Authentication
Every BIDEX request needs two credentials: an API key that authenticates the caller, and a BuyersID that selects the customer account.
API key
The API key is a private access code supplied by Belgian Cycling Factory. Send it with every request in the x-api-key header:
curl -H 'x-api-key: xxxx' 'https://connections.cyclingfactory.be/api/v1/bidex/products?BuyersID=YOUR-BUYERS-ID'
The key is also accepted as the key query parameter, like on the rest of the Connections API (see the API introduction). The header is the recommended and safest option, because values in the request address end up in logs, bookmarks and browser history.
Treat the key as confidential:
- store it in a password manager or an approved secrets vault;
- never place it in an email, screenshot, spreadsheet or web address;
- if you believe the key has been exposed, contact Belgian Cycling Factory and request a replacement.
BuyersID
The BuyersID is the unique identifier of your customer account. It is a UUID: five groups of hexadecimal digits separated by hyphens, for example:
123e4567-e89b-12d3-a456-426614174000
Send it as the BuyersID query parameter:
/api/v1/bidex/products?BuyersID=123e4567-e89b-12d3-a456-426614174000
The BuyersID must be copied completely, including hyphens and without spaces. Requests with a missing or malformed BuyersID are rejected with a 400 error; a BuyersID that does not match a known customer account is rejected with 401.
The API key and the BuyersID must belong together: the key must be authorised for the account identified by the BuyersID. If they do not match, access is refused.
What is logged
For every request the service records an audit entry and a database log entry, including a request ID. When you report a problem, support can look up your request by that ID. Never include the API key in a support request; the request address with the BuyersID removed, the date and time, and the HTTP status are enough.