NormAPI for companies: contract, operations and exit

The questions an IT project lead asks before deciding — answered before anyone has to ask them. Where something is committed in the individual contract and where it is not, it says so.

As of 8 October 2026 · Rule set v2026-08-31

In short

  • €599 a month for 150,000 generated invoices a year, a 12-month term, each further invoice €0.04. Validation costs nothing on any plan.
  • Every generated invoice is validated before it is returned, with the official KoSIT validator; the response names the rule set and the validation scenario.
  • Invoice content is processed in the memory of a server in the EU and not stored. There is no data to get back if you switch.
  • Availability, response times and liability are set in an individual contract that takes precedence over the terms.
  • NormAPI is young and run by one person. What that means for your risk, and what limits it, is below — without spin.

Price and contract

The Volume plan costs €599 net a month on a 12-month term. It includes 150,000 generated invoices per contract year — about €0.048 per invoice. Each further invoice costs €0.04, billed once a year. There is no setup fee.

Every successfully generated invoice counts, whether XRechnung in UBL or CII or a ZUGFeRD PDF. Rejected requests do not count, and validation never does. We set the monthly limit together, with headroom for peak months — a quarter-end run should not hang on an allowance.

The basis is the terms and an individual contract in text form that takes precedence over them (§ 1). The data processing agreement under Art. 28 GDPR applies to every customer; we send a signed copy on request. Design partners pay nothing for three months and 50% in the first year. All plans: pricing.

Availability and SLA

Starter and Business carry the target from the terms: 99.5% availability of the API per calendar month, announced maintenance excluded, with no claim to credits. On the Volume plan it becomes a commitment. Our standard for the individual contract:

CommitmentWhat it says
Availability99.5% per calendar month, measured from outside (UptimeRobot, public status page); announced maintenance excluded
CreditFor each started half percentage point below 99.5%: 10% of the monthly fee credited, at most 50%
Response to incidentsWithin four hours, working days 8:00–18:00 CET; other requests within one working day
New KoSIT rule setLive no later than ten working days after publication, and before the day it applies from
Changes to the APIIncompatible changes only as a new version, running at least twelve months alongside the old one
Discontinuing the serviceAnnounced at least twelve months in advance

Liability beyond the terms — a higher cap, say — is agreed in the individual contract if your legal department needs it.

When the API does not answer

NormAPI runs in one region, Amsterdam, with no second site. Failed services restart automatically, and any deployed version can be replaced by the previous one within minutes. Under load the API answers at once with 503 and Retry-After instead of timing out. The current state is on the status page.

Losing invoices is not a risk, because none are stored. The database holds only accounts, key hashes and usage counters — none of it part of your invoices.

For your integration this means: invoicing should not depend synchronously on generation. Generation is stateless, and as XML the same request yields the same document byte for byte — retrying after an error is safe. What works:

  1. 1Finalise the invoice in the ERP, as today.
  2. 2Put the generation into a queue as a job.
  3. 3On 503, 5xx or a timeout, retry with growing intervals; on 503, after Retry-After.
  4. 4If generation stays impossible for a while, keep the invoice as "e-invoice pending" and catch up later.

Rule-set updates

KoSIT publishes the XRechnung validation configuration about twice a year. We adopt each new version as soon as it passes our tests: the current one, v2026-08-31, came out on 2 September 2026 and was validating here 2 days later. Your integration does not change.

The version in force is in every response, in the X-Normapi-Ruleset header. What each version changes and whether you need to do anything is in the rule-set changelog — also as an Atom feed.

Interface stability

The API is versioned (/v1). Within a version, fields are added, but none is removed or changes its meaning, and no new field becomes required. An incompatible change would come as a new version, with the old one running for at least twelve months.

The interface is published as an OpenAPI file for code generators and test tools; a TypeScript client is on npm. Everything else is in the API documentation.

What exactly is generated

OutputStandard
XRechnung UBLXRechnung 3.0.2 in UBL 2.1 — invoices as Invoice, credit notes as CreditNote
XRechnung CIIXRechnung 3.0.2 in UN/CEFACT CII D16B
ZUGFeRDHybrid PDF per ZUGFeRD 2 / Factur-X, profile XRECHNUNG: PDF/A-3u with an embedded xrechnung.xml (CII)

Document types: invoice, partial and final invoice, corrected invoice, credit note and self-billed invoice; with allowances and charges at document and line level, amounts already paid, and credit transfer, SEPA direct debit and card payment.

Every document is validated by the KoSIT validator before the response. ZUGFeRD PDFs are also checked for PDF/A conformance with veraPDF in every test run. The readable page of the PDF is deliberately plain and uniform; your own invoice layout with the XML embedded is not offered yet.

Not included: sending by email or Peppol, and archiving. The file goes back to your ERP, and your existing delivery route takes over.

Data protection and security

Processing happens at the hosting provider Railway in the EU West region (Amsterdam). Railway is a US company; that is covered by a data processing agreement and the EU Standard Contractual Clauses. Only the operator has administrative access, from Ukraine — covered by the Standard Contractual Clauses as well. API keys are stored only as hashes; request logs contain no invoice data and are deleted after seven days.

The details for your data protection review: security and the data processing agreement, with the technical and organisational measures and the list of sub-processors.

Who runs NormAPI

NormAPI is a sole proprietorship: Dmytro Yalanskyi develops and runs the service, based in Ukraine (legal notice, about). NormAPI has been running since 12 August 2026. We are at the beginning and say so: whoever joins now gets design-partner terms and a say in what comes next.

What a one-person company means for your risk, and what limits it:

  • Nothing to get back. Invoice content is not stored; your ERP stays the system of record.
  • Standards, not a proprietary format. What comes out is XRechnung and ZUGFeRD, readable by any software. Validation rests on the open-source KoSIT validator, which you can run yourself.
  • Operations without manual steps. Every change passes automated tests against the official rule set before it is deployed; services restart themselves; availability is monitored from outside and shown publicly.
  • An end with notice. Should NormAPI ever be discontinued, you hear it at least twelve months in advance.

Termination and exit

The Volume plan runs 12 months; Starter and Business can be cancelled monthly (terms § 6). Switching is not a migration project: your ERP sends JSON and gets standard XML back, and only that one call is replaced.

To keep it that way, we recommend calling NormAPI behind an interface of your own in the ERP — a neutral invoice model from which an adapter builds the request. Then the provider is replaceable, us included.

How getting started works

  1. 1You send two or three anonymised sample invoices from your ERP — with credit notes, allowances or direct debit if you have them.
  2. 2We validate them against the rule set and show you, in a report with rule codes, what your mapping has to supply.
  3. 3You get an account with your allowance and test with real data; validation is always free.
  4. 4Sign the individual contract and the data processing agreement, create the production key, go live.