Skip to main content
Some sources only answer to a signed-in person. SUNARP needs a Peruvian DNI, and DIAN the taxpayer’s own DIAN account. For those, you register your own account once as a connection, and every query of that source runs as it.
You only do this once per account. After that you query the source like any other endpoint: nothing extra in the request.

How it fits together

The API that receives your credentials can store them but cannot read them. Only the isolated service that signs in to the source can open them, and only for the query that needs them.

1. Register a connection

authorized: true records that you own the account or have its owner’s authorization. The answer never includes the credentials, only a masked name.

2. Query

  • Picking. Croma prefers the connection whose session is already open, then the one with the most allowance left. Send connection_id to use a specific one.
  • One query per account at a time. Queries on different accounts run in parallel; queries on the same account wait their turn, so they never sign in over each other.
  • Rotation. When an account reaches its daily allowance, the same query moves to your next connection. Register more than one for more capacity.

Connection states

GET /pe/sunarp/connections/v1 shows each connection’s state, the sign-ins used today and when it resets.

Security

  • Credentials are encrypted as soon as they reach Croma and bound to your organization: they cannot be used by anyone else’s.
  • Only the isolated service that signs in to the source can open them.
  • They are never returned by the API or shown to anyone, and never written to logs.
  • Deleting a connection destroys it permanently.

From the console

platform.usecroma.com/connections lists your organization’s connections with their state and sign-ins used today, connects new ones and deletes them. What you type there goes from your browser straight to the Croma API and is encrypted on arrival.

From an agent (MCP)

The same verbs are tools on the MCP server, one set per source: sunarp_connect, sunarp_list_connections and sunarp_delete_connection, and the same for dian_muisca. Credentials never pass through the conversation: the connect tool takes no account details and answers with a secure link to the console, valid for 30 minutes. After that the agent queries the source like any other.

SUNARP

Peru’s public registries, signed in with a DNI.

DIAN

A taxpayer’s electronic invoices and third-party reports, signed in with their DIAN account on their own behalf or for a company they represent.