BluebulbAPI
    Get started

    Authentication

    Every call to the Orbita API is checked four ways: a valid API key, a request from an allowlisted IP address, a valid RSA signature, and a per-key rate limit.

    API keys

    Each business has one API key. Your business's Primary Admin manages it from the Orbita dashboard under Settings → API Keys, confirming their password for every change:

    • Generate a key. It is shown once, in the form <appId>.<secret> — store it in a secret manager straight away.
    • Rotate the key. A new key is issued and the old one stops working.
    • Revoke the key to switch off API access for your business.

    Send the key in the x-api-key header on every request:

    curl "{baseUrl}/api/rates" \
      -H "x-api-key: <appId>.<secret>" \
      -H "X-Signature: <signature>" \
      -H "X-Signature-Timestamp: <unix ms>"
    Call the API only from your servers. Your API key and signing key carry the full permissions of your business. Never put them in a browser, mobile app, or source control. If a key leaks, rotate it immediately.

    IP allowlist

    Requests are accepted only from IP addresses on your business's allowlist. Bluebulb manages the list for you — send the public IP addresses of the servers that call the API to your Bluebulb contact, and tell them before those addresses change.

    • Addresses are matched exactly; ranges (CIDR) aren't supported, so list each address.
    • If your allowlist is empty, every request is rejected.
    • A request from an unlisted address gets 403 with the address Orbita saw, which helps when your traffic leaves through a proxy or NAT gateway.

    Request signing

    Every request also carries an RSA-SHA256 signature in the X-Signature and X-Signature-Timestamp headers, made with a private key only you hold. This proves the request came from you and wasn't altered or replayed. Setup and code are on Request signing.

    Rate limits

    Each API key can make 60 requests per minute to each endpoint. Going over returns 429; wait a few seconds and retry with backoff. Poll status endpoints at a sensible interval (e.g. every 30–60 seconds) rather than in a tight loop.

    Authentication errors

    These can be returned by any authenticated endpoint:

    403
    Forbidden resource
    x-api-key is missing, malformed, revoked or wrong.
    403
    This API key is not authorized for customer routes
    The key isn't a customer API key.
    403
    This IP address (203.0.113.10) is not whitelisted for this API key
    The request came from an address that isn't on your allowlist.
    403
    Missing or expired request signature
    A signing header is missing, or X-Signature-Timestamp is more than 5 minutes from Orbita's clock.
    403
    No approved signing key on file for this business. Upload one from the dashboard’s API Keys settings and wait for it to be approved before this request can be signed.
    Your public key hasn't been uploaded, is still pending, or was rejected.
    403
    Invalid request signature
    The signature doesn't match the request. See common signing mistakes.
    403
    Request signature already used
    The exact signed request was sent twice. Sign every request, including retries, afresh.
    400
    API key is not linked to a business
    The key isn't attached to a business. Contact Bluebulb.
    429
    You're making requests a little too quickly. Please wait a moment and try again.
    More than 60 requests in a minute to one endpoint.