Skip to content

Supplier Portal

The supplier portal is a small area a supplier reaches with their own credential, to see the purchase orders you have raised for them, what has happened to their bills, what you have paid, and to send you an invoice.

It is deliberately narrow. A supplier can look at their own records and send you a document. Nothing else.

Issuing, rotating and revoking a credential needs procurement:manage_suppliers or finance:manage_settings. Accepting or declining what a supplier sends needs procurement:manage_bills. Minting a link for a purchase order needs procurement:manage_pos.

Suppliers gain access only after you issue a credential. Open Finance → Supplier access → Credentials, choose the supplier and contact email, select the billing entities and permitted actions, then issue the credential. Copy the displayed code and share it securely with that contact. The supplier can also request a one-time sign-in link using that recorded email address.

A link you send with a document and a supplier’s access to the portal are two different things, and they do not meet.

A document linkA supplier credential
Stands forOne document, at one versionA supplier’s relationship with you
Comes fromSending or sharing that documentA person issuing one deliberately
ReachesThat document onlyThe portal, inside its scope
Lives for90 days for an invoice, a year for a purchase orderUp to three years, and can be rotated or revoked

A purchase order link cannot be used to sign in to the portal, and a portal session cannot be used to open a document link. A forwarded link never becomes standing authority over everything a supplier has been sent.

A credential is scoped when you issue it: to your organisation, to one supplier, to the billing entities you name, and to the actions you name. The action list is four entries and nothing else:

  • view purchase orders
  • view bills
  • view remittances
  • upload an invoice

There is no approve, pay, receive or change-bank-details action, and there is no setting that adds one. Those are not refusals a supplier runs into; they are surfaces that do not exist on this side.

The secret is shown once, when the credential is issued and again if you rotate it. Runnit stores only a fingerprint of it, so nobody, including you, can read it back afterwards.

  • Rotate issues a new credential with the same scope, revokes the old one and ends its live sessions in one step. There is no moment when both work.
  • Revoke takes effect on the supplier’s next request, not at the end of whatever session they have open.
  • Expiry is a date on the credential.
  • Five wrong attempts lock a credential for fifteen minutes, and the right secret fails while it is locked.

Every refusal looks the same from outside. Unknown, wrong, revoked, expired, locked and belonging to another organisation are indistinguishable, so nobody can use the sign-in page to learn which suppliers you buy from.

A credential is exchanged for a short session, an hour by default. Using a session does not extend it, so a session cannot be kept alive by replaying it.

Their viewWhat it holds
Purchase ordersNumber, state, version, order date, expected delivery, currency and total, and whether the document is ready to download
One purchase orderThe above plus your terms, your entity’s name, address, email and tax identifier, and the lines with quantity, unit, unit price and amounts
BillsYour reference, their own invoice number, state, bill date, due date, currency, total and tax
RemittancesWhen you paid, by what method, the reference, the amount, and which of their bills it settled
Their uploadsWhat they sent, when, its acknowledgement reference and what has happened to it

Each view is built from a fixed list of fields rather than by hiding parts of an internal record, so a field added to Runnit later cannot appear here by accident.

Never visible: what you sell the work for, markup, margin, internal notes, who approved something or whether it is waiting on an approval, accounting or payment provider detail, the budget or project behind an order, the client the work is for, and anything belonging to another supplier.

Internal states are collapsed to what a supplier can act on. A purchase order reads as open, receipted, closed or cancelled, and drafts, quote requests and anything waiting on approval are not visible at all. A bill reads as in review, approved, part paid, paid, disputed or void, and a draft bill is not listed.

The supplier uploads a PDF, PNG, JPEG or WEBP file, up to 15 MB. They get an acknowledgement reference back as evidence it arrived. Sending the same file twice is the same upload with the same reference, not two.

Runnit works out what the document belongs to, not the supplier. The supplier is whoever the session says they are, and a purchase order they name is re-resolved against what that credential may see. Nothing they send can widen what they reach or attach a file anywhere they choose.

Runnit may then read the document and propose the invoice number, dates, currency, totals and individual lines. That reading runs as the person who issued the credential, inside a restricted lane that can only read the document and propose fields.

Someone with procurement:manage_bills then accepts or declines it:

  • Accept creates a draft supplier bill with the uploaded document attached, which then goes through the ordinary matching, approval and payment path. Accepting twice returns the same bill.
  • Decline records a reason and closes the upload.

With the cost lens, Make draft bill opens a review of the invoice. Open the original file, choose the billing entity, check the currency and dates, and review each description, quantity and gross line amount. Gross amounts include tax and apply to the whole line; quantity does not multiply them. Select a purchase tax treatment for every line, or No tax after checking the invoice. You can add or remove lines, up to 200. Confirm Make draft bill, then use Open draft bill to continue matching and approval in Purchasing.

Missing dates, currency, amounts or tax treatment need review before a draft can be created. Without the cost lens, complete untaxed proposals can be accepted, but their amounts remain hidden. Ask someone with the cost lens to review incomplete or taxable proposals.

The supplier receives a status email at the recorded contact address if their access is still current. Acceptance means a draft is in review; it does not mean approval or payment. A decline email excludes your internal reason. Suppliers can also see the outcome in their upload history.

Select an order number to read its lines, totals and terms. Download PDF saves the issued document. If it is still being prepared, wait a moment and try again. Access stays restricted to the signed-in supplier; signing out clears that supplier’s records from the page. On smaller screens, scroll inside a table to reach its remaining columns.

An issued purchase order can be given a link the supplier opens without signing in. It shows the document and its PDF, and it does not reach anything else. If the link is lost, Runnit can mint a fresh one for the supplier contact it resolves itself, once per cooldown, and never for an address somebody types into the request.

A recovery request emails the current link and issued PDF to the supplier’s recorded contact, subject to a 15-minute cooldown. A revoked link cannot restore access. If the email does not arrive, check with your contact before requesting another. A queued or accepted email is not a guarantee of delivery.

On the supplier sign-in page, enter the email used for your access and choose Email me a sign-in link. The page gives the same response whether or not an address has access. A current credential receives a link usable once, for up to 30 minutes. If you work with several agencies, each link opens only the agency and supplier access it names. Requests are limited to one per credential every 15 minutes, with at most 20 current grants considered for an address.

Recovery does not change your code, permissions or access expiry. Revoked, expired, locked or archived access cannot be recovered this way. Ask your agency contact to review access if you still cannot sign in.

Match and approve what arrives: Purchasing, or issue the invoice yourself on the supplier’s behalf with Self-Billing.