const response = await fetch('https://service.pcibooking.net/api/accounts/authenticate/', {
method: 'POST',
headers: {
'Authorization': 'APIKEY your-api-key'
}
});
console.log(response.status); // 200 if valid
import requests
response = requests.post(
'https://service.pcibooking.net/api/accounts/authenticate/',
headers={
'Authorization': 'APIKEY your-api-key'
}
)
print(response.status_code) # 200 if valid
// Empty body. The API key is valid and the service is available.
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
Authentication
Authenticate API Key
Verify that the PCI Booking service is available and your API key is valid.
POST
/
api
/
accounts
/
authenticate
/
const response = await fetch('https://service.pcibooking.net/api/accounts/authenticate/', {
method: 'POST',
headers: {
'Authorization': 'APIKEY your-api-key'
}
});
console.log(response.status); // 200 if valid
import requests
response = requests.post(
'https://service.pcibooking.net/api/accounts/authenticate/',
headers={
'Authorization': 'APIKEY your-api-key'
}
)
print(response.status_code) # 200 if valid
// Empty body. The API key is valid and the service is available.
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
This method lets you verify that the PCI Booking service is available and that your API key is valid.
Both
Authentication Guide
Learn about API key authentication
Error Responses
| HTTP Status | Error Code | Description |
|---|---|---|
| 401 | none | Not authenticated. The API key is missing, malformed, or not valid. The response body is empty. |
| 403 | -1003 | Your IP address is not in your account’s allowed IP list. message names the reason. See Authentication and Permission Failures. |
| 500 | -150 | The API key belongs to a user that has been closed. |
POST and GET methods are supported:
GET https://service.pcibooking.net/api/accounts/authenticate/
Error detail
The condition below gives the exact response, why it happens and how to resolve it. The full set is on the Error Handling page.401 with an empty body - authentication failed
401 with an empty body - authentication failed
HTTP status:
401Response body: empty. There is no code, message or moreInfo.Reason. PCI Booking could not identify the caller. The response is the same for every cause:- The
Authorizationheader (or thex-pcibooking-api-keyheader) is missing, badly formatted, or has noAPIKEYkeyword. - The API key is not valid, or it belongs to the other environment (sandbox or production).
- The
sessionTokenis not valid or has expired. - The
accessTokenis not valid, has expired, has an expiration time further ahead than the maximum allowed, or was already used. An access token works once only, so reloading a page that uses it, such as a card display iframe, also returns this response.
- Confirm the
APIKEYprefix is present and there is a single space between it and the key. - Confirm the key belongs to the same environment as the host you called. Sandbox and production keys are not interchangeable.
- If you use a session token, check it has not expired and start a new session if it has.
- If you use an access token, generate a new one for every request, including every reload of an iframe.
- Check that your HTTP client does not drop the
Authorizationheader on a redirect. Most clients remove it after a 301 or 302.
Parameters
Authentication
API key only. This endpoint does not accept access tokens or session tokens.string
required
Your API key prefixed with
APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.const response = await fetch('https://service.pcibooking.net/api/accounts/authenticate/', {
method: 'POST',
headers: {
'Authorization': 'APIKEY your-api-key'
}
});
console.log(response.status); // 200 if valid
import requests
response = requests.post(
'https://service.pcibooking.net/api/accounts/authenticate/',
headers={
'Authorization': 'APIKEY your-api-key'
}
)
print(response.status_code) # 200 if valid
Response
// Empty body. The API key is valid and the service is available.
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.

