boolean
              required:
                - period
                - entry_date
                - description
                - source
                - lines
              additionalProperties: false
            digest:
              type: string
            period_status:
              type: string
          required:
            - contract
            - draft
            - digest
            - period_status
          additionalProperties: false
        calculation_reason:
          type: string
        journals:
          type:
            - 'null'
            - array
          items:
            type: object
            properties:
              status:
                type: string
              reversal_of:
                type: string
              live:
                type: boolean
              id:
                type: string
              entry_number:
                type: string
              review_id:
                type: string
            required:
              - status
              - reversal_of
              - live
              - id
              - entry_number
              - review_id
            additionalProperties: false
        posting_state:
          type: string
        posting_ready:
          type: boolean
        posting_reason:
          type: string
        actor:
          type: object
          properties:
            kind:
              type: string
            realm:
              type: string
            subject:
              type: string
            tenant_id:
              type: string
          required:
            - kind
            - realm
            - subject
          additionalProperties: false
        actions:
          type:
            - 'null'
            - array
          items:
            type: object
            properties:
              operation:
                type: object
                properties:
                  id:
                    type: string
                  version:
                    type: integer
                    minimum: 0
                    maximum: 65535
                required:
                  - id
                  - version
                additionalProperties: false
              role_eligible:
                type: boolean
            required:
              - operation
              - role_eligible
            additionalProperties: false
        requires_staff_confirmation:
          type: boolean
      required:
        - customer_id
        - bill
        - original
        - latest_review
        - review_state
        - review_reason
        - calculation
        - calculation_reason
        - journals
        - posting_state
        - posting_ready
        - posting_reason
        - actor
        - actions
        - requires_staff_confirmation
      additionalProperties: false
    Error:
      type: object
      description: Standard error envelope.
      properties:
        error:
          type: string
          description: Machine-readable error message.
        detail:
          type: string
          description: Human-readable detail.
  responses:
    Unauthorized:
      description: Missing or invalid bearer token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Forbidden:
      description: >-
        Insufficient scope or role — e.g. a read-scoped key on a mutating
        method, or an API key on an interactive-session-only endpoint.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      bearerFormat: lac_sk_...
      description: >-
        Portal API key minted in portal Settings → API access. Scope `read` or
        `write`; pinned to one company. Send as `Authorization: Bearer
        lac_sk_...`.
    firebaseToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Firebase ID token from an interactive portal session. Required for
        interactive operations (payroll, company settings, API-key management)
        and invoice decisions allowed by the member's review permissions.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.