Quickstart
Go from approved partner to first stream playback and event tracking in ten steps. Every operation here runs in Sandbox (https://signal-partners.newunivers.ai/v1). See the Sandbox guide.
First set the base URL. Organization IDs and keys come from the approval claim and bootstrap responses:
export NSP_BASE="https://signal-partners.newunivers.ai/v1"
1. Get the organization approved
Consent to the privacy policy and submit the partner application:
curl -X POST "$NSP_BASE/partner-applications" \
-H "Content-Type: application/json" \
-d '{
"company_name": "Acme Streaming",
"service_type": "OTT",
"contact_name": "Jin Park",
"contact_email": "dev@acme.example",
"privacy_consent": true,
"target_territories": ["KR", "JP"],
"expected_use_case": "Catalog licensing + VOD playback"
}'Immediately store application_reference and status_token from the response in secure secret storage. The status token is shown once; never put it in URLs or logs. Resubmitting the same email within 24 hours returns the existing application_id instead of creating a new application. Poll the status call while NU reviews the organization.
Run the claim exactly once after status is approved and claim_available is true.
export NSP_APPLICATION_REFERENCE="nsp_app_..."
export NSP_STATUS_TOKEN="nsp_ast_..."
curl -X POST "$NSP_BASE/partner-applications/status" -H "Content-Type: application/json" -d "{"application_reference":"$NSP_APPLICATION_REFERENCE","status_token":"$NSP_STATUS_TOKEN"}"
curl -X POST "$NSP_BASE/partner-applications/claim" -H "Content-Type: application/json" -d "{"application_reference":"$NSP_APPLICATION_REFERENCE","status_token":"$NSP_STATUS_TOKEN"}"
export NSP_APPROVAL_TOKEN="nsp_appr_..."2. Issue the first Sandbox key
After approval, exchange the one-time approval token from /partner-applications/claim for a Sandbox key with the nsp_test_ prefix. The secret is shown once, so store it in a secrets manager. The read-only Partner Portal can inspect state with the same key, but key creation, rotation, and revocation remain API-only operations.
curl -X POST "$NSP_BASE/api-keys/bootstrap" \
-H "Content-Type: application/json" \
-d "{ \"approval_token\": \"$NSP_APPROVAL_TOKEN\" }"
export NSP_ADMIN_KEY="nsp_test_xxxxxxxxxxxxxxxx"3. Scope with least privilege
Use the bootstrap key to create a narrower integration key with only the scopes needed here: catalog:read, playback:token, and events:write. Keep a server-side management key with api_keys:write separately, and optionally pin each key to allowed origins and IPs. See API keys.
curl --fail-with-body -X POST "$NSP_BASE/api-keys" \
-H "Authorization: Bearer $NSP_ADMIN_KEY" \
-H "Content-Type: application/json" \
-d '{
"environment": "sandbox",
"scopes": ["catalog:read", "playback:token", "events:write"]
}'
export NSP_KEY="nsp_test_xxxxxxxxxxxxxxxx"4. Download the Postman collection
Download the Postman collection and Sandbox environment file, import them into Postman, then set base_url and api_key to the values above.
5. List catalog titles
curl "$NSP_BASE/catalog/titles?territory=KR&limit=5" \
-H "Authorization: Bearer $NSP_KEY"The organization is derived securely from the API key; you do not need to send X-NU-Partner-Id separately.
Choose a title_id from data[], list its episodes with GET /catalog/titles/{title_id}/episodes, and copy an episode_id. See Catalog API.
6. Authorize playback
viewer_id_hash is a SHA-256 value you compute from a viewer ID and salt. Production requires 64 lowercase hexadecimal characters; it must never be raw PII. Optionally send non-PII preferences to personalize the hosted webview.
Do not reuse the sample value. Compute the hash on your server with a secret partner-held salt.
export NSP_VIEWER_HASH="$(printf '%s' 'stable-viewer-id:replace-with-secret-salt' | sha256sum | cut -d' ' -f1)"curl -X POST "$NSP_BASE/playback/tokens" \
-H "Authorization: Bearer $NSP_KEY" \
-H "Content-Type: application/json" \
-d '{
"title_id": "ttl_abc",
"episode_id": "ep_001",
"viewer_id_hash": "'"$NSP_VIEWER_HASH"'",
"country": "KR",
"device": "web",
"origin": "https://app.acme.example",
"preferences": { "subtitle_language": "ko", "autoplay_next": true },
"expires_in": 1800
}'Sandbox playback needs no license agreement, but rights gates still apply: the title needs a visible, unexpired rights package and, when sent, country must be allowed or the session is blocked with territory_not_allowed. The response includes playback_session_id, expires_at, hosted webview_url, a manifest with signed hls/dash URLs, and tracking containing event_endpoint plus required_events. See Playback API.
7. Play
Choose either equivalent method for the same session:
- Hosted webview (recommended): open
webview_urlin a WebView (WKWebView/android.webkit.WebView) or<iframe>. No player integration is required andpreferencesare applied automatically. The URL contains a signed token; treat it as a secret. - Own player: point any HLS player (hls.js, AVPlayer, ExoPlayer) at
manifest.hls. The CDN verifies signature and TTL before serving segments; the master file is never exposed.
8. Send an event
curl -X POST "$NSP_BASE/events" \
-H "Authorization: Bearer $NSP_KEY" \
-H "Content-Type: application/json" \
-d '{
"event_id": "evt_acme_0001",
"event_type": "EPISODE_STARTED",
"title_id": "ttl_abc",
"episode_id": "ep_001",
"playback_session_id": "pbs_123",
"occurred_at": "2026-06-24T00:00:00Z"
}'Returns 200 with { data: { event_id, status: "validated", received_at } }. event_id is unique per organization and idempotent; resending it returns 409 duplicate_event_id. See Event API.
9. Verify ingestion
Confirm the status is validated. Store request_id from error responses in logs and use stable event_id values so retries return duplicate_event_id instead of being counted twice.
10. Request a Production key
When integration is complete, follow the Production checklist. Execute a Production agreement until status is active and production_api_enabled is true (License API); request a nsp_live_ key, configure allowed_origins/allowed_ips, then switch NSP_BASE to https://signal-partners.newunivers.ai/v1.