> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usecroma.com/llms.txt
> Use this file to discover all available pages before exploring further.

# DIAN Electronic Document

> Validate a Colombian electronic document (factura electrónica, nota crédito/débito) by its CUFE/UUID and the emisor or receptor NIT. Returns the issuer, recipient, totals and taxes (whole pesos, as the registry publishes them), current legitimate holder, validations, and events, each with its `code` (030, 032, 033...), name, date and parties. Set `include_pdf: true` to also receive `pdf_url`, the URL of the official PDF representation. The issuer may protect that PDF with a password; when handing it over, tell the user which passwords to try, in this order: (1) the issuer's NIT without check digit (`issuer.nit`, e.g. 900108281), the most common; (2) the recipient's document number without check digit (`recipient.nit`); (3) the recipient's NIT with its check digit appended. If none works, point the user to DIAN's public catalog (https://catalogo-vpfe.dian.gov.co/User/SearchDocument), where pasting the CUFE downloads DIAN's own graphical representation. Do not try to open or extract a protected PDF with other tools; give the user the link and the password hints instead. A result is reused for 24 hours; pass `cache: false` to read the registry again, for instance after filing an event. `found: false` means the document is not registered under that CUFE, or the NIT matches neither the emisor nor the receptor.

Supports async delivery: set `Prefer: wait=N` for an inline result, pass `callback_url` to receive a POST when ready, or poll `GET /jobs/{id}`.



## OpenAPI

````yaml /api-reference/openapi.json post /co/dian/electronic-document/v1
openapi: 3.1.0
info:
  title: Croma Marketplace API
  version: 1.0.0
  description: >-
    Government-data APIs for Colombia, Peru, Mexico, United States, Brazil, El
    Salvador, Bolivia, and Japan, plus global web search. Croma normalizes
    public-sector data into structured JSON for product teams and AI agents.


    Every operation is a POST with a JSON body and an organization API key as a
    bearer token; every operation is an idempotent lookup and accepts an
    optional `Idempotency-Key` header. Paths carry their major version (`/v1`);
    the versioning and deprecation policy, including the `Deprecation` and
    `Sunset` headers a retiring endpoint sends, is at
    https://docs.usecroma.com/versioning. Rate limits are per organization and
    reported on every response (`RateLimit-Policy`, `X-RateLimit-*`):
    https://docs.usecroma.com/rate-limits.
  termsOfService: https://usecroma.com/en/terms
  contact:
    name: Croma support
    url: https://usecroma.com/en/support
    email: support@usecroma.com
servers:
  - url: https://api.croma.run
security: []
paths:
  /co/dian/electronic-document/v1:
    post:
      tags:
        - Colombia
        - DIAN
      summary: DIAN Electronic Document
      description: >-
        Validate a Colombian electronic document (factura electrónica, nota
        crédito/débito) by its CUFE/UUID and the emisor or receptor NIT. Returns
        the issuer, recipient, totals and taxes (whole pesos, as the registry
        publishes them), current legitimate holder, validations, and events,
        each with its `code` (030, 032, 033...), name, date and parties. Set
        `include_pdf: true` to also receive `pdf_url`, the URL of the official
        PDF representation. The issuer may protect that PDF with a password;
        when handing it over, tell the user which passwords to try, in this
        order: (1) the issuer's NIT without check digit (`issuer.nit`, e.g.
        900108281), the most common; (2) the recipient's document number without
        check digit (`recipient.nit`); (3) the recipient's NIT with its check
        digit appended. If none works, point the user to DIAN's public catalog
        (https://catalogo-vpfe.dian.gov.co/User/SearchDocument), where pasting
        the CUFE downloads DIAN's own graphical representation. Do not try to
        open or extract a protected PDF with other tools; give the user the link
        and the password hints instead. A result is reused for 24 hours; pass
        `cache: false` to read the registry again, for instance after filing an
        event. `found: false` means the document is not registered under that
        CUFE, or the NIT matches neither the emisor nor the receptor.


        Supports async delivery: set `Prefer: wait=N` for an inline result, pass
        `callback_url` to receive a POST when ready, or poll `GET /jobs/{id}`.
      operationId: dian_electronic_document
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
        - $ref: '#/components/parameters/Prefer'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - cufe
                - document_number
              properties:
                cufe:
                  type: string
                  minLength: 30
                  maxLength: 100
                  pattern: ^[A-Za-z0-9-]{30,100}$
                  description: >-
                    CUFE/CUDE (unique electronic-document code) or UUID of the
                    document.
                document_number:
                  type: string
                  minLength: 4
                  maxLength: 15
                  pattern: ^\d{4,15}$
                  description: Colombian NIT (numeric, no verification digit). 4-15 digits.
                include_pdf:
                  type: boolean
                  default: false
                  description: >-
                    When true, the response includes `pdf_url`, the URL of the
                    official PDF representation of the document.
                cache:
                  type: boolean
                  default: true
                  description: >-
                    Set to `false` to skip any stored result for this lookup and
                    read the source again. The fresh answer replaces the stored
                    one and is charged as a new request. Default `true`.
                callback_url:
                  type: string
                  format: uri
                  description: POST the job result here when it finishes.
              additionalProperties: false
            example:
              cufe: >-
                0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
              document_number: '900123456'
      responses:
        '200':
          description: Successful response
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Idempotency-Key:
              $ref: '#/components/headers/Idempotency-Key'
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Sunset:
              $ref: '#/components/headers/Sunset'
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
            X-Cache:
              $ref: '#/components/headers/X-Cache'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DianElectronicDocumentResponse'
        '202':
          description: >-
            Accepted — the result is being computed asynchronously. Poll
            `job.status_url` (GET /jobs/{id}) or supply `callback_url` to have
            the result POSTed to you. Returned when `Prefer: wait` elapses
            before completion, or immediately when `callback_url` is set.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            Retry-After:
              $ref: '#/components/headers/Retry-After'
            Location:
              description: Absolute URL to poll for job status.
              schema:
                type: string
                format: uri
                example: https://api.croma.run/jobs/run_123
            X-Job-Id:
              description: Id of the created job.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/JobEnvelope'
        '400':
          description: Invalid request body
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Idempotency-Key:
              $ref: '#/components/headers/Idempotency-Key'
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Sunset:
              $ref: '#/components/headers/Sunset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '401':
          description: Missing or invalid API key
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Idempotency-Key:
              $ref: '#/components/headers/Idempotency-Key'
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Sunset:
              $ref: '#/components/headers/Sunset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '429':
          description: Rate limit exceeded
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Idempotency-Key:
              $ref: '#/components/headers/Idempotency-Key'
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Sunset:
              $ref: '#/components/headers/Sunset'
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
            Retry-After:
              $ref: '#/components/headers/Retry-After'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '500':
          description: Internal error
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Idempotency-Key:
              $ref: '#/components/headers/Idempotency-Key'
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Sunset:
              $ref: '#/components/headers/Sunset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '502':
          description: Upstream source returned an error
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Idempotency-Key:
              $ref: '#/components/headers/Idempotency-Key'
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Sunset:
              $ref: '#/components/headers/Sunset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
      security:
        - bearerAuth: []
      externalDocs:
        description: Interactive documentation and examples
        url: https://docs.usecroma.com/guides/colombia/dian
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: false
      description: >-
        Optional client-chosen key for this request (any string up to 255
        characters, e.g. a UUID). Every Croma operation is an idempotent lookup:
        repeating a request with the same body returns the same result and
        creates nothing, so retrying after a timeout or network failure is
        always safe. The key is echoed back in the `Idempotency-Key` response
        header so you can correlate a retry with its first attempt. Each attempt
        that reaches the API counts against the rate limit.
      schema:
        type: string
        maxLength: 255
        example: 0f8e9a42-6b7c-4d1e-9a3f-2c5d7e8f9a0b
    Prefer:
      name: Prefer
      in: header
      required: false
      description: >-
        Set `wait=N` to hold the connection up to N seconds for an inline
        result. If the job finishes in time you get the normal 200 body;
        otherwise a 202 with a `status_url` to poll.
      schema:
        type: string
        example: wait=30
  headers:
    X-Request-Id:
      description: Unique id for the request (req_…). Include it in support reports.
      schema:
        type: string
    RateLimit-Policy:
      description: >-
        Quota policy for this endpoint as an IETF RateLimit-Policy structured
        field, e.g. `"default";q=100;w=86400` (100 requests per 86400-second
        window per organization). Endpoints with an extra hourly ceiling list
        both policies, e.g. `"webSearch";q=100;w=3600, "default";q=100;w=86400`.
        Present on every response, including 401 and 429.
      schema:
        type: string
        example: '"default";q=100;w=86400'
    Idempotency-Key:
      description: >-
        The `Idempotency-Key` the request carried, echoed back unchanged. Absent
        when the request sent none.
      schema:
        type: string
    Deprecation:
      description: >-
        Present only on an endpoint version scheduled for removal: the date the
        deprecation took effect (RFC 9745). A `Sunset` header and a `Link` with
        `rel="successor-version"` accompany it. Policy:
        https://docs.usecroma.com/versioning
      schema:
        type: string
        example: '@1767225600'
    Sunset:
      description: >-
        Present only on an endpoint version scheduled for removal: the date
        after which it answers 410 (RFC 8594). Announced in the changelog at
        least 90 days ahead.
      schema:
        type: string
        format: date-time
        example: Wed, 01 Apr 2026 00:00:00 GMT
    X-RateLimit-Limit:
      description: Requests allowed in the current window.
      schema:
        type: integer
    X-RateLimit-Remaining:
      description: Requests left before you are throttled.
      schema:
        type: integer
    X-RateLimit-Reset:
      description: ISO 8601 timestamp when the window resets.
      schema:
        type: string
        format: date-time
    X-Cache:
      description: >-
        HIT or MISS. Cached hits spend no credits, but still count toward an
        hourly ceiling.
      schema:
        type: string
        enum:
          - HIT
          - MISS
    Retry-After:
      description: Seconds to wait before retrying.
      schema:
        type: integer
  schemas:
    DianElectronicDocumentResponse:
      type: object
      required:
        - data
      properties:
        data:
          $ref: '#/components/schemas/DianElectronicDocumentData'
    JobEnvelope:
      type: object
      required:
        - job
        - data
        - error
      description: >-
        Returned by async-capable endpoints (202) and by GET /jobs/{id}. `data`
        holds the endpoint's normal result once `status` is `completed`; `error`
        is populated once `status` is `failed`.
      properties:
        job:
          type: object
          required:
            - id
            - status
            - endpoint
            - created_at
            - finished_at
            - status_url
          properties:
            id:
              type: string
            status:
              type: string
              enum:
                - queued
                - running
                - completed
                - failed
                - canceled
                - expired
            endpoint:
              type: string
              description: The endpoint path that created this job.
            created_at:
              type:
                - string
                - 'null'
              format: date-time
            finished_at:
              type:
                - string
                - 'null'
              format: date-time
            status_url:
              type: string
              format: uri
              description: GET this URL to poll the job.
        data:
          description: The endpoint's normal result object once completed; null until then.
          oneOf:
            - type: object
            - type: 'null'
        error:
          description: Populated once the job has failed; null otherwise.
          oneOf:
            - type: object
              required:
                - type
                - code
                - message
              properties:
                type:
                  type: string
                code:
                  type: string
                message:
                  type: string
            - type: 'null'
    ApiError:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - type
            - code
            - message
          properties:
            type:
              type: string
              description: >-
                Broad category: invalid_request_error, authentication_error,
                not_found_error, rate_limit_error, upstream_error, api_error.
            code:
              type: string
              description: Machine-readable specific code.
            message:
              type: string
              description: Human-readable explanation, safe to surface in UI.
            param:
              type: string
              description: Field that triggered the error. Present on validation errors.
            details:
              type: object
              description: Free-form structured detail.
    DianElectronicDocumentData:
      type: object
      properties:
        found:
          type: boolean
          description: Whether the document is registered.
        cufe:
          type: string
          description: The queried CUFE, echoed back.
        document_type:
          anyOf:
            - type: string
            - type: 'null'
        series:
          anyOf:
            - type: string
            - type: 'null'
        folio:
          anyOf:
            - type: string
            - type: 'null'
        issue_date:
          anyOf:
            - type: string
            - type: 'null'
          description: Issue date (yyyy-mm-dd when parseable).
        issuer:
          type: object
          properties:
            nit:
              anyOf:
                - type: string
                - type: 'null'
            name:
              anyOf:
                - type: string
                - type: 'null'
          required:
            - nit
            - name
        recipient:
          type: object
          properties:
            nit:
              anyOf:
                - type: string
                - type: 'null'
            name:
              anyOf:
                - type: string
                - type: 'null'
          required:
            - nit
            - name
        total:
          anyOf:
            - type: number
            - type: 'null'
          description: >-
            In COP, as the registry publishes it: whole pesos, with centavos
            rounded by the source. The exact amount is on the official PDF
            (`include_pdf`).
        taxes:
          type: array
          items:
            type: object
            properties:
              name:
                type: string
              value:
                anyOf:
                  - type: number
                  - type: 'null'
                description: >-
                  In COP, as the registry publishes it: whole pesos, with
                  centavos rounded by the source. The exact amount is on the
                  official PDF (`include_pdf`).
            required:
              - name
              - value
        legitimate_holder:
          anyOf:
            - type: string
            - type: 'null'
          description: Current legitimate holder, when the document names one.
        pdf_url:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Official PDF representation of the document. It may be
            password-protected by the issuer: try the issuer's NIT without check
            digit (`issuer.nit`), then the recipient's document number without
            check digit (`recipient.nit`), then the recipient's NIT with its
            check digit. Null when not requested or not found.
        validations:
          type: array
          items:
            type: object
            properties:
              name:
                type: string
                description: The validation the authority performed.
              result:
                type: string
                description: Its verdict, in the authority's own words.
              detail:
                anyOf:
                  - type: string
                  - type: 'null'
                description: The explanation the page attaches to the verdict.
            required:
              - name
              - result
              - detail
        events:
          type: array
          items:
            type: object
            properties:
              code:
                anyOf:
                  - type: string
                  - type: 'null'
                description: >-
                  The registry's event code, e.g. `030` (acuse de recibo), `032`
                  (recibo del bien o servicio), `033` (aceptación expresa).
              name:
                anyOf:
                  - type: string
                  - type: 'null'
                description: The event's name as the registry prints it.
              date:
                anyOf:
                  - type: string
                  - type: 'null'
              issuer:
                type: object
                properties:
                  nit:
                    anyOf:
                      - type: string
                      - type: 'null'
                  name:
                    anyOf:
                      - type: string
                      - type: 'null'
                required:
                  - nit
                  - name
                description: >-
                  Who issued the event, as the registry lists it: the event's
                  emisor, which is not always the invoice's.
              recipient:
                type: object
                properties:
                  nit:
                    anyOf:
                      - type: string
                      - type: 'null'
                  name:
                    anyOf:
                      - type: string
                      - type: 'null'
                required:
                  - nit
                  - name
                description: 'Who the event is addressed to: the event''s receptor.'
              cude:
                anyOf:
                  - type: string
                  - type: 'null'
                description: The event's own document key (CUDE) in the registry.
              description:
                type: string
                description: >-
                  Every column of the row joined with ` · `. Prefer the
                  structured fields.
            required:
              - code
              - name
              - date
              - issuer
              - recipient
              - cude
              - description
      required:
        - found
        - cufe
        - document_type
        - series
        - folio
        - issue_date
        - issuer
        - recipient
        - total
        - taxes
        - legitimate_holder
        - pdf_url
        - validations
        - events
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Use Authorization: Bearer YOUR_API_KEY'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.