Get started / GiftU Partner API
Authentication & environments
Authenticate every request with your partner API key. The key determines both account scope and environment.
Bearer authentication
Send Authorization: Bearer <PARTNER_API_KEY> with every request. Keep keys on trusted servers and in private secret stores. Never embed a key in browser code, a mobile app, a URL, or a shared collection.
Authorization: Bearer <PARTNER_API_KEY>
Accept: application/jsonTEST and LIVE
pk_test_ selects TEST; pk_live_ selects LIVE. Catalog access, orders, financial movements, and statements are scoped to that mode. TEST produces synthetic fulfillment and does not buy real vendor cards. A TEST key cannot access LIVE resources.
Network policy
GiftU can enforce an outbound IP allowlist in addition to the API key. In that mode, an empty allowlist denies access. Some deployments use API-key-only authentication. Confirm the active policy during onboarding; a successful ping verifies your access under that policy.
Authentication failures
Invalid or revoked keys, inactive partners, unavailable modes, and network-policy failures share HTTP 401 / code 6200. Recheck the key and account configuration with GiftU. Do not retry an authentication failure in a tight loop.