> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.zip.tax/v-6-0/api-reference/merchant-transactions-tax-cloud/merchant-cert-list/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.zip.tax/_mcp/server. # List Exemption Certificates POST https://api.zip-tax.com/merchant/cert/list Content-Type: application/json Available on Enterprise PlanForwards to TaxCloud GET /exemption-certificates, scoped to the merchant's connection via a connectionId query filter, and returns the certificate collection verbatim. Requires a TaxCloud-connected merchant with credentials on file: this operation returns 403 for a self-managed merchant, whose only available transaction endpoint is /merchant/cart/calculate. Reference: https://docs.zip.tax/api-reference/merchant-transactions-tax-cloud/merchant-cert-list ## Authentication - `X-API-KEY` header (required) — API Key authentication via header ## Request ### Body (application/json) This endpoint expects an object. - `merchantId` (string, required) — UUID of the merchant. Must be owned by the calling account. Consumed by the Ziptax layer for routing and not forwarded to TaxCloud. - `ascending` (boolean, optional, default: false) — Whether to sort results in ascending order. Defaults to false (descending). - `cursor` (string, optional) — Opaque pagination cursor from the nextCursor field of a previous response. Omit to start at the first page. - `customerId` (string, optional) — Filter results to certificates belonging to this customerId. - `disabled` (boolean, optional, default: false) — Set true to list disabled (revoked) certificates instead of active ones. Defaults to false. - `limit` (long, optional, default: 20) — Maximum number of certificates to return per page. Defaults to 20; maximum 100. - `sortBy` (enum, optional, default: id) — The field to sort results by: 'createdDate' or 'id'. Defaults to 'id'. - Allowed values: `createdDate`, `id` ## Response ### 200 TaxCloud response relayed verbatim. - `limit` (long, required) — The maximum number of results per page that was applied. - `nextCursor` (string, required) — Opaque cursor to pass as 'cursor' on the next call to fetch the following page. Null when there are no further results. - `items` (list of TaxCloudCertResponse, optional) — The exemption certificates on this page of results. ## Errors ### 400 Merchant Cert List Body Bad Request Error Bad Request - `detail` (string, optional) — A human-readable explanation specific to this occurrence of the problem. - `errors` (list of ErrorDetail, optional) — List of individual error details - `instance` (string, optional) — A URI reference that identifies the specific occurrence of the problem. - `status` (long, optional) — HTTP status code - `title` (string, optional) — A short, human-readable summary of the problem type. This value should not change between occurrences of the error. - `type` (string, optional, default: about:blank) — A URI reference to human-readable documentation for the error. ### 401 Merchant Cert List Body Unauthorized Error Unauthorized - `detail` (string, optional) — A human-readable explanation specific to this occurrence of the problem. - `errors` (list of ErrorDetail, optional) — List of individual error details - `instance` (string, optional) — A URI reference that identifies the specific occurrence of the problem. - `status` (long, optional) — HTTP status code - `title` (string, optional) — A short, human-readable summary of the problem type. This value should not change between occurrences of the error. - `type` (string, optional, default: about:blank) — A URI reference to human-readable documentation for the error. ### 403 Merchant Cert List Body Forbidden Error Forbidden - `detail` (string, optional) — A human-readable explanation specific to this occurrence of the problem. - `errors` (list of ErrorDetail, optional) — List of individual error details - `instance` (string, optional) — A URI reference that identifies the specific occurrence of the problem. - `status` (long, optional) — HTTP status code - `title` (string, optional) — A short, human-readable summary of the problem type. This value should not change between occurrences of the error. - `type` (string, optional, default: about:blank) — A URI reference to human-readable documentation for the error. ### 404 Merchant Cert List Body Not Found Error Not Found - `detail` (string, optional) — A human-readable explanation specific to this occurrence of the problem. - `errors` (list of ErrorDetail, optional) — List of individual error details - `instance` (string, optional) — A URI reference that identifies the specific occurrence of the problem. - `status` (long, optional) — HTTP status code - `title` (string, optional) — A short, human-readable summary of the problem type. This value should not change between occurrences of the error. - `type` (string, optional, default: about:blank) — A URI reference to human-readable documentation for the error. ### 413 Merchant Cert List Body Content Too Large Error Request Entity Too Large - `detail` (string, optional) — A human-readable explanation specific to this occurrence of the problem. - `errors` (list of ErrorDetail, optional) — List of individual error details - `instance` (string, optional) — A URI reference that identifies the specific occurrence of the problem. - `status` (long, optional) — HTTP status code - `title` (string, optional) — A short, human-readable summary of the problem type. This value should not change between occurrences of the error. - `type` (string, optional, default: about:blank) — A URI reference to human-readable documentation for the error. ### 422 Merchant Cert List Body Unprocessable Entity Error Unprocessable Entity - `detail` (string, optional) — A human-readable explanation specific to this occurrence of the problem. - `errors` (list of ErrorDetail, optional) — List of individual error details - `instance` (string, optional) — A URI reference that identifies the specific occurrence of the problem. - `status` (long, optional) — HTTP status code - `title` (string, optional) — A short, human-readable summary of the problem type. This value should not change between occurrences of the error. - `type` (string, optional, default: about:blank) — A URI reference to human-readable documentation for the error. ### 429 Merchant Cert List Body Too Many Requests Error Too Many Requests - `detail` (string, optional) — A human-readable explanation specific to this occurrence of the problem. - `errors` (list of ErrorDetail, optional) — List of individual error details - `instance` (string, optional) — A URI reference that identifies the specific occurrence of the problem. - `status` (long, optional) — HTTP status code - `title` (string, optional) — A short, human-readable summary of the problem type. This value should not change between occurrences of the error. - `type` (string, optional, default: about:blank) — A URI reference to human-readable documentation for the error. ### 500 Merchant Cert List Body Internal Server Error Internal Server Error - `detail` (string, optional) — A human-readable explanation specific to this occurrence of the problem. - `errors` (list of ErrorDetail, optional) — List of individual error details - `instance` (string, optional) — A URI reference that identifies the specific occurrence of the problem. - `status` (long, optional) — HTTP status code - `title` (string, optional) — A short, human-readable summary of the problem type. This value should not change between occurrences of the error. - `type` (string, optional, default: about:blank) — A URI reference to human-readable documentation for the error. ### 502 Merchant Cert List Body Bad Gateway Error Bad Gateway - `detail` (string, optional) — A human-readable explanation specific to this occurrence of the problem. - `errors` (list of ErrorDetail, optional) — List of individual error details - `instance` (string, optional) — A URI reference that identifies the specific occurrence of the problem. - `status` (long, optional) — HTTP status code - `title` (string, optional) — A short, human-readable summary of the problem type. This value should not change between occurrences of the error. - `type` (string, optional, default: about:blank) — A URI reference to human-readable documentation for the error. ### 504 Merchant Cert List Body Gateway Timeout Error Gateway Timeout - `detail` (string, optional) — A human-readable explanation specific to this occurrence of the problem. - `errors` (list of ErrorDetail, optional) — List of individual error details - `instance` (string, optional) — A URI reference that identifies the specific occurrence of the problem. - `status` (long, optional) — HTTP status code - `title` (string, optional) — A short, human-readable summary of the problem type. This value should not change between occurrences of the error. - `type` (string, optional, default: about:blank) — A URI reference to human-readable documentation for the error. ## Types ### TaxCloudCertResponse - `accountId` (long, required) — The TaxCloud account id the certificate belongs to. - `address` (TaxCloudAddress, required) — Address of the exempt customer. - `certificateId` (string, required) — TaxCloud's identifier for the exemption certificate. Use it with /merchant/cert/get, /merchant/cert/delete, and as exemptionId on carts and orders. - `connectionId` (string, required) — The TaxCloud connection the certificate belongs to. - `createdDate` (datetime, required) — RFC3339 datetime the certificate was created. - `customerBusinessType` (string, required) — The type of business the customer is (e.g. RetailTrade, Government, NonprofitOrganization). - `customerId` (string, required) — Your identifier for the exempt customer. - `customerName` (string, required) — Name of the customer the certificate was issued to. - `reason` (string, required) — The reason the customer is exempt (e.g. Resale, FederalGovernment, CharitableOrganization). - `reasonDescription` (string, required) — Free-text elaboration of the exemption reason. - `singlePurchase` (boolean, required) — Whether the certificate covers a single purchase only, rather than being a blanket certificate. - `customerBusinessDescription` (string, optional) — Free-text description of the business, present when customerBusinessType is Other. - `disabledAt` (datetime, optional) — RFC3339 datetime the certificate was disabled, or null while it is active. - `states` (list of TaxCloudExemptState, optional) — The states the certificate is valid in. ### ErrorDetail - `location` (string, optional) — Where the error occurred, e.g. 'body.items[3].tags' or 'path.thing-id' - `message` (string, optional) — Error message text - `value` (any, optional) — The value at the given location ### TaxCloudAddress - `city` (string, required) — City or post-town of the address. - `line1` (string, required) — First line of the address: street number and name, PO Box, or building. Values longer than 50 characters are automatically truncated by TaxCloud. - `state` (string, required) — State, province, or other large territorial division, as a two-letter abbreviation (e.g. MN, CA, ON). - `zip` (string, required) — Postal or ZIP code. Five-digit (55401) and ZIP+4 (55401-2427) formats are accepted for US addresses. - `countryCode` (enum, optional, default: US) — ISO 3166-1 alpha-2 country code of the address. US (United States) or CA (Canada). Defaults to US when omitted. - Allowed values: `US`, `CA` - `line2` (string, optional) — Second line of the address, if any (e.g. apartment, suite, or unit number). Values longer than 50 characters are automatically truncated by TaxCloud. ### TaxCloudExemptState - `abbreviation` (string, required) — Two-letter abbreviation of a state the exemption certificate is valid in. ## Examples **Request** ```json { "merchantId": "merchantId" } ``` **Response** ```json { "limit": 1000000, "nextCursor": "nextCursor", "items": [ { "accountId": 1000000, "address": { "city": "Minneapolis", "line1": "323 Washington Ave N", "state": "MN", "zip": "55401-2427" }, "certificateId": "certificateId", "connectionId": "connectionId", "createdDate": "2024-08-01T14:00:00Z", "customerBusinessType": "customerBusinessType", "customerId": "customerId", "customerName": "Mr. Francis Exempt", "reason": "Resale", "reasonDescription": "reasonDescription", "singlePurchase": true, "customerBusinessDescription": "customerBusinessDescription", "disabledAt": "2024-01-15T09:30:00Z", "states": [ { "abbreviation": "MN" } ] } ] } ``` **SDK Code** ```python import requests url = "https://api.zip-tax.com/merchant/cert/list" payload = { "merchantId": "merchantId" } headers = { "X-API-KEY": "", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api.zip-tax.com/merchant/cert/list'; const options = { method: 'POST', headers: {'X-API-KEY': '', 'Content-Type': 'application/json'}, body: '{"merchantId":"merchantId"}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.zip-tax.com/merchant/cert/list" payload := strings.NewReader("{\n \"merchantId\": \"merchantId\"\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("X-API-KEY", "") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api.zip-tax.com/merchant/cert/list") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["X-API-KEY"] = '' request["Content-Type"] = 'application/json' request.body = "{\n \"merchantId\": \"merchantId\"\n}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api.zip-tax.com/merchant/cert/list") .header("X-API-KEY", "") .header("Content-Type", "application/json") .body("{\n \"merchantId\": \"merchantId\"\n}") .asString(); ``` ```php request('POST', 'https://api.zip-tax.com/merchant/cert/list', [ 'body' => '{ "merchantId": "merchantId" }', 'headers' => [ 'Content-Type' => 'application/json', 'X-API-KEY' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api.zip-tax.com/merchant/cert/list"); var request = new RestRequest(Method.POST); request.AddHeader("X-API-KEY", ""); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"merchantId\": \"merchantId\"\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "X-API-KEY": "", "Content-Type": "application/json" ] let parameters = ["merchantId": "merchantId"] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.zip-tax.com/merchant/cert/list")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```