Authentication

All protected API routes require a bearer key except POST /partner-applications* and POST /api-keys/bootstrap. Keep keys on your server and apply least privilege. See Security best practices.

Request headers

HeaderRequiredExampleNotes
AuthorizationYesBearer nsp_live_xxxBearer API key. Required on every protected route.
X-NU-Partner-IdNoorg_xxxOptional assertion. If supplied, it must match the organization derived from the key.
X-NU-Request-IdNoreq_01HQ...Optional stable request ID for tracing and supported idempotent writes.
Accept-LanguageNoja-JP, en;q=0.8Selects the language of human-readable API error messages. Unsupported or omitted values fall back to English.
curl "https://signal-partners.newunivers.ai/v1/catalog/titles" \
  -H "Authorization: Bearer nsp_live_xxxxxxxxxxxx" \
  -H "X-NU-Partner-Id: org_acme" \
  -H "X-NU-Request-Id: req_01HQABCDEF" \
  -H "Accept-Language: ja-JP, en;q=0.8"

Accept-Language affects only human-readable messages. Read the selected locale from Content-Language; caches must honor Vary: Accept-Language. Stable error.code and details[].issue tokens never change with locale.

Content-Language: ja
Vary: Accept-Language

Bearer key

Send the key exactly as issued. It is shown only once and must never be placed in browser code, URLs, or logs. See API keys.

X-NU-Partner-Id

The organization is derived securely from the API key. A mismatched assertion is rejected as invalid_api_key. Omit this header unless your integration needs an explicit consistency check.

X-NU-Request-Id

Supply a stable value to correlate logs. The API echoes it as error.request_id. It also provides idempotency for POST /playback/tokens, POST /licenses/requests, and POST /api-keys/{id}/rotate. Completed retries replay the original response; a concurrent duplicate still being processed returns 409 conflict.

Authentication and authorization errors

SituationHTTPerror.code
Key missing or malformed401invalid_api_key
Unknown, expired, or environment-mismatched key401invalid_api_key
Revoked key401api_key_revoked
Required scope missing403missing_scope
Sandbox key used on a Production-only route403production_key_required
Organization not approved403organization_not_approved
Rights, territory, or episode is not authorized403license_not_active / territory_not_allowed / episode_not_licensed

401 means the credential itself is unusable. 403 means the key is known but lacks permission for this operation. See Error codes.

Scopes

ScopePermission
catalog:readRead visible catalog titles, experiences, and episodes.
license:readRequest quotes and read license agreements.
license:writeCreate license requests.
api_keys:readList API keys without secrets.
api_keys:writeCreate, update, rotate, and revoke API keys.
playback:tokenCreate playback tokens and inspect or revoke sessions.
events:writeSend individual or batched events.
settlement:readRead Production settlement statements and items.
settlement:disputeOpen settlement disputes.

Create separate keys per workload and grant only the scopes each component needs. Keep api_keys:write on a vault-held operational key, not on playback or event runtime keys.