Skip to main content
Kravata assigns API credentials (apiKey and secretKey) to accepted customers after the onboarding and compliance review. You exchange them for a temporary access token and send that token in every request.

Get an access token

Call Client Login with your credentials.
The response contains the token (accessToken) and its validity in seconds (expiresIn). Store the token and reuse it until it expires instead of requesting a new one for every call.

Authenticate your requests

Send the token in the Authorization header of every other request:
When the token expires the API responds with 401. Request a new one with the same endpoint.

Production access: mTLS and IP allowlist

For security, the production domain partners-api.kravata.co only accepts connections that present the client certificate issued by Kravata for your company, coming from IP addresses you have registered.
1

Request your mTLS certificate

Ask your Kravata point of contact for your client certificate (client.crt) and private key (client.key). Store the private key securely: anyone with it and your API credentials can connect as your company.
2

Present the certificate in every request

Configure your HTTP client to send the certificate and key on every production request, including the token request. Connections without a valid certificate are closed during the TLS handshake, before reaching the API.
3

Register your IP allowlist

Call Update IP Allowlist with the IP ranges of your servers, in CIDR notation. Once a list is registered, requests from any other IP are rejected.
The list you send replaces the current one. Always include the IP you are calling from: if it is not in the new list, your next requests are rejected, including calls to update the list. Sending an empty list ([]) blocks all IPs. If you lock yourself out, contact Kravata to restore access.

Using the certificate in your HTTP client

In Postman, add the certificate in Settings → Certificates → Add certificate for host partners-api.kravata.co.
The interactive playground in this documentation cannot present a client certificate, so use it against the test environment. For production, use your own backend, curl or Postman with the certificate configured.
Call the API only from your backend. Your apiKey, secretKey, certificate private key and access tokens must never reach a browser or a mobile app.