Version 1. Authenticate with Authorization: Bearer <key> or X-API-Key. Production accepts sk_live_ keys; development and test accept sk_test_ keys.
Every key is bound to one organization and explicit scopes. Create operations require Idempotency-Key; successful responses can be replayed for 24 hours, while reuse with a different payload returns 409.
List endpoints accept one-based page and pageSize (maximum 100). Responses expose per-second rate-limit headers; 429 responses include Retry-After. Daily quotas reset at 00:00 UTC.
curl --request GET --url 'https://api.example.test/api/open/v1/short-links?page=1&pageSize=20' --header 'Authorization: Bearer sk_live_example_REDACTED' --header 'X-Request-Id: example-request-id'
Webhook requests include X-Webhook-Id, X-Webhook-Timestamp, X-Webhook-Signature, X-Webhook-Event, and X-Webhook-Attempt. Verify v1=HMAC-SHA256(secret, delivery_id + "." + timestamp + "." + exact_body_bytes) and reject timestamps outside five minutes.
Download the OpenAPI 3.1 document
Loading…