How to pass headers via the Proxy API?
The Proxy API lets you call any endpoint of a connected provider, including ones the Unified API doesn't cover, using the consumer's existing connection. You tell Apideck where to send the request with a few x-apideck-* headers, and Apideck adds the provider authentication for you.
A basic request
Send every request to https://unify.apideck.com/proxy, with the provider's full URL in x-apideck-downstream-url. The HTTP method you use (GET, POST, PATCH…) is the method sent to the provider.
curl --request GET 'https://unify.apideck.com/proxy' \
--header 'Authorization: Bearer {YOUR_APIDECK_API_KEY}' \
--header 'x-apideck-app-id: {YOUR_APP_ID}' \
--header 'x-apideck-consumer-id: {CONSUMER_ID}' \
--header 'x-apideck-service-id: {SERVICE_ID}' \
--header 'x-apideck-downstream-url: https://api.provider.com/v1/resource?status=active'
Put query parameters in the downstream URL. Include them in x-apideck-downstream-url (like ?status=active above). Query parameters on the /proxy URL itself aren't forwarded.
Apideck headers
Header | Required | What it does |
|---|---|---|
| Yes |
|
| Yes | Your Apideck application ID |
| Yes | The consumer whose connection to use |
| Yes | The full provider URL to call, including query parameters |
| Recommended | The connector, for example |
| Sometimes | Which Unified API's connection to use, for connectors available in several (for example Workday in HRIS, Accounting and ATS) |
| No | Overrides the HTTP method sent to the provider |
| No | Your own |
| No | How long to wait for the provider, in milliseconds. The default is 28000 (28 seconds). |
| No | Set to |
Your own headers
Any other headers you send are forwarded to the provider as they are, with a few exceptions:
x-apideck-*headers are used by Apideck and not forwarded.Authorizationis your Apideck key, so it isn't forwarded. Apideck adds the provider's own authorization instead. To send your own, usex-apideck-downstream-authorization.Content-Lengthis recalculated by Apideck.HostandCookiearen't forwarded.
Large responses
Responses larger than 2 MB are returned as a redirect to a temporary download link, which most HTTP clients follow automatically. If your client forwards your Authorization header on redirects, send x-apideck-follow-redirects: false and fetch the returned url yourself.
Providers that require a fixed IP address
Some providers only accept requests from approved IP addresses. Apideck sends requests from fixed IP addresses that the provider (or your customer's IT team) can allow. These addresses are shared by all Apideck customers. The current list is in the Static IP section of the Proxy API docs.
