The Sparqle API authenticates requests with an API key sent in the api-key
HTTP header.
Each key is scoped to one environment and to the companies it was issued for. It
can act on any location belonging to those companies, and no others.
Sparqle supplies the API key for your integration — it is not something you
create or retrieve from the dashboard. Contact your Sparqle account manager, or
[email protected], to receive a key for the test
and/or live environment. If you lose a key, ask us to issue a replacement and
revoke the old one.
Treat your API key like a password. Never embed it in client-side code, mobile
apps, or public repositories. Make all Sparqle API calls from your backend.
Test vs. live keys
You get a separate key per environment. A test key only works against the test
base URL, and a live key only works against the live base URL. See
Environments for the URLs.
What a key can reach
A key is valid only on the endpoints listed under API
Reference. Any other endpoint returns 401 Unauthorized, even with a valid key.
Failed authentication
A missing, malformed, or revoked key returns 401 Unauthorized. Using a valid
key against a locationId, order, or label belonging to a company it wasn’t
issued for returns 403 Forbidden. See Errors for the full list.