Authentication
این محتوا هنوز به زبان شما در دسترس نیست.
Send your API key as the user and its secret as the password, with HTTP Basic authentication. It is the same scheme Stripe uses, so every HTTP client already supports it and you can try a call with curl before writing any code.
curl -u "$COURIER_KEY:$COURIER_SECRET" "$COURIER_API/v1/jobs"const response = await fetch(`${process.env.COURIER_API}/v1/jobs`, { headers: { Authorization: 'Basic ' + Buffer.from(`${process.env.COURIER_KEY}:${process.env.COURIER_SECRET}`).toString('base64'), },})import os, requests
response = requests.get( f"{os.environ['COURIER_API']}/v1/jobs", auth=(os.environ["COURIER_KEY"], os.environ["COURIER_SECRET"]),)var credentials = Convert.ToBase64String(Encoding.UTF8.GetBytes($"{key}:{secret}"));http.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Basic", credentials);var response = await http.GetAsync($"{api}/v1/jobs");What the key decides
Section titled “What the key decides”- Who you are. Every request acts for the merchant the key belongs to. There is no merchant parameter: you can only ever see and book your own deliveries.
- Which environment.
ck_test_keys reach the sandbox andck_live_keys the live platform — see Sandbox and API keys.
When it fails
Section titled “When it fails”A missing or wrong credential is answered with 401 Unauthorized and a WWW-Authenticate: Basic header.
An unknown key and a wrong secret get the same answer on purpose, so the response never tells anyone which
half they got right.
Always call over HTTPS. Basic credentials are only encoded, not encrypted, so they must never travel over plain HTTP.