Panelr

Authentication

API key

Every request is authenticated by the store's API key, sent as a request header. There is one key for the whole store and it stays on your server: never in a browser, an app, version control or a public repository. Generate it from the API page in the Panelr admin.

Required headers

X-Panelr-API-Key — Your API key

Content-Type — application/json (POST requests only)

Example

curl -X GET "PANELR_API_URL?action=get_products" \
  -H "X-Panelr-API-Key: YOUR_API_KEY"

Errors

A missing key answers HTTP 401 with Missing API key.; a wrong one answers HTTP 401 with Invalid API key.

Rate limits

Successful requests are capped at 120 per minute per IP. Ten failed key checks in fifteen minutes block that IP for the rest of the window.

Sign-in checks are also throttled per account and per visitor: verify_login, verify_customer_login, verify_site_password, and order lookups by email on get_work_order and submit_payment. Ten failures in fifteen minutes answer HTTP 429 Too many attempts. Please try again later. Pass the visitor's own address as customer_ip so the throttle counts them and not your server.