Integrate the affiliate REST API
Use the supported public contract with app scope, safe retries and exact money.
On this page
What you need
An app-scoped hcak_ key with the operation’s required scope. Owner dashboard cookie routes are not a substitute for this public contract.
Steps
- Create a labeled key in Affiliate Developers, grant only the scopes your integration needs and store it privately.
- Use base
https://heycrust.com/api/affiliate-platform/v1andAuthorization: Bearer <key>. - Choose an operation from the API reference. Lists accept only their supported filters, limit and cursor; reuse a cursor with the same actor/section/filter context.
- For mutations, send JSON and an
Idempotency-Keyof at most 200 characters. Reuse it only for the same intended request. Request body size is capped at 65,536 bytes. - Handle validation/auth/scope/conflict failures explicitly. Respect 429 and
Retry-After; the authenticated API quota is 120 requests per key per minute. - Keep
amountMinoras exact decimal strings and use the returned currency and its supported settlement precision. Read payout records for state; no public transfer execution operation is advertised.
Expected result
A supported scoped response, with auditable mutation/replay behavior where applicable. Schema-valid input is not a promise that its business state is eligible.
Troubleshooting
Check the operation-specific scope, app ownership, ID, filters and current terms/state. Do not guess a write endpoint because a similarly named read exists. Use the separate Install claim interface for the install bridge.