apiKey and secretKey) to accepted customers after the onboarding and compliance review. You exchange them for a temporary access token and send that token in every request.
Get an access token
Call Client Login with your credentials.accessToken) and its validity in seconds (expiresIn). Store the token and reuse it until it expires instead of requesting a new one for every call.
Authenticate your requests
Send the token in theAuthorization header of every other request:
401. Request a new one with the same endpoint.
Production access: mTLS and IP allowlist
For security, the production domainpartners-api.kravata.co only accepts connections that present the client certificate issued by Kravata for your company, coming from IP addresses you have registered.
1
Request your mTLS certificate
Ask your Kravata point of contact for your client certificate (
client.crt) and private key (client.key). Store the private key securely: anyone with it and your API credentials can connect as your company.2
Present the certificate in every request
Configure your HTTP client to send the certificate and key on every production request, including the token request. Connections without a valid certificate are closed during the TLS handshake, before reaching the API.
3
Register your IP allowlist
Call Update IP Allowlist with the IP ranges of your servers, in CIDR notation. Once a list is registered, requests from any other IP are rejected.
Using the certificate in your HTTP client
partners-api.kravata.co.
The interactive playground in this documentation cannot present a client certificate, so use it against the test environment. For production, use your own backend, curl or Postman with the certificate configured.

