Quickstart

Go from approved partner to first stream playback and event tracking in ten steps. Every operation here runs in Sandbox (https://signal-partners.newunivers.ai/v1). See the Sandbox guide.

First set the base URL. Organization IDs and keys come from the approval claim and bootstrap responses:

export NSP_BASE="https://signal-partners.newunivers.ai/v1"

1. Get the organization approved

Consent to the privacy policy and submit the partner application:

curl -X POST "$NSP_BASE/partner-applications" \
  -H "Content-Type: application/json" \
  -d '{
    "company_name": "Acme Streaming",
    "service_type": "OTT",
    "contact_name": "Jin Park",
    "contact_email": "dev@acme.example",
    "privacy_consent": true,
    "target_territories": ["KR", "JP"],
    "expected_use_case": "Catalog licensing + VOD playback"
  }'

Immediately store application_reference and status_token from the response in secure secret storage. The status token is shown once; never put it in URLs or logs. Resubmitting the same email within 24 hours returns the existing application_id instead of creating a new application. Poll the status call while NU reviews the organization.

Run the claim exactly once after status is approved and claim_available is true.

export NSP_APPLICATION_REFERENCE="nsp_app_..."
export NSP_STATUS_TOKEN="nsp_ast_..."

curl -X POST "$NSP_BASE/partner-applications/status"   -H "Content-Type: application/json"   -d "{"application_reference":"$NSP_APPLICATION_REFERENCE","status_token":"$NSP_STATUS_TOKEN"}"

curl -X POST "$NSP_BASE/partner-applications/claim"   -H "Content-Type: application/json"   -d "{"application_reference":"$NSP_APPLICATION_REFERENCE","status_token":"$NSP_STATUS_TOKEN"}"

export NSP_APPROVAL_TOKEN="nsp_appr_..."

2. Issue the first Sandbox key

After approval, exchange the one-time approval token from /partner-applications/claim for a Sandbox key with the nsp_test_ prefix. The secret is shown once, so store it in a secrets manager. The read-only Partner Portal can inspect state with the same key, but key creation, rotation, and revocation remain API-only operations.

curl -X POST "$NSP_BASE/api-keys/bootstrap" \
  -H "Content-Type: application/json" \
  -d "{ \"approval_token\": \"$NSP_APPROVAL_TOKEN\" }"

export NSP_ADMIN_KEY="nsp_test_xxxxxxxxxxxxxxxx"

3. Scope with least privilege

Use the bootstrap key to create a narrower integration key with only the scopes needed here: catalog:read, playback:token, and events:write. Keep a server-side management key with api_keys:write separately, and optionally pin each key to allowed origins and IPs. See API keys.

curl --fail-with-body -X POST "$NSP_BASE/api-keys" \
  -H "Authorization: Bearer $NSP_ADMIN_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "environment": "sandbox",
    "scopes": ["catalog:read", "playback:token", "events:write"]
  }'

export NSP_KEY="nsp_test_xxxxxxxxxxxxxxxx"

4. Download the Postman collection

Download the Postman collection and Sandbox environment file, import them into Postman, then set base_url and api_key to the values above.

5. List catalog titles

curl "$NSP_BASE/catalog/titles?territory=KR&limit=5" \
  -H "Authorization: Bearer $NSP_KEY"

The organization is derived securely from the API key; you do not need to send X-NU-Partner-Id separately.

Choose a title_id from data[], list its episodes with GET /catalog/titles/{title_id}/episodes, and copy an episode_id. See Catalog API.

6. Authorize playback

viewer_id_hash is a SHA-256 value you compute from a viewer ID and salt. Production requires 64 lowercase hexadecimal characters; it must never be raw PII. Optionally send non-PII preferences to personalize the hosted webview.

Do not reuse the sample value. Compute the hash on your server with a secret partner-held salt.

export NSP_VIEWER_HASH="$(printf '%s' 'stable-viewer-id:replace-with-secret-salt' | sha256sum | cut -d' ' -f1)"
curl -X POST "$NSP_BASE/playback/tokens" \
  -H "Authorization: Bearer $NSP_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "title_id": "ttl_abc",
    "episode_id": "ep_001",
    "viewer_id_hash": "'"$NSP_VIEWER_HASH"'",
    "country": "KR",
    "device": "web",
    "origin": "https://app.acme.example",
    "preferences": { "subtitle_language": "ko", "autoplay_next": true },
    "expires_in": 1800
  }'

Sandbox playback needs no license agreement, but rights gates still apply: the title needs a visible, unexpired rights package and, when sent, country must be allowed or the session is blocked with territory_not_allowed. The response includes playback_session_id, expires_at, hosted webview_url, a manifest with signed hls/dash URLs, and tracking containing event_endpoint plus required_events. See Playback API.

7. Play

Choose either equivalent method for the same session:

  • Hosted webview (recommended): open webview_url in a WebView (WKWebView/android.webkit.WebView) or <iframe>. No player integration is required and preferences are applied automatically. The URL contains a signed token; treat it as a secret.
  • Own player: point any HLS player (hls.js, AVPlayer, ExoPlayer) at manifest.hls. The CDN verifies signature and TTL before serving segments; the master file is never exposed.

8. Send an event

curl -X POST "$NSP_BASE/events" \
  -H "Authorization: Bearer $NSP_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "event_id": "evt_acme_0001",
    "event_type": "EPISODE_STARTED",
    "title_id": "ttl_abc",
    "episode_id": "ep_001",
    "playback_session_id": "pbs_123",
    "occurred_at": "2026-06-24T00:00:00Z"
  }'

Returns 200 with { data: { event_id, status: "validated", received_at } }. event_id is unique per organization and idempotent; resending it returns 409 duplicate_event_id. See Event API.

9. Verify ingestion

Confirm the status is validated. Store request_id from error responses in logs and use stable event_id values so retries return duplicate_event_id instead of being counted twice.

10. Request a Production key

When integration is complete, follow the Production checklist. Execute a Production agreement until status is active and production_api_enabled is true (License API); request a nsp_live_ key, configure allowed_origins/allowed_ips, then switch NSP_BASE to https://signal-partners.newunivers.ai/v1.