Digicust API
The Digicust API
REST, SFTP, Email, MCP and Webhooks. Every Digicust integration mode in one place. Pick the modality that fits your stack and ship.
Getting started in two steps
Most integrations are live within an afternoon. Create scoped API keys, point your client at the EU base URL, and start sending cases.
1. Create API keys
Generate scoped, revocable API keys directly in the platform. Use them for server-to-server integrations, ERP feeds or automation scripts.
Open the platform2. Explore the OpenAPI spec
Browse every endpoint in the interactive Swagger UI, or download the full OpenAPI 3.0 specification as JSON or YAML.
Open Swagger UIAPI keys for machines, sessions for people
Use API keys for server-to-server integrations and session tokens for user-facing apps. Both authenticate against the same endpoints; pick whatever fits the workflow.
- API keys are prefixed with `dgc_`, scoped per project and revocable from the platform.
- Session tokens are issued by Digicust's native auth for the web app, the Excel add-in and any signed-in user.
- Headers Send `Authorization: Bearer <key>` or `X-API-Key: <key>`. Either is accepted.
curl -X GET "https://api.eu.digicust.com/api/{orgId}/{projectId}/cases" \
-H "Authorization: Bearer dgc_1234567890abcdef1234567890abcdef"Full REST API with OpenAPI 3.0
Drive every Digicust capability over standard REST. Cases, conversations, strategies, integrations, mappings, MCP servers, API keys, tariff classification and trade-compliance checks are all addressable with the same authentication and shape.
- Authenticate with `Authorization: Bearer dgc_…` API keys or a session token from the Digicust login.
- One-step `cases/create-and-process` accepts files plus metadata in a single multipart request.
- Async `classify-batch` for large catalogues with WebSocket progress events.
- Polling and webhook patterns documented with copy-paste JS and Python examples.
- Full OpenAPI spec downloadable as JSON or YAML.
Digicust API
v3.0.0 · OpenAPI 3.0 · api.eu.digicust.com
- POST
/{orgId}/{projectId}/cases/create-and-processRequest body (multipart)
filesFile[]caseDataJSONstrategyIdstringmessagestring
Responses
- 200Case created and processing started
- 401Missing or invalid API key
- 429Rate limit exceeded
cURLmultipart/form-datacurl -X POST "https://api.eu.digicust.com/api/{orgId}/{projectId}/cases/create-and-process" \ -H "Authorization: Bearer dgc_your-api-key" \ -F "files=@invoice.pdf" \ -F 'caseData={"reference":"CASE-2026-001"}' - GET
/{orgId}/{projectId}/cases/{caseId} - POST
/{orgId}/{projectId}/classify-batch - POST
/{orgId}/{projectId}/trade-compliance/check - POST
/{orgId}/{projectId}/integrations - GET
/organizations/{orgId}/projects/{projectId}/api-keys
SFTP for legacy file flows
When an ERP, customs broker or partner can only speak files, Digicust drops processed cases on SFTP and picks up new ones from a watched folder. Same pipelines, same audit trail, no new schema for them to learn.
- Outbound: push processed declarations, structured payloads or PDF outputs to your SFTP server.
- Pre-built SFTP profiles for Scope, DAKOSY, E2OPEN, MERCURIO and DBH.
- Inbound: drop documents into a strategy folder; Digicust creates the case automatically.
- Password and key-based authentication with optional passphrase.
- Optional FTP fallback for partners that have not migrated to SFTP.
{
"name": "Export to SFTP",
"type": "SFTP",
"enabled": true,
"config": {
"sftp": {
"host": "sftp.example.com",
"port": 22,
"username": "sftp-user",
"privateKeyBase64": "LS0tLS1CRUdJTi…",
"remotePath": "/exports/customs"
}
}
}Email gateway for documents and follow-ups
Every strategy gets its own ingest email address; every case gets its own follow-up address. Send PDFs, EML, MSG or even photos and Digicust opens the case, parses attachments, classifies the goods and replies in your team's voice.
- Per-strategy ingest address creates new cases automatically.
- Per-case reply address attaches incoming mail to the open case.
- Document control agent can chase suppliers, brokers or carriers in their own language.
- Notifications on processing start, completion and SLA breaches.
- Custom email gateway endpoint for teams that want to relay through their own MTA.
ALPHATEX SRL
09:14Re: Invoice INV-2026-0481 + packing list
Attached the corrected packing list as requested. Please confirm receipt.
packing-list-INV-2026-0481.pdfDemo Components AG
08:42LTSD signed for 2026 catalogue
Bitte bestätigen Sie den Erhalt der unterzeichneten Lieferantenerklärung.
LTSD-2026-DEMO.pdfDAKOSY notifications
08:31ATLAS reference 26DE12345 released
Customs released 4 line items. ABD attached.
ABD-26DE12345.pdfTANGENS Spedition
YesterdayRückfrage zur Sendung 0481
Können Sie die Tarifnummer zu Position 3 noch einmal prüfen?
Re: Invoice INV-2026-0481 + packing list
Hello,
please find attached the corrected packing list for invoice INV-2026-0481. The dimensions for line 3 have been updated as you requested.
Best regards,
ALPHATEX SRL · logistics desk
1 attachment
packing-list-INV-2026-0481.pdf
168 KB · Parsed by Digicust agent
Model Context Protocol, first-class
Digicust speaks MCP, the open protocol that connects AI agents to external tools. Plug your own MCP server in to extend the Digicust agent with custom tools and data sources, or expose Digicust's customs tools to your own LLM apps.
- SSE, HTTP and stdio transports supported.
- Bring your own auth: bearer token, API key or basic.
- Per-strategy enabling so the agent only sees the tools it should use.
- Available tools surface live during case processing, no redeploy required.
- Use the Digicust MCP server from any LLM app to run customs workflows on demand.
{
"name": "Custom Tools Server",
"transport": "sse",
"url": "https://your-mcp-server.com/sse",
"auth": { "type": "bearer", "token": "your-mcp-token" },
"enabled": true
}Webhooks for outbound events
Get notified the moment a case is processed, a finding is raised or a strategy event fires. Webhooks are configured per-strategy and can be paired with mappings to deliver exactly the payload your system expects.
- POST/PUT/GET/DELETE delivery with custom headers.
- None, Basic, Bearer or Keycloak OAuth2 authentication.
- Pair with a mapping to transform the case into your downstream schema.
- Automatic retries (3 attempts, 60s timeout) with delivery audit log.
- Receive base64-encoded attachments alongside the structured payload.
{
"caseId": "6501234567890abcdef12345",
"reference": "CASE-2026-001",
"timestamp": "2026-01-15T10:35:00Z",
"data": {
"invoiceNumber": "INV-2026-001",
"items": [
{ "description": "Widget A", "hsCode": "8473.30.20", "value": 2550.00 }
]
}
}Tariff classification API
HS codes with reasoning, alternatives and BTI references
Single-item or batch (up to 10) classification with explicit GR1 to GR6 reasoning, confidence scores and alternative codes. Use the async batch endpoint for whole catalogues with WebSocket progress events.
curl -X POST "https://api.eu.digicust.com/api/{orgId}/{projectId}/tools/tariff-classification" \
-H "Authorization: Bearer dgc_your-api-key" \
-H "Content-Type: application/json" \
-d '{ "goodsDescription": "USB-A to USB-C cable, 2m, copper" }'Trade compliance API
Sanctions, dual-use, embargoes, CBAM, US re-export
One endpoint runs item checks (export/import controls, embargoes, CBAM, US re-export) and party screening across global denied-party lists, with a structured risk score.
curl -X POST "https://api.eu.digicust.com/api/{orgId}/{projectId}/trade-compliance/check" \
-H "Authorization: Bearer dgc_your-api-key" \
-H "Content-Type: application/json" \
-d '{
"itemChecks": [{ "customsTariffNumber": "8456301000", "destinationCountry": "CN" }],
"partyChecks": [{ "name": "Acme Corporation Ltd.", "role": "buyer" }]
}'Built for production
Global coverage
Submission-ready data for ATLAS, AES, NCTS, ASYCUDA, DAKOSY, AEB, Format, Scope, Mercurio and more across 30+ countries.
Async + sync
Sync endpoints for short-lived calls, async pipelines for batches and long-running classifications, with WebSocket progress events.
Enterprise security
API key plus session-based authentication, scoped keys, instant revocation, audit log on every action, GDPR-aligned EU hosting.
Security note: Keep API keys out of client-side code, rotate them periodically and revoke any key that may have leaked. Reach out to support if you suspect a compromise. Keys can be revoked instantly.
Ready to integrate?
Spin up an API key and start with a sandbox project, or talk to us first about the integration shape that fits your stack.