Authentication
Every request carries one credential. Which one depends on the API:
| API | Credential | Sent as |
|---|---|---|
Public, /v1/public/* |
A website key | Tp-Publishable-Key: tp_pk_… |
| Public, a signed-in traveller | The website key and the traveller’s session | The key, and the session cookie as the API set it |
Seller, /v1/* |
A secret key | Authorization: Bearer tp_sk_… |
| Seller, in the portal | A staff session | The portal’s own cookie |
Which key to use explains the two kinds of key.
Over HTTPS, from your server or your site
Section titled “Over HTTPS, from your server or your site”All requests go to https://api.stg.vacationpackagesoman.com over HTTPS.
From your server or your site’s build, a website key always works. From a
visitor’s browser, it works only on the addresses (origins) its site lists
in the portal, under API keys, Website keys. A browser on any other
address is refused at the preflight, or with 403 OriginNotAllowed, which
names the refused origin.
Missing or wrong
Section titled “Missing or wrong”A missing, unknown or revoked credential is 401 Unauthenticated:
curl "https://api.stg.vacationpackagesoman.com/v1/public/products" \ -H "Tp-Publishable-Key: $TP_KEY"const res = await fetch("https://api.stg.vacationpackagesoman.com/v1/public/products", { headers: { "Tp-Publishable-Key": process.env.TP_KEY!, },})const answer = await res.json()Answer: 401 Unauthorized
{ "type": "about:blank", "title": "Unauthorized", "status": 401, "code": "Unauthenticated", "detail": "Send the storefront's publishable key as `Tp-Publishable-Key: tp_pk_…`."}A secret key whose role or scopes lack what an endpoint needs is
403 NotPermitted, with the permission missing and the reason.
The key sets the scope
Section titled “The key sets the scope”The seller, the site, its languages and its currencies come from the credential, never from a parameter. A request can’t widen what its key sees, and you never send a seller’s id.