Authentication
API Key
All supported partner contract requests must include the x-partner-key header:
x-partner-key: YOUR_PARTNER_API_KEY
During a planned key rotation, DigiWedge may temporarily accept both the current key and a staged next key. Treat both values as secrets and use only the key supplied through the onboarding or rotation channel.
Missing or invalid keys return:
{
"message": "Invalid partner API key",
"error": "Forbidden",
"statusCode": 403
}
Auth Scope
- Authenticated:
/api/v1/pos/partners/* - Unauthenticated:
/api/health/ready,/api/health/live
Legacy Compatibility
Legacy /pos/* and /transactional/* routes remain available for compatibility, but they are not the supported Trident Phase 1 integration path for new partner work.
Operational Note
Partner requests are rate-limited at the API edge/runtime boundary. DigiWedge may rotate keys without downtime by temporarily accepting a staged next key.