Skip to content

Authentication ​

Every request carries the key in the Authorization header:

sh
curl https://api.example.com/partner/v1/bookings \
  -H "Authorization: Bearer ugp_…" \
  -H "Accept-Language: en"
  • No session, no cookie, no token exchange. The key is the identity.
  • Do not send x-ug-role: the role is on the key and the header is ignored.
  • Accept-Language: en returns the partner layer's own error messages in English (codes never change).
  • Send X-Request-Id and it comes back unchanged; otherwise the server generates one. Quote it when you contact support.

Calling from a browser ​

The API allows any origin and never accepts cookies. Still, do not put a key into a web page: anyone who opens the page can read it. Use the reference page's "Try it" for experiments only.

Failed authentication ​

A missing, malformed, unknown, revoked or expired key gets the same answer:

json
{
  "message": "The API key is invalid, revoked or expired.",
  "code": "PARTNER_KEY_INVALID"
}