Testing the API

Try endpoints from the API Reference or with our Postman collection.

You can explore the API without writing any code, either directly from the API Reference or with Postman. Both need the same two things:

WhatHow to get it
The api_url of a licenseReturned at the end of the authorization flow. It is different for every license.
A valid access token for that licenseObtained by exchanging the authorization code. It expires after 1 hour.
🚧

You are working on real data

Requests run against the license's real database. Use a test license or a test folder for write operations (.new, .update, .delete).

Getting a first token quickly

The quickest way is the Postman collection described below: it exchanges the code and stores the tokens for you. Alternatively, follow steps 1 to 4 of the Quickstart with curl.

In both cases, you can get the authorization code without a working callback page: open the authorization URL in your browser and log in. Even if the redirect page fails to load, the address bar shows the full redirect URL, from which you can copy code and api_url. The code is valid for 2 minutes.

From the API Reference

Every endpoint in the API Reference can be called from your browser with the Try It button.

  1. Set the API URL. The server URL is a variable named apiUrl. Replace the default value https://enter-your-api-url.invalid with your license's api_url. This default is deliberately invalid: requests fail until you replace it.
  2. Enter the access token in the authentication field.
  3. Send the request. Parameters and bodies are pre-filled with examples: adapt the identifiers (FolderId, CompanyId…) to data that exists in your license.

With Postman

The Horus Postman collection contains every endpoint, organised like the API Reference, with example bodies and responses.

Download the Postman collection

1. Import and configure

Import the file in Postman (Import), then open the collection's Variables tab:

VariableValue
apiUrlThe license's api_url. Required: requests are blocked while it is empty.
clientId, clientSecretYour integration's credentials.
redirectUriOne of the redirect URLs registered for your integration.
🚧

Keep your secret out of shared workspaces

If you share the collection with your team, store clientSecret in a Postman environment or vault rather than in the collection itself.

2. Get your tokens

  1. Open the authorization URL in your browser (see Quickstart, step 1).
  2. After login, copy code and api_url from the redirect URL into the authorizationCode and apiUrl variables.
  3. Run Authentication › Exchange authorization code within 2 minutes. The access and refresh tokens are saved automatically in the collection variables.

3. Call the API

Every request of the collection sends the access token as a Bearer token. When it expires, after 1 hour, run Authentication › Refresh access token.

📘

Sending files from Postman

Requests that accept a document are pre-filled with a JSON body. To attach a file, switch the body to form-data, add a file field of type File with your file, and a body field of type Text containing the JSON.


Did this page help you?