Partner & Developer onboarding
Trying endpoints in the explorer
How a developer calls live endpoints from the API Docs explorer in your API Portal: what the explorer prefills from a subscription, what the developer enters so a call succeeds, getting an access token, full screen, sandbox docs, and CORS.
A developer calls live endpoints from the API Docs explorer in your API Portal. The explorer sends real requests to your API. Your API Portal shows a subscription's API key or client secret in full only once, at creation, so the explorer can prefill a Client ID but never a key or secret. The developer pastes the key or secret they saved.
What is the API Docs explorer?
The explorer renders your OpenAPI specification with an interactive editor turned on. A developer reads each endpoint, fills in parameters, and sends a request from the portal. The response appears in the same view.
The explorer appears in two places: on a product's documentation, and on a subscription's API Reference tab. On the subscription tab it is locked to that subscription's plan. Its credential fields come from the security schemes your specification declares, under Authorization & Authentication.
What does the explorer fill in, and what does the developer enter?
On a subscription's API Reference tab, the explorer prefills the Client ID on OAuth2 plans, and nothing else. The API key and the client secret come back masked, so the explorer leaves those fields empty. The developer enters them from the values they saved.
The explorer loads the subscription's credential details only after the developer reveals the credentials on the subscription's Details tab with the eye icon, or creates them, during the same visit. On a product's own documentation, outside a subscription, nothing is prefilled.
| Plan security | The explorer prefills | The developer enters |
|---|---|---|
| API key | Nothing | The API key they saved, in the API key field. The field carries the header or parameter name from your specification's security scheme. |
| Client ID and Client Secret | Client ID | The Client Secret they saved, then Set new Access Token. Or an access token pasted into Access Token. |
| Private Key JWT | Client ID | An access token they requested with a JWT signed by their private key, pasted into Access Token. The explorer can't sign that JWT. |
| Intermediate JWT or advanced code flow | Client ID | The secret they saved, or an access token pasted into Access Token. |
If the developer no longer has the key or secret, the portal can't show it again. They regenerate the credentials and save the new values; see API credentials.
How does a developer make a call with OAuth2 client credentials?
They fill in the secret, let the explorer fetch a token from your token endpoint, and send the request. The token then applies to every call in the explorer.
- Open the subscription, and on the Details tab reveal the credentials with the eye icon.
- Open the API Reference tab. Under Authorization & Authentication, the Client ID is already filled in.
- Paste the Client Secret they saved. Select any scopes the flow lists.
- Click Set new Access Token. The explorer requests a token from the token URL in your specification and shows Authorization Applied.
- Pick an endpoint and send the request.
The explorer keeps the token for 30 minutes in the browser session. For Set new Access Token to work, your specification's client credentials flow must include its token URL, and your token endpoint must accept requests from the browser. See the CORS rows under Troubleshooting.
How does a developer get an access token right after creating credentials?
With Generate Token. Right after a developer creates a Client ID and Client Secret, the panel that shows the new values has a Generate Access Token section. Generate Token requests an access token through your API Portal and shows it with a copy button.
The developer pastes that token into the explorer's Access Token field. The button is available only while the new values are on screen, on the credentials section of a subscription and on both sandbox and production credential cards.
What changes in full screen?
Launch in full screen mode opens the specification on its own page, with Plan, API, and Version selectors and the active team's subscription to the plan. Minimize Docs returns to the previous view.
Full screen fills the credential fields with the values exactly as the portal returns them, which for an API key or client secret is a masked value. The developer replaces a masked value with the key or secret they saved before sending, or the call fails.
| What the page shows | What it means |
|---|---|
| "Your active team has an active subscription to this plan:" | A selector lists the active team's Active subscriptions to the plan, with a Manage Subscription link. |
| "No active subscription to this plan found." | The active team has no Active subscription to the plan. Subscribe? opens the subscription wizard. |
| All APIs (combined) in the API selector | On a portal that uses catalog-led documentation, a plan documented per API with more than one API opens on all its APIs in one specification. |
How does a developer pick the plan, API, and version?
The explorer shows up to three selectors above the documentation: Plan, API, and Version. The API and Version selectors appear only when there is more than one option.
| Selector | When it appears | What it does |
|---|---|---|
| Plan | When the view is not locked to one plan, or when a sandbox option exists. | Switches the documentation to another plan, or to the sandbox. |
| API | When the plan documents at the API level and has more than one API. | Filters to one API's documentation. |
| Version | When the selected documentation has more than one visible version. | Switches to a specific version. |
On a subscription's API Reference tab, the plan is locked to the subscription's plan, plus a sandbox option where one exists.
Can a developer try sandbox endpoints?
Yes, when the plan's sandbox carries its own documentation. The Plan selector adds the plan with (Sandbox) after its name, and the explorer loads the sandbox specification when it is chosen.
On a subscription in the pipeline, the API Reference tab shows only the sandbox documentation during the Sandbox, In Review, and Rejected phases. From Production, it offers both the sandbox and the plan's own documentation. See From sandbox to production for the phases.
Troubleshooting
| What you see | What to do |
|---|---|
| The API key or Client Secret field is empty | Expected. Paste the value saved when the credentials were created. If it is lost, regenerate the credentials. |
| The Client ID is not prefilled | Reveal the credentials on the subscription's Details tab first, in the same visit. On a product page, nothing is prefilled. |
| A full-screen field holds a value with asterisks | That is the masked value. Replace it with the saved key or secret. |
| No credential fields under Authorization & Authentication | Your specification declares no security schemes. Add them under components.securitySchemes. |
| Set new Access Token shows "Failed to fetch (CORS or Network Issue)" | Your token endpoint does not accept browser requests from the portal. Allow the portal's origin, turn on Bypass CORS, or paste a token into Access Token. |
| "Connection Blocked - Unable to reach the server" when sending | Your API does not accept browser requests from the portal's origin. Allow the portal's origin in your API's CORS settings, or use Bypass CORS. |
| No Bypass CORS option | It appears only when you turn on Show Bypass Cors in the dashboard's API specification settings; see Spec viewer and validation. |
| Only sandbox documentation on the subscription | The subscription has not reached Production. |