1. Getting Started
CIAO API
  • Getting Started
    • Introduction
    • Authentication
    • Responses and Error
  • Partners
    • Webhooks
    • Redemption Intent (Partners)
      • Create Redemption Intent
      • Retrieve Redemption Intent
    • Subscriptions
      • Create Subscription
      • Retrieve a subscription
      • Cancel Subscription
  • Resellers
    • Webhooks
    • Voucher Generation (Resellers)
      • Create Voucher Payment
      • Retrieve Voucher Payment
  • General
    • Get all Counties
      GET
  1. Getting Started

Authentication

All API requests require a bearer token in the Authorization header:
Authorization: Bearer sk_live_xxxxxxxx

API keys#

PrefixEnvironmentEntity
sk_live_...LivePartner or Reseller (depends on the key issued)
sk_test_...TestPartner or Reseller (depends on the key issued)
The key prefix selects the environment automatically.
The key type selects the entity. Partner endpoints reject reseller keys and vice versa
(401 Unauthenticated).
Keys are matched by SHA-256 hash. Inactive entities are rejected.
Repeated invalid authentication attempts are rate-limited: 5 failures per 60 seconds → 429.

Example#

Security#

Store keys securely. Never expose them in client-side code or public repositories.
Use test keys during development; switch to live keys only in production.
Modified at 2026-07-21 11:59:45
Previous
Introduction
Next
Responses and Error
Built with