Skip to main content

Authentication

Public integration endpoints use an API key. Include it in every request using the X-API-Key header.

X-API-Key: YOUR_API_KEY

Create and manage keys in Merchant Portal → Integrations → API. Give each integration and environment its own key, select only the scopes it needs, and optionally set an expiry date. A new or rotated secret is displayed once; Remy stores only a one-way hash and cannot show the secret again.

API keys are linked to one Remy merchant. Keep keys on your server, store them in a secret manager or environment variable, and never expose them in browser code or commit them to source control. Revoke a key immediately in the merchant portal if it may have been exposed.

Use the authentication endpoint to test a key:

curl "https://api.remyrewards.co.uk/v1/public/auth" \
-H "X-API-Key: YOUR_API_KEY"

A missing or invalid key returns an error response. Remy also requires clients to send a User-Agent; standard HTTP libraries do this automatically.

Existing Zapier signing keys remain valid for their historical order-creation and reward-coupon-update operations during the migration to dedicated API keys. They do not grant access to the rest of the Developer API. Zapier and the Developer API are separate integration cards in the merchant portal.