API key
Keys are issued by the UstaGeliyor operations team; there is no self-service. When you ask for one, tell us:
- The account the key acts as (the phone number of your UstaGeliyor customer or usta account). Every call made with the key acts as that account.
- The role:
customer(the side that books) orusta(the side that does the work). A key carries one role; ask for two keys to use both. - The scopes:
read,write,money— see Roles and scopes. - Optionally an expiry date and a per-minute quota.
A key starts with ugp_ followed by 64 hex characters:
ugp_3f9a1c0e…(64 characters)The secret is shown once
UstaGeliyor stores only the key's SHA-256 digest. A lost key cannot be recovered: have it revoked and ask for a new one. Never embed a key in client code (mobile app, browser) — keep it on your server.
Revocation and expiry
A revoked or expired key gets 401 PARTNER_KEY_INVALID on its next call. If the account loses its usta role, an usta key gets 403 PARTNER_ROLE_UNAVAILABLE.