# API reference

Public HTTP contracts, credentials, app scopes and exact financial values.

## Public affiliate API

The public affiliate REST base is `https://heycrust.com/api/affiliate-platform/v1`. Use an app-scoped affiliate API credential with the permissions required by the operation. Program, membership, referral, commission, bonus and payout operations are supported by this contract.

## Other integration interfaces

Identification, backend events, browser tracking, Shopify uninstall forwarding and signed affiliate install claims have separate request and authentication contracts. A cookie-authenticated dashboard route is not automatically part of the external affiliate REST API.

## Money and dates

Money objects carry a currency and a minor-unit integer string. Do not combine currencies or assume every currency has two decimal places. Use the date format and filters accepted by the operation; cohort report boundaries are UTC instants with inclusive start and exclusive end.

## Errors and permissions

Inspect the response status and body. Missing or revoked credentials are different from a credential lacking the required app or operation scope. Validation, conflict, incomplete-source, review and rate-limit responses need different recovery actions.

## Continue

Use [Developer integration](/docs/developers) for setup and [MCP](/docs/mcp) for the JSON-RPC tool interface.
