Authentication & environments
The Pricing API uses the same OAuth2 client-credentials flow as the rest of the Vyro platform. Exchange your client ID and secret for an access token, then send it as a Bearer token.
๐ Credentialsโ
- Vyro issues you an API client: a
client_idandclient_secret. - The client is bound to your showroom code(s), e.g.
your-showroom-code. Every quote names the showroom it is for inshowroomCode. - A request for any showroom your client isn't bound to is rejected with
403 SHOWROOM_ACCESS_DENIED. - To get credentials, or credentials for an additional environment, email support@vyro.co.
Keep the client secret on your server. Call the Pricing API from your backend, never from a browser or mobile app. If you show drive-away prices on a website, compute them server-side (or cache them against your stock) and render the result.
๐๏ธ Get an access tokenโ
curl -s -X POST "https://authentication-api.vyro.com.au/api-client/authenticate" \
-H 'Content-Type: application/json' \
-d '{ "client_id": "your-client-id", "client_secret": "your-client-secret" }'
200 OK
{ "access_token": "your-access-token" }
The access token is valid for up to 1 hour. Cache it and reuse it for every request until shortly before it expires. Don't request a new token per quote.
Send it on every Pricing API request:
Authorization: Bearer your-access-token
๐ Environmentsโ
Use the region your credentials were issued for. Credentials, tokens and showroom codes are per environment: a staging client won't work in production, and vice versa.
| Environment | Authenticate endpoint | Pricing API base URL |
|---|---|---|
| Production Asia-Pacific | https://authentication-api.vyro.com.au/api-client/authenticate | https://pricing-api.vyro.com.au |
| Production Europe | https://authentication-api.vyro-eu.com/api-client/authenticate | https://pricing-api.vyro-eu.com |
| Staging | https://authentication-api.vyrolabs-staging.net/api-client/authenticate | https://pricing-api.vyrolabs-staging.net |
| Dev | https://authentication-api.vyrolabs.net/api-client/authenticate | https://pricing-api.vyrolabs.net |
Pricing is for Australian jurisdictions in every region. Most Australian businesses use Production Asia-Pacific. If you're unsure which region you're in, see Environments or contact support.
๐งช Connectivity checkโ
These two routes need no token:
curl -s https://pricing-api.vyro.com.au/healthcheck
# OK
curl -s https://pricing-api.vyro.com.au/spec
# the OpenAPI specification (YAML)
๐ซ Authentication errorsโ
| Status | code | Meaning |
|---|---|---|
401 | not-authenticated | No token, or the token is invalid or expired. Request a new token. |
403 | USER_INACTIVE | The API client has been revoked. Contact support. |
403 | SHOWROOM_ACCESS_DENIED | The showroomCode isn't one your client is bound to. Check for typos; codes are lowercase. |
400 | INVALID_SHOWROOM_CODE | showroomCode is missing or blank. |
๐ฆ Rate limitsโ
The API is built for high volume. A quote is computed in a few milliseconds. If you plan to price your whole inventory in a burst (for example, a nightly re-price of every listing), use the batch endpoint (up to 25 quotes per request), and let us know your expected peak volume so we can confirm capacity.