Authentication
Every Partner API request is a JSON call to one of two servers, signed with your partner API key. Create your production key in the console; the key never leaves your servers.
Base URLs
| Server | Base URL | Key |
|---|---|---|
| production | https://server.heyprio.com | from your console |
| development | https://server-dev.heyprio.com | from Prio, on request |
The key header
Send the key in the x-partner-api-key header on every request. A missing header returns 401; a key Prio does not know, or a partner that is switched off, returns 403. A user who is not yours returns 404.
Responses
A success returns success: true, a message and the result. An error returns its HTTP status and a message naming the first thing that failed.
| Status | Meaning | When |
|---|---|---|
| 200 | OK | a read, an update or a paid invoice |
| 201 | Created | a user, payment or request was made |
| 400 | Bad Request | a field is missing or invalid |
| 401 | Unauthorized | no x-partner-api-key header |
| 403 | Forbidden | unknown key, or partner switched off |
| 404 | Not Found | the user or invoice is not yours |
| 409 | Conflict | the email or phone is taken |
| 422 | Unprocessable | Prio could not send the payment |
Sandbox
The development server, https://server-dev.heyprio.com, takes a separate development key that Prio issues on request, and its data is not production’s. The key your console issues works only on https://server.heyprio.com.