> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lastaccountingcompany.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Enable read permissions

> Give LAC complete read-only access to your existing accounting and bank data in one pass.

Choose your system below. Give Last Accounting Company every available
**read** or **view** permission, then paste the credentials in LAC.

<Note>
  Read-only means no create, edit, approve, pay, delete, or invalidate access.
  LAC stores credentials securely and never shows them again.
</Note>

<Tabs>
  <Tab title="Fennoa" id="fennoa">
    The Fennoa key has no separate scope screen. Access belongs to the API
    user that owns the key.

    <Steps>
      <Step title="Create one API user for LAC">
        A Fennoa administrator or the current accounting firm opens
        **Users → Create new API user**. Choose **Yleinen API-käyttäjä**
        (General API user) and name it **Last Accounting Company**.

        [Open Fennoa's API-user guide](https://tietopankki.fennoa.com/tuotantoon-siirtyminen)
      </Step>

      <Step title="Give it every read right">
        If Fennoa shows a bulk read/view choice, use it. Otherwise, enable
        every permission labelled read or view. Leave every create, change,
        approve, payment, and delete permission off.

        Fennoa does not publish one universal read-only preset. Check the
        wording before you save.
      </Step>

      <Step title="Paste the credentials in LAC">
        Copy and paste the **API username** and **API key**.
      </Step>
    </Steps>

    <Accordion title="Read coverage: 28 available, 23 used today">
      | Area              | Available reads | Used today | Grant                    |
      | ----------------- | --------------: | ---------: | ------------------------ |
      | Accounting        |               8 |          7 | All read/view rights     |
      | Sales invoices    |               6 |          5 | All read/view rights     |
      | Purchase invoices |               8 |          8 | All read/view rights     |
      | Customers         |               3 |          1 | All read/view rights     |
      | Dimensions        |               3 |          2 | All read/view rights     |
      | **Total**         |          **28** |     **23** | **All read/view rights** |

      **Used today**

      * Accounting: `GET /accounting_api/get/ledger/{start}/{end}`,
        `/accounting_api/get/accounts`, `/accounting_api/get/vatcodes`,
        `/accounting_api/get/periods`,
        `/accounting_api/get/opening_balances/{period_id}`,
        `/accounting_api/get/locking_periods`, `/accounting_api/get/budgets`
      * Sales: `GET /sales_api/`, `/sales_api/{id}`,
        `/sales_api/get/payments/{start}/{end}`, `/sales_api/get/pdf/{id}`,
        `/sales_api/get/delivery_errors`
      * Purchases: `GET /purchases_api/get/list`, `/purchases_api/{id}`,
        `/purchases_api/get/approval_queue`, `/purchases_api/get/finvoice/{id}`,
        `/purchases_api/get/attachment/{id}/{attachment_id}`,
        `/purchases_api/get/tags/{id}`, `/purchases_api/get/unbooked`,
        `/purchases_api/get/suppliers`
      * Customers: `GET /customer_api/`
      * Dimensions: `GET /dimension_api/`, `/dimension_api/get/types`

      **Available for later**

      * `GET /accounting_api/get/account_balance`
      * `GET /sales_api/get/invoice_no/{invoice_no}`
      * `GET /customer_api/{id}`
      * `GET /customer_api/get/customer_no/{customer_no}`
      * `GET /dimension_api/{id}`

      Sources: [accounting](https://tietopankki.fennoa.com/api-accounting),
      [sales](https://tietopankki.fennoa.com/api-sales-invoices),
      [purchases](https://tietopankki.fennoa.com/api-purchases),
      [customers](https://tietopankki.fennoa.com/api-customers), and
      [dimensions](https://tietopankki.fennoa.com/api-dimensions).
    </Accordion>
  </Tab>

  <Tab title="Procountor" id="procountor">
    A Procountor API key has no permission picker. It inherits the rights of
    the user for whom it was created. Use a dedicated user so access stays
    read-only and easy to revoke.

    <Steps>
      <Step title="Create a dedicated user">
        A company administrator opens **Management → Users and user rights**
        and creates a user named **Last Accounting Company**.

        [Open Procountor's user-rights guide](https://help.procountor.fi/en/articles/532516-users-and-user-rights)
      </Step>

      <Step title="Set all safe viewing rights">
        Use **Management / Auditor** as the starting role. Set every available
        permission to **Viewing rights**. Set **Only allow API M2M login** to
        **Yes**. Remove personal-invoice and dimension-only limitations.

        Leave any right that only offers write-capable **All rights** at
        **No access**. In particular, do not grant payment, salary payment,
        approval, import, or editing authority.
      </Step>

      <Step title="Create and paste the API key">
        Sign in as a company administrator. Open **Basics → API client keys →
        New API key**. Select the dedicated LAC user and paste the **LAC client
        ID** shown on the connection screen. Create the key and paste it in
        LAC.

        [Open Procountor's API-key guide](https://dev.procountor.com/m2m-authentication/)
      </Step>
    </Steps>

    <Accordion title="Read coverage: 104 available operations, 16 used today">
      Procountor's public API currently contains 101 `GET` operations and
      three read-only report operations that use `POST`. Product, role, country,
      and two-factor rules can limit some operations for an M2M user.

      | API area                    | Available | Used today |
      | --------------------------- | --------: | ---------: |
      | Attachments                 |         2 |          1 |
      | Bank accounts               |         2 |          0 |
      | Bank statements             |         1 |          1 |
      | Business partners           |         9 |          2 |
      | Chart of accounts           |         1 |          1 |
      | Company                     |         9 |          1 |
      | Currencies                  |         4 |          0 |
      | Dimensions                  |         2 |          1 |
      | Employees                   |        11 |          0 |
      | Factoring contracts         |         2 |          0 |
      | Fiscal years                |         1 |          1 |
      | Health status               |         1 |          0 |
      | Integrations                |         2 |          0 |
      | Invoices                    |        12 |          3 |
      | Journal                     |         1 |          0 |
      | Ledger receipts             |         2 |          2 |
      | Multi-factor authentication |         1 |          0 |
      | Payments                    |         6 |          0 |
      | Payrolls                    |        10 |          0 |
      | Persons                     |         5 |          0 |
      | Products                    |         6 |          0 |
      | Reference payments          |         1 |          1 |
      | Reports                     |         3 |          1 |
      | SIE file                    |         2 |          0 |
      | Session information         |         1 |          0 |
      | Users                       |         3 |          0 |
      | VAT                         |         3 |          1 |
      | Webhooks                    |         1 |          0 |
      | **Total**                   |   **104** |     **16** |

      **Used today**

      `GET /company`, `GET /fiscalyears`, `GET /coa`, `GET /dimensions`,
      `GET /vats/default`, `GET /businesspartners`,
      `GET /businesspartners/{id}`, `GET /ledgerreceipts`,
      `GET /ledgerreceipts/{receiptId}`, `GET /invoices`,
      `GET /invoices/{invoiceId}`, `POST /reports/ledgeraccounts`,
      `GET /bankstatements`, `GET /referencepayments`,
      `GET /attachments/{attachmentId}`, `GET /invoices/{invoiceId}/image`.

      **All available read operations**

      * Attachments: `GET /attachments`, `GET /attachments/{attachmentId}`
      * Bank accounts: `GET /bankaccounts`, `GET /bankaccounts/{id}`
      * Bank statements: `GET /bankstatements`
      * Business partners: `GET /businesspartners`, `/businesspartners/groups`,
        `/businesspartners/groups/{id}`, `/businesspartners/personaldetails`,
        `/businesspartners/{id}`, `/businesspartners/{id}/defaults/accounts`,
        `/businesspartners/{id}/defaults/dimensions`,
        `/businesspartners/{id}/defaults/dimensions/{dimensionId}`,
        `/businesspartners/{id}/defaults/products`
      * Chart of accounts: `GET /coa`
      * Company: `GET /company`, `/company/deliveryterms`,
        `/company/einvoiceaddresses`, `/company/expenses/collectionpenal/settings`,
        `/company/invoicecirculation/settings`,
        `/company/invoicecirculation/verifierlists`,
        `/company/invoicecirculation/verifierlists/{id}`,
        `/company/invoicetemplates`, `/company/usagesettings`
      * Currencies: `GET /currencies`, `/currencies/company`,
        `/currencies/exchangerate`, `/currencies/latest`
      * Dimensions: `GET /dimensions`, `GET /dimensions/{dimensionId}`
      * Employees: `GET /payrolls/employees`,
        `/payrolls/employees/{id}/holidaypay`,
        `/payrolls/employees/{id}/salarybase`,
        `/payrolls/employees/{id}/salaryinfo`,
        `/payrolls/employees/{id}/salaryinfo/employments`,
        `/payrolls/employees/{id}/salaryinfo/employments/{employmentId}`,
        `/payrolls/employees/{id}/salaryinfo/laborunionmemberships`,
        `/payrolls/employees/{id}/salaryinfo/laborunionmemberships/{laborUnionMembershipId}`,
        `/payrolls/employees/{id}/salaryinfo/taxcards`,
        `/payrolls/employees/{id}/salaryinfo/taxcards/{taxCardId}`,
        `/payrolls/employees/{id}/workinghourreduction`
      * Factoring contracts: `GET /factoringcontracts`,
        `GET /se/factoringcontracts`
      * Fiscal years: `GET /fiscalyears`
      * Health status: `GET /status`
      * Integrations: `GET /integrations/{integrationId}/customers`,
        `GET /integrations/{requestId}`
      * Invoices: `GET /invoices`, `/invoices/personalapprovals`,
        `/invoices/personalverifications`, `/invoices/transactions`,
        `/invoices/{invoiceId}`, `/invoices/{invoiceId}/comments`,
        `/invoices/{invoiceId}/comments/taggableusers`,
        `/invoices/{invoiceId}/comments/{commentId}`,
        `/invoices/{invoiceId}/image`, `/invoices/{invoiceId}/paymentevents`,
        `/invoices/{invoiceId}/paymentevents/{paymentEventId}`,
        `/invoices/{invoiceId}/transactions`
      * Journal: `GET /journals`
      * Ledger receipts: `GET /ledgerreceipts`,
        `GET /ledgerreceipts/{receiptId}`
      * Multi-factor authentication: `GET /mfatransactionresult/{transactionIdentifier}`
      * Payments: `GET /payments`, `/payments/directsalarypayments`,
        `/payments/directsalarypayments/{paymentListId}`, `/payments/errormessages`,
        `/payments/paymentevents`, `/payments/{paymentId}`
      * Payrolls: `GET /payrolls/laborunionsettings`,
        `/payrolls/salariesbasicinfo`, `/payrolls/salarylists`,
        `/payrolls/salarylists/{id}`, `/payrolls/salaryperiods`,
        `/payrolls/salaryperiods/{id}`, `/payrolls/salaryslips`,
        `/payrolls/salaryslips/{id}`, `/payrolls/salaryslips/{id}/accounting`,
        `/payrolls/salarytypes`
      * Persons: `GET /persons`, `/persons/{id}`,
        `/persons/{id}/defaults/dimensions`,
        `/persons/{id}/defaults/dimensions/{dimensionId}`,
        `/persons/{id}/defaults/products`
      * Products: `GET /products`, `/products/groups`,
        `/products/groups/{groupId}`, `/products/{productId}`,
        `/products/{productId}/defaults/dimensions`,
        `/products/{productId}/defaults/dimensions/{dimensionId}`
      * Reference payments: `GET /referencepayments`
      * Reports: `POST /reports/accounting`,
        `POST /reports/generalledger/{id}`, `POST /reports/ledgeraccounts`
      * SIE file: `GET /sie/availability`, `GET /sie/file`
      * Session information: `GET /sessioninfo`
      * Users: `GET /users`, `/users/profiles/{userId}`, `/users/rights`
      * VAT: `GET /vats/country`, `/vats/default`, `/vats/settings`
      * Webhooks: `GET /webhooks`

      Source: [Procountor API reference](https://dev.procountor.com/api-reference/),
      version 26.08.
    </Accordion>
  </Tab>

  <Tab title="Netvisor" id="netvisor">
    Netvisor grants access to a custom integration, not to a generic key
    scope. The connection screen shows the LAC integration key that identifies
    the correct resource list.

    <Steps>
      <Step title="Create the LAC integration">
        Open **Company menu → Software API identifiers**. Create a dedicated
        identifier named **Last Accounting Company**. Then open **Company menu
        → API resource permissions → Custom integrations** and add LAC with the
        **LAC integration key** shown on the connection screen.

        [Open Netvisor's resource-permissions guide](https://support.netvisor.fi/en/articles/766836-rights-of-api-resources)
      </Step>

      <Step title="Enable the complete LAC read bundle">
        First scan the resource actions shown inside the LAC integration.

        * If every action is read or export, turn on **Integration allowed**.
          This is Netvisor's clean bulk option.
        * If you see any import, add, create, edit, update, approve, pay,
          delete, or invalidate action, leave **Integration allowed** off.
          Enable only the 22 read/export resources listed below.

        If the LAC panel is missing one of the 22 resources, stop and message
        us. LAC must correct the registered integration bundle with Netvisor;
        you should not need to troubleshoot our setup.
      </Step>

      <Step title="Finish in LAC">
        Paste the **API identifier** and **API key**. LAC already knows your
        company Business ID.
      </Step>
    </Steps>

    <Accordion title="Read coverage: 22 requested resources, 10 used today">
      | Area                           | Requested | Used today |
      | ------------------------------ | --------: | ---------: |
      | Sales invoices and payments    |         5 |          2 |
      | Purchase invoices and payments |         6 |          2 |
      | Accounting and dimensions      |        11 |          6 |
      | **Total**                      |    **22** |     **10** |

      **Used today**

      `accountlist.nv`, `accountingperiodlist.nv`,
      `getaccountdimensionlist.nv`, `accountingledger.nv`,
      `accountbalance.nv`, `getvoucherattachments.nv`,
      `salesinvoicelist.nv`, `getsalesinvoice.nv`,
      `purchaseinvoicelist.nv`, `getpurchaseinvoice.nv`.

      **Complete requested bundle**

      * Sales invoices and payments: `salesinvoicelist.nv`,
        `getsalesinvoice.nv`, `deletedsalesinvoices.nv`,
        `salespaymentlist.nv`, `deletedsalespayments.nv`
      * Purchase invoices and payments: `purchaseinvoicelist.nv`,
        `getpurchaseinvoice.nv`, `getattachments.nv`,
        `deletedpurchaseinvoices.nv`, `paymentlist.nv`,
        `deletedpurchasepayments.nv`
      * Accounting and dimensions: `accountingledger.nv`,
        `deletedvouchers.nv`, `accountlist.nv`, `accountingperiodlist.nv`,
        `vouchertypelist.nv`, `dimensionlist.nv`, `accountbalance.nv`,
        `getbankaccounts.nv`, `getvoucherattachments.nv`,
        `getaccountdimensionlist.nv`, `financialobligationstatus.nv`

      The extra reads are limited to accounting completeness: source deletion
      detection, bank-account identity, invoice payment links, purchase
      evidence, voucher/dimension interpretation, and Netvisor's obligation
      and ledger-reconciliation status. “Deleted…” resources only read deletion
      history; they do not delete data. Several of Netvisor's deletion reads
      expose only a seven-day history, so LAC must poll them without gaps.

      Payroll, user administration, customer/vendor masters, orders, products,
      warehouse data, imports, approvals, payment initiation, and every source
      mutation are excluded. If one of the 22 resources is missing from the LAC
      panel, message us: only Netvisor partner support can add it to the
      registered integration bundle.

      Sources: Netvisor's [accounting](https://support.netvisor.fi/en/articles/766886-accounting-and-dimensions-in-general),
      [sales](https://support.netvisor.fi/en/articles/766852-sales-invoices-orders-and-payments-in-general),
      and [purchase](https://support.netvisor.fi/en/articles/766853-purchase-invoices-orders-payments-and-vendors-in-general)
      resource guides; its [deleted-voucher guide](https://support.netvisor.fi/en/articles/766891-get-deleted-vouchers-deletedvouchers-nv)
      documents the seven-day deletion-history constraint.
    </Accordion>
  </Tab>

  <Tab title="Wise" id="wise">
    Wise puts the access choice directly on the token. You do not need to
    choose individual API routes.

    <Steps>
      <Step title="Open API tokens in a browser">
        Sign in to the correct Wise Business profile on the web. Open **Your
        account → Connect and manage apps → API tokens**. Wise does not offer
        token creation in the mobile app.

        [Open Wise's API-token guide](https://wise.com/help/articles/2958107/getting-started-with-the-api)
      </Step>

      <Step title="Create the safe bulk token">
        Choose **Add new token**, name it **Last Accounting Company**, and set
        the access level to **Read only**. Complete two-step verification.
      </Step>

      <Step title="Paste it in LAC">
        Wise shows the token only once. Copy it and paste the **API token** in
        LAC before you close the dialog.
      </Step>
    </Steps>

    <Accordion title="Read coverage: one read-only token, 4 routes used today">
      Wise does not ask you to grant routes one by one. The **Read only** access
      level is the full safe choice. LAC currently uses:

      * `GET /v2/profiles`
      * `GET /v4/profiles/{profile_id}/balances`
      * `GET /v1/profiles/{profile_id}/balance-statements/{balance_id}/statement.json`
      * `GET /v1/transfers`

      Wise can limit statement access by account country and token product.
      LAC shows any missing statement months after the first sync.
    </Accordion>
  </Tab>
</Tabs>
