Skip to main content

Authentication

API Key​

All supported partner contract requests must include the x-partner-key header:

x-partner-key: YOUR_PARTNER_API_KEY

During a planned key rotation, DigiWedge may temporarily accept both the current key and a staged next key. Treat both values as secrets and use only the key supplied through the onboarding or rotation channel.

Missing or invalid keys return:

{
"message": "Invalid partner API key",
"error": "Forbidden",
"statusCode": 403
}

Auth Scope​

  • Authenticated: /api/v1/pos/partners/*
  • Unauthenticated: /api/health/ready, /api/health/live

Legacy Compatibility​

Legacy /pos/* and /transactional/* routes remain available for compatibility, but they are not the supported Trident Phase 1 integration path for new partner work.

Operational Note​

Partner requests are rate-limited at the API edge/runtime boundary. DigiWedge may rotate keys without downtime by temporarily accepting a staged next key.