API Access and Authentication
SPREEAI provides a public API reference for approved partner workflows: https://docs.spreeai.com/swagger/public/.
Access model
API scope, environment, credentials, and allowed operations are agreed during partner onboarding. Do not assume that an internal, development, or historical endpoint is available in production.
Credential rules
- Store client secrets and access tokens only in a secure server-side secret store.
- Never commit credentials to Git, documentation, issue trackers, screenshots, or sample applications.
- Never send credentials to analytics or logging platforms.
- Use environment-specific credentials only with the environment for which they were issued.
- Rotate a credential immediately if it is exposed.
- Redact authorization headers and tokens from support requests.
Browser versus server
The Web SDK uses partner-issued browser configuration. A client secret must not be included in the browser.
Server-side integrations should follow the authentication flow and endpoint definitions in the current approved API reference. When a needed operation is absent, request it through Partner Engineering instead of constructing an undocumented route.
Webhooks
Server-push webhooks are not part of the currently published Web SDK documentation. Confirm any webhook requirement before designing a dependency on it.
Environment checklist
- [ ] The environment name is documented.
- [ ] The base URL came from the approved reference or onboarding handoff.
- [ ] Credentials were issued for that environment.
- [ ] Secrets are stored server-side.
- [ ] Logs redact tokens and customer imagery.
- [ ] Timeouts, retries, and idempotency behavior have been agreed for write operations.
- [ ] A non-production test succeeds before production access is used.