Skip to content

Quickstart

This walks through your first call. You’ll need a key issued by OpenBrix (format obxp_<prefix>_<secret>) and a service your brand is entitled to.

  1. Store your key

    Put the key in your secret manager and load it as an environment variable — never commit it.

    Terminal window
    export TLYFE_API_KEY="obxp_<prefix>_<secret>"
  2. Call an in-scope endpoint

    List your branch’s portal leads (requires the portal scope + entitlement):

    Terminal window
    curl https://wl.api.cluster.openbrix.co.uk/v2.0/properties/portal/leads \
    -H "Authorization: Bearer $TLYFE_API_KEY"

    A success looks like:

    { "data": [], "count": 0 }

    An empty result is normal — you’re seeing your data, which starts empty. That empty, brand-scoped response is data isolation working as intended.

  3. Understand a scope rejection

    Call a service your key doesn’t hold the scope for, e.g. maintenance:

    Terminal window
    curl https://wl.api.cluster.openbrix.co.uk/v2.0/maintenance/issues \
    -H "Authorization: Bearer $TLYFE_API_KEY"
    { "status": false, "message": "This API key does not have the 'maintenance' scope." }

    That’s a 403. To call maintenance you’d need both the maintenance scope on your key and the maintenance entitlement on your brand — see Scopes & entitlements.