TransaktDocs
API reference

API reference

The product API, generated from its OpenAPI document.

The product API is served on the api host (for this site's environment, https://api.test.konsolutelab.uk) under /api/v1. It answers your applications about your customers' entitlements and your catalogue, and takes metered usage. Every call runs in your partner workspace, resolved from the credential: the same URL never answers about another partner's products or customers.

Authentication

Send one of:

CredentialHeader
Entra application (preferred)Authorization: Bearer <client-credentials token for api://{apiAppId}> with the matching app role
API keyX-Api-Key: transakt_{env}_{keyId}_{secret}
Acting for a signed-in userThe user's delegated token (scope Entitlement.Read), with the API key or from a verified Entra application
EndpointsAPI client scopeApp role (Entra tokens)
Entitlements and eligibilityentitlements:readEntitlement.Read.All
Cataloguecatalogue:readCatalogue.Read.All
Metered usageusage:writeUsage.Write.All

An Entra token needs both the API client's scope and the app role. Any refused credential answers 401 auth.credentials_invalid without saying which part failed; see Getting started.

Conventions

  • JSON with camelCase names; enumeration values are PascalCase strings; timestamps are UTC (2026-10-01T09:30:00.000Z); nullable members are always present.
  • Additive changes only within /api/v1: ignore unknown members, tolerate unknown enumeration values (an unknown licenceOutcome is Unconfirmed, an unknown accessLevel the most restrictive) and handle unknown error codes by their HTTP status. A breaking change becomes /api/v2, with at least 12 months' notice; deprecations are announced with Deprecation and Sunset headers.
  • Rate limits are per API client within your plan's quota. Responses carry RateLimit-Policy and RateLimit headers; a rejection is 429 request.rate_limited with Retry-After.
  • Caching: read endpoints return an ETag; revalidate with If-None-Match for a 304.
  • Errors are problem details with a stable code.

The OpenAPI document is served at /openapi/product.json on the API host, so you can generate a client from it.

On this page