Extension teams
0 / 11 complete

Integration checklist

Verify your Chrome extension sends the required headers and can reach RepliZen's public endpoints. Progress is saved in your browser.

Test credentials
Used only in your browser to run the live tests below.

1. Headers

Owners and admins can create keys under Settings → API keys. Keys start with ck_live_. Store the key in extension storage, never in code.

Required on every /lookup, /draft, /coupon, /products call.

Authorization: Bearer ck_live_xxxxxxxxxxxxxxxx

Reported minimum is 1.0.0. Older versions receive HTTP 426 Upgrade Required.

x-extension-version: 1.0.0

Include your extension name and version — helps support triage.

User-Agent: RepliZenExt/1.0.0 (chrome)

Browsers send an OPTIONS before authorized POSTs. Expect 204 with Access-Control-Allow-Headers including authorization, content-type, x-extension-version.

curl -i -X OPTIONS /api/public/lookup \
  -H "Origin: chrome-extension://<your-id>" \
  -H "Access-Control-Request-Method: POST" \
  -H "Access-Control-Request-Headers: authorization,content-type,x-extension-version"

2. Live tests

GET /api/public/health
Unauthenticated. Should return 200 with { status: "ok" }.

Confirms network path, DNS, and TLS. Safe to poll from the extension.

POST /api/public/lookup
Requires Authorization and x-extension-version.

Response includes ok: true, a customer block, and an orders array (may be empty if the email is unknown).

Try clearing the key or corrupting one character, then re-run.

Set the version field above to 0.9.0 and re-run to confirm your extension surfaces an upgrade prompt.

Watch for x-ratelimit-remaining, x-ratelimit-reset, and x-quota-remaining. On 429, back off until the reset timestamp.

Errors are JSON: { ok: false, error: { code, message } }. Show message to the user; log code.