Testing the API
Try endpoints from the API Reference or with our Postman collection.
You can explore the API without writing any code, either directly from the API Reference or with Postman. Both need the same two things:
| What | How to get it |
|---|---|
The api_url of a license | Returned at the end of the authorization flow. It is different for every license. |
| A valid access token for that license | Obtained by exchanging the authorization code. It expires after 1 hour. |
You are working on real dataRequests run against the license's real database. Use a test license or a test folder for write operations (
.new,.update,.delete).
Getting a first token quickly
The quickest way is the Postman collection described below: it exchanges the code and stores the tokens for you. Alternatively, follow steps 1 to 4 of the Quickstart with curl.
In both cases, you can get the authorization code without a working callback page: open the authorization URL in your browser and log in. Even if the redirect page fails to load, the address bar shows the full redirect URL, from which you can copy code and api_url. The code is valid for 2 minutes.
From the API Reference
Every endpoint in the API Reference can be called from your browser with the Try It button.
- Set the API URL. The server URL is a variable named
apiUrl. Replace the default valuehttps://enter-your-api-url.invalidwith your license'sapi_url. This default is deliberately invalid: requests fail until you replace it. - Enter the access token in the authentication field.
- Send the request. Parameters and bodies are pre-filled with examples: adapt the identifiers (
FolderId,CompanyId…) to data that exists in your license.
With Postman
The Horus Postman collection contains every endpoint, organised like the API Reference, with example bodies and responses.
Download the Postman collection
1. Import and configure
Import the file in Postman (Import), then open the collection's Variables tab:
| Variable | Value |
|---|---|
apiUrl | The license's api_url. Required: requests are blocked while it is empty. |
clientId, clientSecret | Your integration's credentials. |
redirectUri | One of the redirect URLs registered for your integration. |
Keep your secret out of shared workspacesIf you share the collection with your team, store
clientSecretin a Postman environment or vault rather than in the collection itself.
2. Get your tokens
- Open the authorization URL in your browser (see Quickstart, step 1).
- After login, copy
codeandapi_urlfrom the redirect URL into theauthorizationCodeandapiUrlvariables. - Run Authentication › Exchange authorization code within 2 minutes. The access and refresh tokens are saved automatically in the collection variables.
3. Call the API
Every request of the collection sends the access token as a Bearer token. When it expires, after 1 hour, run Authentication › Refresh access token.
Sending files from PostmanRequests that accept a document are pre-filled with a JSON body. To attach a file, switch the body to form-data, add a
filefield of type File with your file, and abodyfield of type Text containing the JSON.
Updated about 1 hour ago