Appearance
API
The Subtreo API lets your application work with supported billing resources programmatically. API access is tenant-specific: a request made with an API key operates only on the tenant that owns that key.
Set up API access
- In the admin panel, open Settings → API Key.
- Select Add new.
- Enter a descriptive Name, such as
Production customer portalorAccounting export. - Leave Enabled selected.
- The admin panel generates an API key automatically. Copy it and store it in a secure server-side secret manager or environment variable.
- Save the key.
Treat an API key like a password. Do not commit it to source control, put it in a client-side application, or share it in tickets and chat messages.
Authenticate requests
Send the key on every API request in the X-API-Key HTTP header:
bash
curl \
--header "X-API-Key: sk_your_api_key" \
--header "Accept: application/json" \
https://your-subtreo-domain.example/api/v1/customersThe API returns 401 Unauthorized when the header is missing, the key is invalid, or the key has been disabled.
Operate keys safely
- Give each integration its own named key so activity is easy to identify.
- Review the Last used at value in the API-key list to confirm a key is still in use.
- Disable a key to stop its access without deleting the record.
- Delete keys that have been permanently retired. If a key is exposed, disable it immediately and create a replacement for the integration.
API reference
The API Reference contains the current endpoint list, authentication requirements, request schemas, filters, and response examples.
Use webhooks when your application needs to receive subscription or invoice changes as they occur, rather than polling the API.
