How to pass headers via the Proxy API?

Edited

The Proxy API lets you call any endpoint of a connected provider, including ones the Unified API doesn't cover, using the consumer's existing connection. You tell Apideck where to send the request with a few x-apideck-* headers, and Apideck adds the provider authentication for you.

A basic request

Send every request to https://unify.apideck.com/proxy, with the provider's full URL in x-apideck-downstream-url. The HTTP method you use (GET, POST, PATCH…) is the method sent to the provider.

curl --request GET 'https://unify.apideck.com/proxy' \
  --header 'Authorization: Bearer {YOUR_APIDECK_API_KEY}' \
  --header 'x-apideck-app-id: {YOUR_APP_ID}' \
  --header 'x-apideck-consumer-id: {CONSUMER_ID}' \
  --header 'x-apideck-service-id: {SERVICE_ID}' \
  --header 'x-apideck-downstream-url: https://api.provider.com/v1/resource?status=active'

Put query parameters in the downstream URL. Include them in x-apideck-downstream-url (like ?status=active above). Query parameters on the /proxy URL itself aren't forwarded.

Apideck headers

Header

Required

What it does

Authorization

Yes

Bearer followed by your Apideck API key

x-apideck-app-id

Yes

Your Apideck application ID

x-apideck-consumer-id

Yes

The consumer whose connection to use

x-apideck-downstream-url

Yes

The full provider URL to call, including query parameters

x-apideck-service-id

Recommended

The connector, for example netsuite. Needed when the consumer has more than one connector for the same Unified API.

x-apideck-unified-api

Sometimes

Which Unified API's connection to use, for connectors available in several (for example Workday in HRIS, Accounting and ATS)

x-apideck-downstream-method

No

Overrides the HTTP method sent to the provider

x-apideck-downstream-authorization

No

Your own Authorization value for the provider. Apideck then doesn't add the stored credentials.

x-apideck-timeout

No

How long to wait for the provider, in milliseconds. The default is 28000 (28 seconds).

x-apideck-follow-redirects

No

Set to false to get large responses as a JSON link instead of a redirect (see below)

Your own headers

Any other headers you send are forwarded to the provider as they are, with a few exceptions:

  • x-apideck-* headers are used by Apideck and not forwarded.

  • Authorization is your Apideck key, so it isn't forwarded. Apideck adds the provider's own authorization instead. To send your own, use x-apideck-downstream-authorization.

  • Content-Length is recalculated by Apideck.

  • Host and Cookie aren't forwarded.

Large responses

Responses larger than 2 MB are returned as a redirect to a temporary download link, which most HTTP clients follow automatically. If your client forwards your Authorization header on redirects, send x-apideck-follow-redirects: false and fetch the returned url yourself.

Providers that require a fixed IP address

Some providers only accept requests from approved IP addresses. Apideck sends requests from fixed IP addresses that the provider (or your customer's IT team) can allow. These addresses are shared by all Apideck customers. The current list is in the Static IP section of the Proxy API docs.

Related

Was this article helpful?

Sorry about that! Care to tell us more?

Thanks for the feedback!

There was an issue submitting your feedback
Please check your connection and try again.