API reference/Authentication and conventions
Authentication and conventions
Requests carry a bearer key scoped to one business and one environment. Keys are shown once and can carry a policy: daily budget, per-payout maximum, allowed channels and an approval threshold. Every POST that creates a payout, batch or recipient accepts an Idempotency-Key; the same key with the same body returns the original result and a different body returns 409. Amounts are decimal strings. Lists take limit and cursor.
Sandbox funds are free and sandbox payouts simulate every state, including provider failure and refund.
Rate limits
| Group | Limit |
|---|---|
| Reads | 600 requests per minute |
| Quotes | 300 requests per minute |
| Writes | 120 requests per minute |
Examples: List channels
curl -X GET https://sandbox.api.decaf.so/v1/channels \
-H "Authorization: Bearer $DECAF_API_KEY"Get access
Build against the sandbox this week.
Tell us the corridors you need and the recipients you pay. Sandbox keys are issued by a person.