--- updatedAt: 2026-08-16T09:58:39.000Z agentTools: projectIndex: https://docs.rekaz.io/llms.txt --- # Quick start Authenticate and make your first Rekaz public API request. Rekaz uses HTTP Basic authentication. Create an API key in the dashboard to get a Base64 credential and Tenant ID. Use the Base64 value exactly as shown. Do not decode it, edit it, or encode it again. Send all dates and times in UTC. The API also returns them in UTC. ## 1. Create an API key 1. Sign in to the Rekaz dashboard. 2. Open **Settings > API Keys**. 3. Select **Create API key**, enter a name, and create it. 4. Copy the **Base64** credential and **Tenant ID** from the confirmation window. The dashboard shows the Base64 credential only when you create or rotate the key. Store it in a server-side secret manager. Keep it out of frontend code and mobile applications. ## 2. Add the authorization header Set the header to `Basic`, followed by one space and the copied Base64 value: ```http Authorization: Basic YOUR_BASE64_VALUE ``` ## 3. Add the tenant header Every request also needs the tenant header. `__tenant` starts with two underscores: ```http __tenant: YOUR_TENANT_ID ``` ## 4. Make your first request Replace only `YOUR_BASE64_VALUE` and `YOUR_TENANT_ID`: ```bash curl --request GET \ 'https://platform.rekaz.io/api/public/products?skipCount=0&maxResultCount=20' \ --header 'Authorization: Basic YOUR_BASE64_VALUE' \ --header '__tenant: YOUR_TENANT_ID' \ --header 'Accept: application/json' \ --header 'Accept-Language: en' ``` HTTPie: ```bash http GET 'https://platform.rekaz.io/api/public/products?skipCount=0&maxResultCount=20' \ 'Authorization:Basic YOUR_BASE64_VALUE' \ '__tenant:YOUR_TENANT_ID' \ 'Accept:application/json' \ 'Accept-Language:en' ``` A successful response returns HTTP `200` with this shape: ```json { "items": [], "totalCount": 0 } ``` `items` may contain products. An empty array is still a successful response when the tenant has no matching products. ## 5. Create a customer This request writes data. Use a new mobile number each time you test it. ```bash curl --request POST \ 'https://platform.rekaz.io/api/public/customers' \ --header 'Authorization: Basic YOUR_BASE64_VALUE' \ --header '__tenant: YOUR_TENANT_ID' \ --header 'Content-Type: application/json' \ --data '{ "name": "Test Customer", "mobileNumber": "+966501234567", "type": 1 }' ``` A successful response returns HTTP `200`: ```json { "customerId": "NEW_CUSTOMER_UUID" } ``` Phone numbers should use E.164 format, including the leading `+`. ## Troubleshooting | Result | Check | | ------------------ | ------------------------------------------------------------------------------------------------------------------------------ | | `400 Bad Request` | Required fields, date ranges, phone format, and page size | | `401 Unauthorized` | The header starts with `Basic `, uses the copied Base64 value without re-encoding, and the key has not been rotated or deleted | | `403 Forbidden` | The `__tenant` value is correct and belongs to the API key | | `404 Not Found` | The route or resource ID is correct for this tenant | Use HTTPS for every request. Rekaz has no separate public sandbox; use dedicated test records in a tenant set aside for testing. See the [API reference](/legacy/reference/) for other endpoints and [webhooks](/legacy/webhooks) for event notifications.