> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zivio.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List Purchase Orders

> Retrieve a paginated list of purchase_orders. Use filters to narrow results.

## Filtering

Use the `filter[<attribute>]` parameter to filter results. Multiple filters are combined with AND logic.

### Basic Examples
```
# Equality (implicit)
GET /api/v4/purchase_orders?filter[external_provider]=active

# Multiple values (implicit IN)
GET /api/v4/purchase_orders?filter[external_provider]=draft,pending

# With explicit operator
GET /api/v4/purchase_orders?filter[created_at][gte]=2024-01-01

# Range query
GET /api/v4/purchase_orders?filter[client_org_id][between]=10,100

# Multiple filters (AND)
GET /api/v4/purchase_orders?filter[external_provider]=active&filter[client_org_id][gte]=10
```

### Available Attributes

| Attribute | Type | Operators | Permitted Values |
|-----------|------|-----------|------------------|
| ccy | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | - |
| client_org_id | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`, `lt`, `lte`, `between` | - |
| created_at | datetime | `eq`, `not_eq`, `gt`, `gte`, `lt`, `lte`, `between` | - |
| deleted_at | datetime | `eq`, `not_eq`, `gt`, `gte`, `lt`, `lte`, `between` | - |
| expiry_date | date | `eq`, `not_eq`, `gt`, `gte`, `lt`, `lte`, `between` | - |
| external_id | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | - |
| external_provider | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | - |
| id | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`, `lt`, `lte`, `between` | - |
| po_number | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | - |
| status | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`, `lt`, `lte`, `between` | - |
| updated_at | datetime | `eq`, `not_eq`, `gt`, `gte`, `lt`, `lte`, `between` | - |
| updating | boolean | `eq`, `not_eq` | - |
| version | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`, `lt`, `lte`, `between` | - |

### OR Conditions

Use `or[group]` to combine filter groups with OR logic. Filters within a group are ANDed:
```
# Simple OR
GET /api/v4/purchase_orders?or[1][external_provider]=pending&or[2][external_provider]=active

# Complex OR (external_provider=pending AND client_org_id>=10) OR (external_provider=active)
GET /api/v4/purchase_orders?or[1][external_provider]=pending&or[1][client_org_id][gte]=10&or[2][external_provider]=active
```

## Sorting

Use `sort[<attribute>]` to order results. Default direction is ascending.
```
# Ascending (implicit)
GET /api/v4/purchase_orders?sort[created_at]=

# Descending
GET /api/v4/purchase_orders?sort[created_at]=desc

# Combined with filters
GET /api/v4/purchase_orders?filter[external_provider]=active&sort[created_at]=desc
```



## OpenAPI

````yaml /api-reference/v4/openapi.json get /purchase_orders
openapi: 3.1.0
info:
  title: API V4
  version: '4'
  description: >-
    OAuth 2.0 secured API. Obtain an access token using client credentials to
    access protected endpoints. The regional endpoints listed below serve every
    Zivio organisation, so each request — including the token request — must
    carry a `zivio-tenant-id` header identifying yours. Requests without it are
    rejected with a 404 before any token is checked.
  contact:
    name: API Support
    email: support@zivio.com
servers:
  - url: https://api.zivio.net/api/v4
    description: Global API Router
  - url: https://api.eu.zivio.net/api/v4
    description: EU Data Region
  - url: https://api.uk.zivio.net/api/v4
    description: UK Data Region
  - url: https://api.us.zivio.net/api/v4
    description: US Data Region
security:
  - oauth2: []
    tenantId: []
paths:
  /purchase_orders:
    get:
      tags:
        - Purchase Orders
      summary: List Purchase Orders
      description: >-
        Retrieve a paginated list of purchase_orders. Use filters to narrow
        results.


        ## Filtering


        Use the `filter[<attribute>]` parameter to filter results. Multiple
        filters are combined with AND logic.


        ### Basic Examples

        ```

        # Equality (implicit)

        GET /api/v4/purchase_orders?filter[external_provider]=active


        # Multiple values (implicit IN)

        GET /api/v4/purchase_orders?filter[external_provider]=draft,pending


        # With explicit operator

        GET /api/v4/purchase_orders?filter[created_at][gte]=2024-01-01


        # Range query

        GET /api/v4/purchase_orders?filter[client_org_id][between]=10,100


        # Multiple filters (AND)

        GET
        /api/v4/purchase_orders?filter[external_provider]=active&filter[client_org_id][gte]=10

        ```


        ### Available Attributes


        | Attribute | Type | Operators | Permitted Values |

        |-----------|------|-----------|------------------|

        | ccy | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | -
        |

        | client_org_id | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`,
        `lt`, `lte`, `between` | - |

        | created_at | datetime | `eq`, `not_eq`, `gt`, `gte`, `lt`, `lte`,
        `between` | - |

        | deleted_at | datetime | `eq`, `not_eq`, `gt`, `gte`, `lt`, `lte`,
        `between` | - |

        | expiry_date | date | `eq`, `not_eq`, `gt`, `gte`, `lt`, `lte`,
        `between` | - |

        | external_id | string | `eq`, `not_eq`, `in`, `not_in`, `like`,
        `not_like` | - |

        | external_provider | string | `eq`, `not_eq`, `in`, `not_in`, `like`,
        `not_like` | - |

        | id | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`, `lt`,
        `lte`, `between` | - |

        | po_number | string | `eq`, `not_eq`, `in`, `not_in`, `like`,
        `not_like` | - |

        | status | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`, `lt`,
        `lte`, `between` | - |

        | updated_at | datetime | `eq`, `not_eq`, `gt`, `gte`, `lt`, `lte`,
        `between` | - |

        | updating | boolean | `eq`, `not_eq` | - |

        | version | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`, `lt`,
        `lte`, `between` | - |


        ### OR Conditions


        Use `or[group]` to combine filter groups with OR logic. Filters within a
        group are ANDed:

        ```

        # Simple OR

        GET
        /api/v4/purchase_orders?or[1][external_provider]=pending&or[2][external_provider]=active


        # Complex OR (external_provider=pending AND client_org_id>=10) OR
        (external_provider=active)

        GET
        /api/v4/purchase_orders?or[1][external_provider]=pending&or[1][client_org_id][gte]=10&or[2][external_provider]=active

        ```


        ## Sorting


        Use `sort[<attribute>]` to order results. Default direction is
        ascending.

        ```

        # Ascending (implicit)

        GET /api/v4/purchase_orders?sort[created_at]=


        # Descending

        GET /api/v4/purchase_orders?sort[created_at]=desc


        # Combined with filters

        GET
        /api/v4/purchase_orders?filter[external_provider]=active&sort[created_at]=desc

        ```
      operationId: getPurchaseOrders
      parameters:
        - name: page
          in: query
          schema:
            type: integer
            default: 1
          description: Page number for pagination
        - name: limit
          in: query
          schema:
            type: integer
            default: 20
            maximum: 100
          description: Number of results per page (max 100)
        - name: filter[<attribute>]
          in: query
          style: deepObject
          explode: true
          schema:
            type: object
          description: >-
            Filterable attributes:


            **integer** (operators: eq, not_eq, in, not_in, gt, gte, lt, lte,
            between): client_org_id, id, status, version

            **datetime** (operators: eq, not_eq, gt, gte, lt, lte, between):
            created_at, deleted_at, updated_at

            **string** (operators: eq, not_eq, in, not_in, like, not_like): ccy,
            external_id, external_provider, po_number

            **boolean** (operators: eq, not_eq): updating

            **date** (operators: eq, not_eq, gt, gte, lt, lte, between):
            expiry_date


            Note: `like` is a case-insensitive substring match — pass the bare
            term (filter[title][like]=redesign). Do not add % wildcards; they
            are not needed.
          examples:
            equality:
              summary: Simple equality
              value:
                external_provider: active
            multiple_values:
              summary: Multiple values (implicit IN)
              value:
                external_provider: draft,pending
            with_operator:
              summary: With explicit operator
              value:
                created_at:
                  gte: '2024-01-01'
            range:
              summary: Range query
              value:
                client_org_id:
                  between: 10,100
        - name: or[group]
          in: query
          style: deepObject
          explode: true
          schema:
            type: object
          description: >-
            OR condition groups. Filters within a group are ANDed; groups are
            ORed.


            **Syntax**: `or[group_key][<attribute>]=value` or
            `or[group_key][<attribute>][operator]=value`


            **Examples**:

            - Simple OR: `or[1][state]=draft&or[2][state]=pending`

            - Complex:
            `or[1][state]=draft&or[1][budget][gte]=50000&or[2][state]=closed`

            - With custom fields:
            `or[1][cf][priority]=high&or[2][state]=pending`


            Group keys can be any string (1, 2, a, b, etc.) - they just need to
            be unique.
          examples:
            simple_or:
              summary: Simple OR
              value:
                '1':
                  external_provider: pending
                '2':
                  external_provider: active
            complex_or:
              summary: Complex OR with AND within groups
              value:
                '1':
                  external_provider: pending
                  client_org_id:
                    gte: '10'
                '2':
                  external_provider: active
        - name: sort[<attribute>]
          in: query
          style: deepObject
          explode: true
          schema:
            type: object
          description: >-
            Sort results by attribute. Direction defaults to ascending.


            **Syntax**: `sort[<attribute>]=` (ascending) or
            `sort[<attribute>]=desc` (descending)


            **Sortable attributes**: ccy, client_org_id, created_at, deleted_at,
            expiry_date, external_id, external_provider, id, po_number, status,
            updated_at, updating, version


            **Examples**:

            - Ascending: `sort[created_at]=` or `sort[created_at]=asc`

            - Descending: `sort[created_at]=desc`
          examples:
            ascending:
              summary: Ascending (implicit)
              value:
                created_at: ''
            descending:
              summary: Descending
              value:
                created_at: desc
      responses:
        '200':
          description: List of purchase_orders
          content:
            application/json:
              schema:
                type: object
                properties:
                  purchase_orders:
                    type: array
                    items:
                      $ref: '#/components/schemas/PurchaseOrder'
              examples:
                success:
                  summary: Successful response with purchase_orders
                  value:
                    purchase_orders:
                      - id: 101
                        client_org_id: 501
                        po_number: Example po_number
                        version: 101
                        status: in_progress
                        updating: true
                        external_provider: Example external_provider
                        external_id: EXT-1001
                        ccy: GBP
                        expiry_date: '2024-01-16'
                        deleted_at: '2024-01-16T10:30:00+00:00'
                        created_at: '2024-01-16T10:30:00+00:00'
                        updated_at: '2024-01-16T10:30:00+00:00'
                        owners:
                          - id: 101
                            ownable_id: 501
                            ownable_type: Project
                            purchase_order_id: 501
                            created_at: '2024-01-16T10:30:00+00:00'
                            updated_at: '2024-01-16T10:30:00+00:00'
                          - id: 102
                            ownable_id: 502
                            ownable_type: Project
                            purchase_order_id: 502
                            created_at: '2024-01-17T10:30:00+00:00'
                            updated_at: '2024-01-17T10:30:00+00:00'
                      - id: 102
                        client_org_id: 502
                        po_number: Example po_number
                        version: 102
                        status: approved
                        updating: true
                        external_provider: Example external_provider
                        external_id: EXT-1002
                        ccy: GBP
                        expiry_date: '2024-01-17'
                        deleted_at: '2024-01-17T10:30:00+00:00'
                        created_at: '2024-01-17T10:30:00+00:00'
                        updated_at: '2024-01-17T10:30:00+00:00'
                        owners:
                          - id: 102
                            ownable_id: 502
                            ownable_type: Project
                            purchase_order_id: 502
                            created_at: '2024-01-17T10:30:00+00:00'
                            updated_at: '2024-01-17T10:30:00+00:00'
                          - id: 103
                            ownable_id: 503
                            ownable_type: Project
                            purchase_order_id: 503
                            created_at: '2024-01-18T10:30:00+00:00'
                            updated_at: '2024-01-18T10:30:00+00:00'
                empty:
                  summary: Empty result set
                  value:
                    purchase_orders: []
                filtered:
                  summary: Filtered results
                  description: Results after applying filters
                  value:
                    purchase_orders:
                      - id: 101
                        client_org_id: 501
                        po_number: Example po_number
                        version: 101
                        status: in_progress
                        updating: true
                        external_provider: Example external_provider
                        external_id: EXT-1001
                        ccy: GBP
                        expiry_date: '2024-01-16'
                        deleted_at: '2024-01-16T10:30:00+00:00'
                        created_at: '2024-01-16T10:30:00+00:00'
                        updated_at: '2024-01-16T10:30:00+00:00'
                        owners:
                          - id: 101
                            ownable_id: 501
                            ownable_type: Project
                            purchase_order_id: 501
                            created_at: '2024-01-16T10:30:00+00:00'
                            updated_at: '2024-01-16T10:30:00+00:00'
                          - id: 102
                            ownable_id: 502
                            ownable_type: Project
                            purchase_order_id: 502
                            created_at: '2024-01-17T10:30:00+00:00'
                            updated_at: '2024-01-17T10:30:00+00:00'
        '401':
          description: >-
            Unauthorized - the access token is missing, expired, revoked or
            malformed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: invalid_token
                error_description: >-
                  The access token provided is expired, revoked, malformed, or
                  invalid for other reasons
        '403':
          description: Forbidden - insufficient scope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: insufficient_scope
                error_description: >-
                  The request requires higher privileges than provided by the
                  access token
                required_scope: purchase_orders:read
                provided_scopes:
                  - welcome:read
        '422':
          description: Invalid filter or sort parameters
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                invalid_attribute:
                  summary: Unknown filter attribute
                  value:
                    error: 'Invalid filter attribute: unknown_field'
                invalid_operator:
                  summary: Invalid operator for type
                  value:
                    error: Operator 'like' is not valid for integer type
                invalid_value:
                  summary: Invalid value format
                  value:
                    error: 'Invalid date format for created_at: not-a-date'
                invalid_sort_attribute:
                  summary: Unknown sort attribute
                  value:
                    error: 'Invalid sort attribute: unknown_field'
                invalid_sort_direction:
                  summary: Invalid sort direction
                  value:
                    error: Invalid sort direction 'random'. Must be 'asc' or 'desc'
      security:
        - oauth2:
            - purchase_orders:read
          tenantId: []
components:
  schemas:
    PurchaseOrder:
      type: object
      properties:
        id:
          type: integer
        client_org_id:
          type: integer
        po_number:
          type: string
        version:
          type: integer
        status:
          type: integer
        updating:
          type: boolean
          example: true
        external_provider:
          type: string
        external_id:
          type: string
        ccy:
          type: string
        expiry_date:
          type: string
        deleted_at:
          type: string
        created_at:
          type: string
        updated_at:
          type: string
        owners:
          type: array
          items:
            $ref: '#/components/schemas/PurchaseOrderOwner'
    Error:
      type: object
      description: Error envelope returned by every non-2xx V4 response
      properties:
        error:
          type: string
          example: insufficient_scope
        error_description:
          type: string
        message:
          type: string
        details:
          type: object
          additionalProperties: true
        required_scope:
          type: string
          example: projects:read
        provided_scopes:
          type: array
          items:
            type: string
    PurchaseOrderOwner:
      type: object
      properties:
        id:
          type: integer
        ownable_id:
          type: integer
        ownable_type:
          type: string
        purchase_order_id:
          type: integer
        created_at:
          type: string
        updated_at:
          type: string
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        OAuth 2.0 client credentials. The access token from POST /oauth/token is
        sent as a bearer token. Request only the scopes you need.
      flows:
        clientCredentials:
          tokenUrl: https://api.zivio.net/api/v4/oauth/token
          scopes:
            bank_accounts:read: Read bank account details on suppliers and the org.
            catalogs:read: Read catalog items.
            cost_centers:read: Read cost center records.
            eoi_responses:read: Read responses to expressions of interest.
            eois:read: Read expressions of interest.
            offers:read: Read offers for projects.
            org_units:read: Read your organization unit hierarchy.
            org_users:read: Read members of your organization.
            resources:read: Read resource (worker) records.
            sales_invoices:read: Read invoices issued to clients.
            sales_milestones:read: Read milestones on sales engagements.
            skill_categories:read: Read the skill category taxonomy.
            skill_taxonomies:read: Read skill taxonomy structure.
            skills:read: Read individual skills.
            supplier_documents:read: Read documents uploaded by suppliers.
            supplier_lists:read: Read curated lists of suppliers.
            supplier_users:read: Read users belonging to supplier organizations.
            tax_types:read: Read configured tax types.
            users:read: Read user profiles.
            variation_orders:read: Read variation orders on projects.
            welcome:read: 'Required: confirms your identity to the application.'
            bid_evaluations:read: >-
              Read evaluation scorecards for bids, including criterion scores
              and quality, cost and total scores.
            bid_evaluations:write: >-
              Score bids against a project's quality criteria and override
              calculated cost scores.
            bids:read: Read bids submitted on projects.
            bids:write: >-
              Shortlist, select, eliminate and reinstate bids submitted on
              projects.
            invoices:read: Read invoices on projects.
            invoices:write: Create and update invoices.
            notes:read: Read notes on projects and EOIs.
            notes:write: Create and update notes on projects and EOIs.
            project_approvals:read: Read project approval workflows.
            project_approvals:write: Create and update project approval workflows.
            project_conversations:read: Read messages exchanged with suppliers on a project.
            project_conversations:write: Send messages to suppliers on a project.
            project_invitations:read: Read supplier invitations on projects.
            project_invitations:write: Invite suppliers to bid on projects.
            project_questions:read: Read supplier clarification questions on projects.
            project_questions:write: Answer and approve supplier clarification questions.
            projects:read: Read projects.
            projects:write: Create and update projects.
            milestones:read: Read milestones on projects.
            milestones:write: Create and update milestones.
            orgs:read: Read organization records.
            orgs:write: Create and update organization records.
            purchase_orders:read: Read purchase orders.
            purchase_orders:write: Create and update purchase orders.
            reviews:read: Read reviews left on suppliers.
            reviews:write: Create and update reviews.
            suppliers:read: Read supplier profiles.
            suppliers:write: Create and update supplier profiles.
            raw_scorecard_entries:write: Create and update raw scorecard entries.
            raw_scorecard_entries:read: Read raw scorecard entries.
            tasks:read: >-
              Read the acting user's task queue, including outstanding approvals
              and items to review.
            tasks:write: Complete and dismiss tasks in the acting user's task queue.
            act_as_user: >-
              Make requests as another user within the token holder's delegation
              boundary.
    tenantId:
      type: apiKey
      name: zivio-tenant-id
      in: header
      description: >-
        Your Zivio organisation identifier. The regional API endpoints serve
        every Zivio organisation, so each request must identify yours.

````