Authentication
Every request carries the key in the Authorization header:
sh
curl https://api.example.com/partner/v1/bookings \
-H "Authorization: Bearer ugp_…" \
-H "Accept-Language: en"- No session, no cookie, no token exchange. The key is the identity.
- Do not send
x-ug-role: the role is on the key and the header is ignored. Accept-Language: enreturns the partner layer's own error messages in English (codes never change).- Send
X-Request-Idand it comes back unchanged; otherwise the server generates one. Quote it when you contact support.
Calling from a browser
The API allows any origin and never accepts cookies. Still, do not put a key into a web page: anyone who opens the page can read it. Use the reference page's "Try it" for experiments only.
Failed authentication
A missing, malformed, unknown, revoked or expired key gets the same answer:
json
{
"message": "The API key is invalid, revoked or expired.",
"code": "PARTNER_KEY_INVALID"
}