Skip to main content

XeCubes Developer API

Welcome to the XeCubes REST API Reference. Our API is designed with predictable resource-oriented URLs, standard HTTP response codes, and JSON-encoded request and response bodies.


Base URLs​

Always target our production or sandbox API gateways:

Production: https://api.xecubes.com
Sandbox: https://stg-api.xecubes.com

Authentication Header​

Every API request requires an active API key passed in the X-API-Key HTTP header:

X-API-Key: xh_live_your_secret_key_here

Requests submitted without an API key or with an invalid key will return an HTTP 401 Unauthorized response.


Standard Response Format​

All responses follow our unified response schema:

Success Response​

{
"status": "success",
"message": "Resource retrieved successfully",
"data": { ... }
}

Error Response​

{
"status": "error",
"message": "Invalid API key provided or token has expired",
"code": "UNAUTHORIZED",
"details": {
"timestamp": "2026-06-05T12:00:00Z",
"request_id": "req_8392019482"
}
}

HTTP Status Codes​

CodeStatusMeaning
200OKThe request succeeded and returned data.
201CreatedThe resource was created successfully.
400Bad RequestInvalid request payload, missing mandatory fields.
401UnauthorizedMissing or invalid X-API-Key.
403ForbiddenKey is valid but lacks the required permission scope.
404Not FoundThe specified resource ID does not exist.
429Too Many RequestsRate limit exceeded. Refer to Retry-After header.
500Internal ErrorServer-side error. Contact XeCubes support with request_id.

Interactive Example: Verify Workspace​

curl -X GET "https://api.xecubes.com/recruiter/bootstrap" \
-H "X-API-Key: xh_live_your_secret_key"