Skip to main content
POST
This method lets you verify that the PCI Booking service is available and that your API key is valid.

Authentication Guide

Learn about API key authentication

Error Responses

Both POST and GET methods are supported:

Error detail

The condition below gives the exact response, why it happens and how to resolve it. The full set is on the Error Handling page.
HTTP status: 401Response body: empty. There is no code, message or moreInfo.Reason. PCI Booking could not identify the caller. The response is the same for every cause:
  • The Authorization header (or the x-pcibooking-api-key header) is missing, badly formatted, or has no APIKEY keyword.
  • The API key is not valid, or it belongs to the other environment (sandbox or production).
  • The sessionToken is not valid or has expired.
  • The accessToken is not valid, has expired, has an expiration time further ahead than the maximum allowed, or was already used. An access token works once only, so reloading a page that uses it, such as a card display iframe, also returns this response.
How to resolve.
  1. Confirm the APIKEY prefix is present and there is a single space between it and the key.
  2. Confirm the key belongs to the same environment as the host you called. Sandbox and production keys are not interchangeable.
  3. If you use a session token, check it has not expired and start a new session if it has.
  4. If you use an access token, generate a new one for every request, including every reload of an iframe.
  5. Check that your HTTP client does not drop the Authorization header on a redirect. Most clients remove it after a 301 or 302.
See also: Authentication, Authentication and Permission Failures

Parameters

Authentication

API key only. This endpoint does not accept access tokens or session tokens.
string
required
Your API key prefixed with APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.

Response