Skip to content

Authentication

Send your API key as the user and its secret as the password, with HTTP Basic authentication. It is the same scheme Stripe uses, so every HTTP client already supports it and you can try a call with curl before writing any code.

Terminal window
curl -u "$COURIER_KEY:$COURIER_SECRET" "$COURIER_API/v1/jobs"
  • Who you are. Every request acts for the merchant the key belongs to. There is no merchant parameter: you can only ever see and book your own deliveries.
  • Which environment. ck_test_ keys reach the sandbox and ck_live_ keys the live platform — see Sandbox and API keys.

A missing or wrong credential is answered with 401 Unauthorized and a WWW-Authenticate: Basic header. An unknown key and a wrong secret get the same answer on purpose, so the response never tells anyone which half they got right.

Always call over HTTPS. Basic credentials are only encoded, not encrypted, so they must never travel over plain HTTP.