Request Headers

These are the headers you send with your API requests.

Authorization (required on authenticated endpoints)

Authorization: Bearer sk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Pass your API key as a Bearer token. Required on all endpoints except the public ones listed in Authentication. Requests to authenticated endpoints without this header return 401.

Content-Type (required for POST, PUT, PATCH)

Content-Type: application/json

Required whenever you send a request body. The API only accepts JSON. Omitting this header on a body request will result in a 400 parse error.

X-Request-ID (optional)

X-Request-ID: my-trace-id-abc123

You can supply your own request identifier to help correlate API calls with your own logs. If omitted, Capera generates one automatically. The value is echoed back in the response header and included in the response body as requestId.

X-API-Version (optional)

X-API-Version: v1

Targets a specific API version. Currently v1 is the only version. This header is optional — the default is always the latest stable version.


Response headers

These headers are returned on every response.

X-Request-ID

X-Request-ID: req_a1b2c3d4e5f6

The unique identifier for this request. Always include this value when contacting support — it allows the team to locate the exact request in logs.

X-API-Version

X-API-Version: v1

The API version that served the response.

X-RateLimit-Limit

X-RateLimit-Limit: 1000

The maximum number of requests allowed in the current rate-limit window.

X-RateLimit-Remaining

X-RateLimit-Remaining: 987

The number of requests remaining in the current window.

X-RateLimit-Reset

X-RateLimit-Reset: 1705320000

Unix timestamp of when the current rate-limit window resets.


Example request

curl -X POST https://api.withcapera.com/b2b/v1/transfers/initiate \
  -H "Authorization: Bearer sk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \
  -H "Content-Type: application/json" \
  -H "X-Request-ID: order-1042-transfer-attempt-1" \
  -d '{
    "reference": "TRF-2024-001",
    "amount": 500000,
    "bankSlug": "first-bank",
    "accountNumber": "1234567890",
    "accountName": "Amara Okafor"
  }'

Example response headers:

HTTP/2 200
Content-Type: application/json
X-Request-ID: order-1042-transfer-attempt-1
X-API-Version: v1
X-RateLimit-Limit: 1000
X-RateLimit-Remaining: 986
X-RateLimit-Reset: 1705320000

CORS

The API allows cross-origin requests from any origin. The following headers are accepted from browsers:

Origin, Content-Type, Accept, Authorization, X-Request-ID, X-API-Version

Do not call the API from client-side browser code. While CORS is open, your API key would be exposed to anyone who inspects network traffic. Always make B2B API calls from your backend.


Did this page help you?