Skip to main content

Base URL

All Partner API requests use the following base URL:

Authentication

Include your API key in the x-contro-api-key header:
Never expose your API keys in client-side code or public repositories.

Request format

  • All request bodies must be JSON with Content-Type: application/json
  • Path parameters are denoted by {id} in endpoint paths
  • Query parameters are used for filtering and pagination

Response format

Successful responses return the requested resource or a success indicator:
List endpoints return paginated results:

Pagination

List endpoints support page-based pagination with two query parameters: Increment page to walk through results. You have reached the end when page * limit >= total.

Rate limiting

The Partner API allows 1,000 requests per minute per API key. When exceeded:
  • Response status: 429 Too Many Requests
  • The Retry-After header indicates seconds to wait before retrying

Errors

All errors return a consistent format:
See the errors guide for troubleshooting details.

Resources

Authentication

API key setup and security best practices

Quickstart

Issue your first card in 5 steps

Webhooks

Real-time event notifications

Errors

Error codes and troubleshooting