# Integrate the affiliate REST API

Use the supported public contract with app scope, safe retries and exact money.

## What you need

An app-scoped `hcak_` key with the operation’s required scope. Owner dashboard cookie routes are not a substitute for this public contract.

## Steps

1. Create a labeled key in Affiliate Developers, grant only the scopes your integration needs and store it privately.
2. Use base `https://heycrust.com/api/affiliate-platform/v1` and `Authorization: Bearer <key>`.
3. Choose an operation from the [API reference](/docs/api). Lists accept only their supported filters, limit and cursor; reuse a cursor with the same actor/section/filter context.
4. For mutations, send JSON and an `Idempotency-Key` of at most 200 characters. Reuse it only for the same intended request. Request body size is capped at 65,536 bytes.
5. Handle validation/auth/scope/conflict failures explicitly. Respect 429 and `Retry-After`; the authenticated API quota is 120 requests per key per minute.
6. Keep `amountMinor` as exact decimal strings and use the returned currency and its supported settlement precision. Read payout records for state; no public transfer execution operation is advertised.

## Expected result

A supported scoped response, with auditable mutation/replay behavior where applicable. Schema-valid input is not a promise that its business state is eligible.



## Troubleshooting

Check the operation-specific scope, app ownership, ID, filters and current terms/state. Do not guess a write endpoint because a similarly named read exists. Use the separate [Install claim](/docs/developers/install-claims) interface for the install bridge.
