-H "Authorization: Bearer 4eC39HqLyjWDarjtT1zdp7dc" instead of -u 4eC39HqLyjWDarjtT1zdp7dc.
Scopes
Each API key carries a set of scopes that determine which endpoints it may call. Scopes are configured by your Imprint team based on your integration — see API key rotation for how initial keys are provisioned. The scope required by an individual endpoint is documented on that endpoint’s page under the REST API tab. Endpoints not listed below need no scope beyond a valid API key.
Calling an endpoint with a key that lacks the required scope returns
403 Forbidden:
PCI_DETAILS_READ and AUTHORIZED_USER_READ are the exceptions — they never fail a request. Payment method endpoints succeed without PCI_DETAILS_READ, but omit card.pci_details (PAN, CVV, expiry) from the response. Retrieve Customer succeeds without AUTHORIZED_USER_READ, but omits authorized_users.
A new API key created via
POST /v2/keys inherits exactly the scopes of the
key used to create it. A key with no scopes creates another key with no scopes;
rotation never adds newly enabled product scopes automatically.Multi-Product Support
If your partnership spans multiple products (e.g., a parent company with several co-branded products), include thex-imprint-merchant-key header in your requests to specify which product the request applies to.
If you have multiple products, you must supply the merchant key in the header in order to retrieve information for that merchant/product: