---
title: "Patch Company Peppol Settings"
url: "https://developer.yukisoftware.com/apis/yuki-platform-api-prod-1/versions/9cdc452d-fd77-4e06-8797-f61e76134ec9/operations/patchCompanyPeppolSettings"
---

> Full API specification: https://developer.yukisoftware.com/apis/yuki-platform-api-prod-1/versions/9cdc452d-fd77-4e06-8797-f61e76134ec9.md

# Patch Company Peppol Settings

`PATCH` `/domains/{domain-id}/companies/{company-id}/settings/peppol`

Operation ID: `patchCompanyPeppolSettings`

Partially updates a company's Peppol settings, registering the company on the Peppol network, updating its registration, or removing it when both flags are set to false. You should have the **openid** and **yukiapi:domain:companies:update** scopes to access this endpoint - the gateway requires both together. Peppol must be enabled for the portal and licensed for the company's domain, and sending over Peppol is only possible with a Small bundle or higher. A request that asks for more than the portal or the domain is entitled to is rejected with 422, not with a permissions error - errorCode peppol:portal_not_enabled when Peppol is not enabled for the portal, peppol:domain_not_eligible when the company's domain is not licensed for Peppol, and peppol:sending_not_eligible when enableSending is requested for a domain that may receive over Peppol but not send. <!-- authorization:start --> **Authorization** Called with a **Portal User** token - an employee of an accounting portal. The caller must hold at least one of these roles in the portal: `AccountantManagement`, `Accountant`. Checked before any Peppol eligibility check, so a caller who lacks these roles gets 403 rather than a 422 about Peppol. <!-- authorization:end -->

## Path parameters

- `domain-id` (string, required) - The domain name
- `company-id` (string, uuid, required) - The ID of the company

## Header parameters

- `Authorization` (string, required) - Bearer token for authentication

## Request body (required)

Content types: `application/json`

## Responses

- `204` - Company Peppol settings patched successfully.
- `400` - Bad Request
- `401` - Unauthorized
- `403` - Forbidden
- `404` - Not Found
- `409` - Conflict
- `422` - Unprocessable Entity
- `500` - Internal Server Error
- `502` - Bad Gateway

## OpenAPI definition

```yaml
openapi: 3.0.0
info:
  title: Yuki Platform API Prod
  version: 1.0.77
servers:
  - url: https://apirest.yukiworks.be/api/v1
paths:
  /domains/{domain-id}/companies/{company-id}/settings/peppol:
    patch:
      x-environments:
        - development
        - pilot
        - production
      x-portal-visibility:
        - internal
        - trusted
        - prod
      x-required-roles:
        - any-of:
            - AccountantManagement
            - Accountant
          scope: portal
          note: Checked before any Peppol eligibility check, so a caller who lacks these
            roles gets 403 rather than a 422 about Peppol.
      summary: Patch Company Peppol Settings
      description: >-
        Partially updates a company's Peppol settings, registering the company
        on the Peppol network, updating its registration, or removing it when
        both flags are set to false. You should have the **openid** and
        **yukiapi:domain:companies:update** scopes to access this endpoint - the
        gateway requires both together. Peppol must be enabled for the portal
        and licensed for the company's domain, and sending over Peppol is only
        possible with a Small bundle or higher. A request that asks for more
        than the portal or the domain is entitled to is rejected with 422, not
        with a permissions error - errorCode peppol:portal_not_enabled when
        Peppol is not enabled for the portal, peppol:domain_not_eligible when
        the company's domain is not licensed for Peppol, and
        peppol:sending_not_eligible when enableSending is requested for a domain
        that may receive over Peppol but not send.


        <!-- authorization:start -->


        **Authorization**


        Called with a **Portal User** token - an employee of an accounting
        portal.


        The caller must hold at least one of these roles in the portal:
        `AccountantManagement`, `Accountant`.


        Checked before any Peppol eligibility check, so a caller who lacks these
        roles gets 403 rather than a 422 about Peppol.


        <!-- authorization:end -->
      operationId: patchCompanyPeppolSettings
      tags:
        - Company
      parameters:
        - $ref: "#/components/parameters/AuthorizationHeader"
        - $ref: "#/components/parameters/DomainIdPath"
        - $ref: "#/components/parameters/CompanyIdPath"
      security:
        - vismaConnectPortalUser:
            - openid
            - yukiapi:domain:companies:update
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: "#/components/schemas/PatchPeppolSettingsRequest"
      responses:
        "204":
          description: Company Peppol settings patched successfully.
        "400":
          $ref: "#/components/responses/BadRequestResponse"
        "401":
          $ref: "#/components/responses/UnauthorizedResponse"
        "403":
          $ref: "#/components/responses/ForbiddenResponse"
        "404":
          $ref: "#/components/responses/NotFoundResponse"
        "409":
          $ref: "#/components/responses/ConflictResponse"
        "422":
          $ref: "#/components/responses/UnprocessableEntityResponse"
        "500":
          $ref: "#/components/responses/InternalServerErrorResponse"
        "502":
          $ref: "#/components/responses/BadGatewayResponse"
security:
  - vismaConnectPortalUser:
      - openid
      - yukiapi:domain:companies:update
components:
  parameters:
    AuthorizationHeader:
      name: Authorization
      in: header
      required: true
      description: Bearer token for authentication
      schema:
        type: string
    DomainIdPath:
      name: domain-id
      in: path
      required: true
      description: The domain name
      example: 3afb7b54-6144-4561-9a29-1148006f2375
      schema:
        type: string
    CompanyIdPath:
      name: company-id
      in: path
      required: true
      description: The ID of the company
      example: 3afb7b54-6144-4561-9a29-1148006f2375
      schema:
        type: string
        format: uuid
  schemas:
    PatchPeppolSettingsRequest:
      type: object
      properties:
        enableSending:
          type: boolean
          nullable: true
          description: Enables or disables Peppol sending. Omit to leave unchanged.
        enableReceiving:
          type: boolean
          nullable: true
          description: Enables or disables Peppol receiving. Omit to leave unchanged.
      description: Request body for partially updating company Peppol settings.
    BadRequestError:
      description: A 400 comes in two shapes that differ by title. A request that
        fails model binding never reaches the operation and carries the title
        below, with errors keyed by the rejected field. A request the operation
        itself rejects carries the title Validation Error, with errors keyed by
        the rejected field for a field check, or by the errorCode for a business
        rule. Both shapes carry errorCode, traceId and errors.
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/400
        title: One or more validation errors occurred.
        status: 400
        detail: The request contains invalid or malformed fields. See the errors
          property for details.
        instance: /example/bad-request
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: validation:invalid_input
        errors:
          country:
            - The country field is required.
    UnauthorizedError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/401
        title: Unauthorized
        status: 401
        detail: Authentication is required.
        instance: /example/unauthorized
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: authentication:unauthorized
    ForbiddenError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/403
        title: Forbidden
        status: 403
        detail: You do not have permission to access this resource.
        instance: /example/forbidden
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: authentication:forbidden
        errors:
          authentication:forbidden:
            - You do not have permission to access this resource.
    NotFoundError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/404
        title: Not Found
        status: 404
        detail: The requested resource could not be found.
        instance: /example/not-found
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: companies:not_found
        errors:
          companies:not_found:
            - The requested resource could not be found.
    ConflictError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/409
        title: Conflict
        status: 409
        detail: The request could not be completed due to a conflict with the current
          state of the resource.
        instance: /example/conflict
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: domains:user_already_exists
        errors:
          domains:user_already_exists:
            - The request could not be completed due to a conflict with the
              current state of the resource.
    UnprocessableEntityError:
      description: A 422 is a request the API understood and refused on eligibility or
        state grounds rather than on the shape of the request or the caller's
        permissions. It is raised while the request is being handled, so it
        carries errorCode, traceId and errors, with errors keyed by the
        errorCode. Branch on errorCode together with the status.
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/422
        title: Unprocessable Entity
        status: 422
        detail: Domain is not eligible for Peppol.
        instance: /example/unprocessable-entity
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: peppol:domain_not_eligible
        errors:
          peppol:domain_not_eligible:
            - Domain is not eligible for Peppol.
    InternalServerError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/500
        title: Internal Server Error
        status: 500
        detail: An unexpected error occurred.
        instance: /example/internal-server-error
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: server:internal_error
        errors:
          server:internal_error:
            - An unexpected error occurred.
    BadGatewayError:
      description: An upstream service the request depends on did not respond or
        returned an error.
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/502
        title: Bad Gateway
        status: 502
        detail: Peppol network is currently unavailable
        instance: /example/bad-gateway
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: peppol:network_unavailable
        errors:
          peppol:network_unavailable:
            - Peppol network is currently unavailable
    ProblemDetails:
      type: object
      description: Error body returned as application/problem+json on every 4xx and
        5xx response. Beyond the standard problem members it carries the
        traceId, errorCode and errors extensions.
      properties:
        type:
          type: string
          description: URI reference identifying the problem type. Always
            https://httpstatuses.com/{status}, so it restates the status and
            carries no Yuki-specific meaning; branch on errorCode instead.
          example: https://httpstatuses.com/400
        title:
          type: string
          description: Short, human-readable summary of the problem type, in English.
          example: Validation Error
        status:
          type: integer
          description: HTTP status code, repeated from the response status line.
          example: 400
        detail:
          type: string
          description: Human-readable explanation of this specific occurrence. Free text
            meant for developers, not a stable contract - do not parse it.
          example: The company id is required.
        instance:
          type: string
          description: Optional. Path of the request as the API received it. The gateway
            fronts the API, so it is not always populated and it may differ from
            the URL the client called.
          example: /api/v1/companies/3afb7b54-6144-4561-9a29-1148006f2375
        traceId:
          type: string
          description: Correlation id for the request - the 32-character hexadecimal W3C
            trace id taken from the incoming traceparent header, or a locally
            generated id when none was propagated. Quote it in support requests.
          example: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode:
          type: string
          description: Stable machine-readable error identifier in {feature}:{error_type}
            form. This is the member to branch on, together with the status -
            not the feature prefix on its own. A request refused before it
            reaches the operation can answer 403 with validation:invalid_input,
            and an operation that fails on an unexpected internal state can
            answer 500 with that same code.
          example: companies:not_found
        errors:
          type: object
          description: Messages that explain the failure, grouped by key. Present on the
            errors raised while the request is being handled, not only on
            validation failures. It is absent from the errors that stop a
            request before it reaches the operation - the 401 for a missing or
            unaccepted token, the 403 for an absent scope or an unusable tenant
            claim, and the 500 for a session that could not be created - which
            carry only traceId and errorCode. Keys take one of two shapes - the
            name of the rejected field when the request failed model binding or
            field validation, otherwise the errorCode of the failure, repeating
            the errorCode member.
          additionalProperties:
            type: array
            items:
              type: string
          example:
            companies:validation_failed:
              - The company id is required.
  responses:
    BadRequestResponse:
      description: Bad Request
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/BadRequestError"
    UnauthorizedResponse:
      description: Unauthorized
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/UnauthorizedError"
    ForbiddenResponse:
      description: Forbidden
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/ForbiddenError"
    NotFoundResponse:
      description: Not Found
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/NotFoundError"
    ConflictResponse:
      description: Conflict
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/ConflictError"
    UnprocessableEntityResponse:
      description: Unprocessable Entity
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/UnprocessableEntityError"
    InternalServerErrorResponse:
      description: Internal Server Error
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/InternalServerError"
    BadGatewayResponse:
      description: Bad Gateway
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/BadGatewayError"
  securitySchemes:
    vismaConnectPortalUser:
      type: oauth2
      description: >
        Visma Connect token belonging to a **Portal User** - an employee of an
        accounting portal. The token's tenant must be a portal; the API resolves
        it to the caller's portal. The portal in the route must be that portal
        or one of the caller's master-accountant portals. Unless an endpoint
        says otherwise, the caller's roles are resolved against the portal.
      flows:
        authorizationCode:
          authorizationUrl: https://connect.identity.stagaws.visma.com/connect/authorize
          tokenUrl: https://connect.identity.stagaws.visma.com/connect/token
          scopes:
            openid: Required on every request, together with the endpoint API scope
            yukiapi:domain:companies:read: Allows reading information of a Company
            yukiapi:domain:companies:update: Allows the update of a Company
            yukiapi:portal:portals:read: Allows reading portal information
            yukiapi:domain:domains:read: Allows reading domains information
            yukiapi:domain:domains:write: Allows modifications of domain information, may
              include create/update
            yukiapi:domain:domains:create: Allows the creation of new domains
            yukiapi:domain:domains:update: Allows updating existing domain information
            yukiapi:domain:domains:delete: Allows the deletion of domain data
            yukiapi:domain:users:read: Allows reading of domain user data
            yukiapi:domain:users:write: Allows the creation of Domain Users
            yukiapi:domain:users:delete: Allows the deletion of Domain Users
            yukiapi:portal:portals:write: Allows updating existing portal information
            yukiapi:portal:users:read: Allows reading Portal user data
            yukiapi:portal:users:write: Allows the update of Portal user, may include create/update
            yukiapi:portal:users:update: Allows updating an existing Portal User
            yukiapi:portal:users:delete: Allows the deletion of a Portal User
```
