Base URL and authentication
Base URL and format
-
Test environment:
https://api-test.defraudo.com. Production hosts are issued with your account. -
JSON in, JSON out,
Content-Type: application/json. The default request body limit is 1 MiB;POST /v1/fp/collectis capped at 64 KiB (413). -
Every response uses one envelope:
{ "status": 1, "data": { ... }, "errors": [] }{ "status": 0, "data": null, "errors": [{ "code": "...", "message": "...", "parameter": "..." }] }The first line is success, the second failure.
-
Every response carries
x-request-id. Send your own well-formedx-request-idto have it echoed, and quote it when contacting support.
Authentication
Send the key as a bearer token:
Authorization: Bearer ak_live_xxxxxxxxxxxxxxxxxxxxxx
A key looks like <kind>_<environment>_<22 characters>:
| Prefix | Kind | Where it may live |
|---|---|---|
ak_live_ / ak_sandbox_ | Secret key, holds every scope | Your backend only |
pk_live_ / pk_sandbox_ | Publishable key, holds fp:write only | Page HTML; can only call POST /v1/fp/collect |
The key resolves the tenant and project, so event calls need no project id (exception: GET /v1/cases requires a project_id query parameter matching the key's project). A sandbox key resolves only to the sandbox project. Each key has an explicit scope list (events:write, fp:write, accounts:link, scores:read, accounts:read, accounts:erase, cases:read, cases:write, rules:read, rules:write, rules:publish); a route outside the key's scopes answers 403 SCOPE_ERROR.