Skip to main content
This page covers server-side operations. They use the secret Org-API-Key on your backend only - never ship it in an app, a mobile binary, or any client-side code. A request to any of these endpoints with a member token is rejected with 403. See Authentication.
This page is about authority, not location. Most endpoints accept either credential - browsing the catalog, redeeming, eligibility and reading conversations all work with the Org-API-Key directly, so a backend-only integration never has to mint a member token at all. See Authentication for the full list. What follows is the smaller set that the Org-API-Key is required for: operations that act on a member you name, or that change your program. They carry org-wide authority, so they must execute only on a backend you control.

Which operations require the Org-API-Key

A member token on any of these returns 403.

Why the boundary exists

The two credentials carry very different authority, and that difference is the whole reason for the split.

Org-API-Key

A long-lived secret with full authority over your org: it can mint tokens for any member, move points, change tiers, and read every member’s data. It must stay on your backend.

Member token

A short-lived credential scoped to a single member. If it leaks it exposes one member for a few minutes; it cannot touch other members or any org-wide operation.
Because the Org-API-Key can do anything, it never leaves your backend. The app only ever holds member tokens, which your backend mints on demand with exchangeToken.

Member mode vs server mode

Construct the server client

Initialize the SDK with the Org-API-Key as its token. The server-mode methods are additionally guarded client-side against being called with a member token.
curl
The 403 is enforced on the server: even if a member token reached one of these endpoints, the API rejects it. The client-side guard in the SDK is a second layer that fails fast before the request is sent.

Security checklist

The Org-API-Key is read only on your backend, never bundled into an app.
The app receives only member tokens (from exchangeToken), with their expiry.
Server-side calls - mint, credit, member management, analytics, webhooks - originate from your backend.
The Org-API-Key is stored as a backend secret, not in client-shipped environment variables or source.
If an Org-API-Key is ever exposed, rotate it immediately - it carries full org authority.

Server-side pages

Authentication

Exchange the Org-API-Key for short-lived member tokens and refresh them.

Members and tiers

Upsert profiles and tiers, read member summaries, and remove members.

Points and wallet

Mint and credit points into a member’s wallet from your backend.

Analytics

Program-wide rollups: summary, per-offer, and timeseries.

Webhooks

Register signed, retried event deliveries to your backend.