REST API Base Endpoint
/v1 segment is part of every public service URL.
URL format and API version
Every service path is appended to the same versioned base endpoint:Common request headers
The runtime accepts
dev or development for Development, and prod or production for Production. Credentials and environment are resolved together: changing X-ENV does not turn a Development credential into a Production credential.
X-Privacy-Mode
X-Privacy-Mode is an optional privacy control for an individual API request. Send a truthy value such as 1 when the request contains data that should not be retained in normal observability payload logs.
Common response behaviour
JSON provider operations use AvraAPI response envelopes. A successful operation includessuccess, request_id, and its operation-specific data. Error responses include success: false, request_id, a stable error.code, and a readable error.message. Some infrastructure errors also include meta; do not depend on meta being present for every operation-level validation error.
The X-APIX-Request-ID response header mirrors the request identifier. Keep it when troubleshooting an API issue. Rate-limited operations return 429 and may include Retry-After; wait for that period instead of retrying in a tight loop.
Media operations are documented separately because they can return image or PDF content instead of JSON. Their exact request and response media types are defined on the relevant Utilities pages.
Live Testing Guide: Before using Try it, create a Development project, then enter its Client ID and Client Secret. Configure the relevant provider for that project before sending the request.
Error-code reference
Handle every non-2xx response by HTTP status and error.code. Keep the request_id with your application logs and support request; it is also returned in the X-APIX-Request-ID header.
Typical JSON error envelope
meta is optional. In particular, directly validated operations can return a more specific error.details object instead.
Common platform errors
These codes are produced by the shared API middleware, the common exception renderer, or the Gateway request runtime. They can occur across more than one provider service.Operation-specific errors
Some operations expose additional stable errors because they have their own input or service rules. Their endpoint page is the source of truth for those codes and response details.Some exception names are used internally for observability or billing decisions but are not independently published as stable HTTP
error.code values. This reference intentionally documents only codes that the public API contract can return to an integration.