API keys

API keys authenticate your server to the NU Signal Partners API. After a partner application is approved, you can issue, rotate, and revoke keys directly through API endpoints without a web console.

Get the first key (bootstrap)

After approval, call POST /partner-applications/claim with the application status credentials to receive a one-time approval token (prefix nsp_appr_, valid for 72 hours). Because no API key exists yet, only this endpoint is public and gated by that token. Exchange it for the first Sandbox key:

curl -X POST https://signal-partners.newunivers.ai/v1/api-keys/bootstrap \
  -H "Content-Type: application/json" \
  -d '{ "approval_token": "nsp_appr_..." }'

{
  "data": {
    "api_key_id": "ak_...",
    "key_prefix": "nsp_test_4f2a1b3c",
    "environment": "sandbox",
    "scopes": ["catalog:read", "license:read", "..."],
    "status": "active",
    "secret": "nsp_test_xxxxxxxx"
  }
}

The approval claim and bootstrap token are each consumed on success. A second call returns 401 invalid_approval_token. If the token is lost, ask NU to reissue it. The bootstrap key includes administrative scopes so it can create narrower integration keys. Keep at least one server-side management key with api_keys:write; Production runtime keys generally should not have key-management scopes.

API key endpoints

Method and pathRequired permissionPurpose
POST /v1/api-keys/bootstrapApproval tokenPublic — issue the first Sandbox key from an approval token.
GET /v1/api-keysapi_keys:read or api_keys:writeList keys; secrets are never returned.
POST /v1/api-keysapi_keys:writeCreate another key. Production requires an ACTIVE Production deal with production_api_enabled: true; otherwise it returns license_not_active.
PATCH /v1/api-keys/{id}api_keys:writeUpdate scopes, allowed_origins, or allowed_ips.
POST /v1/api-keys/{id}/rotateapi_keys:writeIssue a replacement and revoke the old key.
DELETE /v1/api-keys/{id}api_keys:writeRevoke a key.

Sandbox and Production keys

SandboxProduction
Prefixnsp_test_nsp_live_
Base URLhttps://signal-partners.newunivers.ai/v1https://signal-partners.newunivers.ai/v1
DataIsolated dummy catalog (isSandbox)Real catalog, deals, and revenue
PlaybackNo license requiredACTIVE license deal required
SettlementsNo access to real financial statementsRead and dispute settlements

Environments are isolated by key prefix, catalog visibility, sessions, logs, and data. nsp_test_ selects Sandbox and nsp_live_ selects Production. Every request runs in the environment encoded in its key.

Secrets are shown once

The full secret is returned exactly once when the key is created. NU stores only a hash and cannot show it again. Copy it immediately to a secrets manager. If lost, revoke it and create a new key.

Status

StatusMeaning
ACTIVEAvailable for use.
REVOKEDManually disabled. Calls return 401 api_key_revoked.
EXPIREDExpired. Calls return 401 invalid_api_key.

Rotation

POST /v1/api-keys/{id}/rotate issues a replacement with the same environment, scopes, and restrictions, then revokes the old key in one call. For zero-downtime rotation, overlap the keys instead:

  1. Create a new key with the same scopes.
  2. Deploy it to your servers.
  3. Verify traffic has moved to the new key, correlating with X-NU-Request-Id.
  4. Revoke the old key.

Rotate regularly and immediately on suspected exposure. Revocation marks the key REVOKED and rejects later calls, but does not cancel existing playback sessions or tokens; they expire by their own TTL.

Revocation

Revocation is immediate and irreversible. Every later call with that key returns 401 api_key_revoked.

Restrict where a key can be used

ControlEffect
allowed_originsPlayback tokens are issued only for origin values in this list.
allowed_ipsWhen configured, requests must originate from these IPs or CIDRs.
scopesLimits which endpoints the key can call (Authentication).

Configure allowed_origins and allowed_ips before launch; they are part of the Production checklist. A playback origin outside allowed_origins is rejected when a token is issued.