List a company's bank operations
GET/api/v1/workspaces/:workspace_id/companies/:company_id/bank_operations
Returns the company's bank operations, newest operation date first. Operations are not created through this API - one arrives from a provider sync, or from the extraction of a statement upload, whether or not that statement has since been committed - and they are not corrected or archived here either.
Beyond the company in the path, no filter is applied by default - and that includes archived. Every reconciliation status is returned unless you narrow it yourself, which matters most for partially_matched: a half-allocated line stays listable until its remainder is placed or dismissed, so a queue built on this endpoint cannot silently lose one. Archived lines are returned too - an absent archived narrows nothing, ?archived=false is how you ask for the active ones, and every row publishes archived so you can also split them yourself.
An unrecognised filter value narrows the result to nothing rather than being refused or ignored, which is the convention across this surface: ?direction=sideways returns an empty page, not a 4xx.
Request
Responses
- 200
- 400
- 401
- 403
- 404
The company's bank operations, newest operation date first.
The page query parameter is not an integer greater than or equal to 1, or it names a page beyond the last one for this filter. per_page is NOT part of this: an unreadable one falls back to the default rather than erroring.
The request carries no bearer token, or one that is invalid or expired. doorkeeper_authorize! is the first gate of the chain, so this is answered before the workspace, the company and the feature flag are ever resolved.
Three gates answer here identically, so message is what distinguishes them. FIRST, the OAuth SCOPE: a GET needs read, and a write-only or destroy-only token is refused before the workspace, the company and the feature are ever looked at. Then the workspace GRANT your application holds, and then the bank_reconciliation FEATURE for that workspace. The example below is refused for want of a grant.
No company with this id belongs to the resolved workspace. A company of ANOTHER workspace answers the same way - even when your token also holds a grant for that one - so the response cannot be used to probe for one.