Quickstart
This walks through your first call. You’ll need a key issued by OpenBrix (format
obxp_<prefix>_<secret>) and a service your brand is entitled to.
-
Store your key
Put the key in your secret manager and load it as an environment variable — never commit it.
Terminal window export TLYFE_API_KEY="obxp_<prefix>_<secret>" -
Call an in-scope endpoint
List your branch’s portal leads (requires the
portalscope + entitlement):Terminal window curl https://wl.api.cluster.openbrix.co.uk/v2.0/properties/portal/leads \-H "Authorization: Bearer $TLYFE_API_KEY"A success looks like:
{ "data": [], "count": 0 }An empty result is normal — you’re seeing your data, which starts empty. That empty, brand-scoped response is data isolation working as intended.
-
Understand a scope rejection
Call a service your key doesn’t hold the scope for, e.g. maintenance:
Terminal window curl https://wl.api.cluster.openbrix.co.uk/v2.0/maintenance/issues \-H "Authorization: Bearer $TLYFE_API_KEY"{ "status": false, "message": "This API key does not have the 'maintenance' scope." }That’s a
403. To call maintenance you’d need both themaintenancescope on your key and the maintenance entitlement on your brand — see Scopes & entitlements.