Skip to content
Veloratech

velora.developers

Build on the Velora platform

A small, stable REST API for entitlements and access control — the same API Velora products use to decide who gets in.

API keys

Organization-scoped keys with read or access scopes. Shown once, stored hashed, revocable any time.

Access control

One endpoint answers “can this customer use this product?” using live subscription status.

Provisioning webhooks

Products receive signed product.activated / product.deactivated events (HMAC-SHA256).

API reference

Base URL is your Velora deployment. Authenticate with Authorization: Bearer vk_live_…. Scopes: read (read products, entitlements and invoices), access (verify product access and licenses).

GET/api/v1/productsAuth: None

Public catalog of published products and their public plans.

curl https://YOUR_DOMAIN/api/v1/products
GET/api/v1/meAuth: API key (read)

The organization the key belongs to, with active subscriptions.

curl -H "Authorization: Bearer $VELORA_API_KEY" https://YOUR_DOMAIN/api/v1/me
GET/api/v1/access?product=velora-assistAuth: API key (access)

Checks whether the key's organization may use a product. Velora products call this on sign-in.

curl -H "Authorization: Bearer $VELORA_API_KEY" "https://YOUR_DOMAIN/api/v1/access?product=velora-assist"
GET/api/v1/licenses/verify?product=velora-erp&key=VLR-…Auth: None (rate-limit at the edge)

Validates a license key for license-type products.

curl "https://YOUR_DOMAIN/api/v1/licenses/verify?product=velora-erp&key=VLR-XXXX-XXXX-XXXX-XXXX"

Verifying provisioning webhooks

Compute HMAC-SHA256(raw_body, PROVISIONING_SIGNING_SECRET) as hex and compare it with the x-velora-signature header using a constant-time comparison.