Skip to main content

Base URL and authentication

Base URL and format​

  • Test environment: https://api-test.defraudo.com. Production hosts are issued with your account.

  • JSON in, JSON out, Content-Type: application/json. The default request body limit is 1 MiB; POST /v1/fp/collect is capped at 64 KiB (413).

  • Every response uses one envelope:

    { "status": 1, "data": { ... }, "errors": [] }
    { "status": 0, "data": null, "errors": [{ "code": "...", "message": "...", "parameter": "..." }] }

    The first line is success, the second failure.

  • Every response carries x-request-id. Send your own well-formed x-request-id to have it echoed, and quote it when contacting support.

Authentication​

Send the key as a bearer token:

Authorization: Bearer ak_live_xxxxxxxxxxxxxxxxxxxxxx

A key looks like <kind>_<environment>_<22 characters>:

PrefixKindWhere it may live
ak_live_ / ak_sandbox_Secret key, holds every scopeYour backend only
pk_live_ / pk_sandbox_Publishable key, holds fp:write onlyPage HTML; can only call POST /v1/fp/collect

The key resolves the tenant and project, so event calls need no project id (exception: GET /v1/cases requires a project_id query parameter matching the key's project). A sandbox key resolves only to the sandbox project. Each key has an explicit scope list (events:write, fp:write, accounts:link, scores:read, accounts:read, accounts:erase, cases:read, cases:write, rules:read, rules:write, rules:publish); a route outside the key's scopes answers 403 SCOPE_ERROR.