Authentication
Every request needs an API key. There is no OAuth flow and no token exchange — the key is the credential.
Sending the key
Section titled “Sending the key”Use a bearer header:
curl https://api.1up.gift/me \ -H "Authorization: Bearer 1up_live_a1b2c3..."An X-Api-Key header is also accepted, for clients that cannot set Authorization:
curl https://api.1up.gift/me \ -H "X-Api-Key: 1up_live_a1b2c3..."Send one or the other, not both. A request with no key, or an unrecognised key, gets
401 Unauthorized.
Getting a key
Section titled “Getting a key”Keys are issued in 1UP under Settings → API keys, by anyone with an admin role on your account.
A key is created against a service account and an environment:
- The service account is who the API acts as. Every order placed with the key is attributed to it in reporting, and the funding accounts it can draw from are the ones assigned to it. Service accounts cannot sign in to the 1UP web app — they exist only to call the API.
- The environment is production or staging. A staging key will never authenticate against production, or the other way around. See Environments.
The key is shown once, at creation. 1UP stores only a hash of it, so a lost key cannot be recovered — issue a new one and delete the old.
Rotating a key
Section titled “Rotating a key”Keys do not expire. To rotate:
- Issue a second key against the same service account.
- Deploy it.
- Confirm the new key is being used — each key records when it was last seen, shown on the API keys page.
- Delete the old key.
Deleting a key takes effect immediately; in-flight requests using it will start failing with 401.
What a key can reach
Section titled “What a key can reach”A key is scoped to the customer it was issued to, so every endpoint returns only your data — your products, your templates, your orders. There is no way to widen that scope from the API.
The API itself is available on the Pro plan and above. On other plans, an otherwise-valid key gets
402 Payment Required.
