Reguly
Reguly

Developers

Grant access without giving up control.

Retail aggregators, channel partners and your own apps fetch your product passport data through the public API — with a key you issue, limit and revoke at any time.

API keys in Reguly: form for label and rate limit plus the list of issued keys with prefix, limit and status
Interface
public passport API
Rate limit per key
1–6000 req/min
Default
60 req/min
Visibility
your own brand only

How you work with it

01

Create a key per partner

The label says who the key is for — “ACME Retail Integration” rather than “Key 3”. Plus the rate limit in requests per minute: 60 by default, 1 to 6000 permitted. One key per partner, otherwise no single access can be ended later.

Creating an API key in Reguly: label “ACME Retail Integration”, rate limit 60 requests per minute, below it the list of existing keys
02

Save the plaintext once

The full key appears exactly once, right after it is generated. After that the list only shows the prefix. Close the window without using it and you issue a new key and revoke the old one.

03

Connect the integration

Authentication runs via “Authorization: Bearer” or “X-API-Key”. The guide in the module shows both variants with curl examples — against the list of passports and against the detail call per GTIN.

Built-in API guide in Reguly with curl examples for the Bearer and X-API-Key headers and the available passport endpoints
04

See usage and revoke

The list carries label, prefix, limit, last use and status. Revocation runs through a confirmation prompt and blocks the access immediately. There is no expiry date — a key ends when you end it.

Integration teams

One key, two endpoints, one clear boundary — the curl examples sit in the module.

Brand owners & admins

Issue a key per partner, see the last use, take a single access back.

Retail & platform partners

Pull passport data programmatically instead of by export — always the state that is currently published.

Im Zusammenspiel

Ein Datenbestand, der weiterreicht

  1. 01

    Product passports

    produces the public passport data

    Passport content per GTIN · public view

  2. 02

    API keys

    governs who may retrieve it programmatically

    Key per partner · Rate limit · Brand scope

  3. 03

    Analytics

    evaluates the use of the passports as scan statistics

    Retrieval counts

Frequently asked questions

What does an API key see?

Your brand’s public passport API: the list of passports and the detail call per GTIN. Keys are bound to the brand and see nothing beyond it — they are not dashboard access.

Can I display a key again later?

No. The plaintext appears exactly once after generation; after that the list only shows the prefix. If it is lost, you issue a new one and revoke the old one.

What happens on revocation?

After a confirmation prompt the key is blocked and stays in the list as revoked. Integrations using it are locked out immediately — so plan the switch beforehand.

Does a key replace dashboard access?

No, and the two routes should stay separate: roles govern who maintains and releases data, keys govern which machine retrieves published passport data. Anyone who is to work in the dashboard is invited with a role in the team module.

How many keys may I issue?

The quota depends on the plan you have booked and is shown in the billing overview. Without the module enabled, the page shows the note about the required plan instead of the management view.

Look at the interface before the integration

We will show you the endpoints, headers and limits of the passport API against your own data.

Reguly

Compliance & customer experience on one platform — PPWR, ESPR and EU AI Act, one data pool.

GDPR compliantEU hosted

Reguly is software for documenting and organizing regulatory requirements and does not provide legal advice within the meaning of the German Legal Services Act (RDG). All content and automatically generated assessments are for information only and do not replace a case-by-case legal review. Responsibility for meeting regulatory obligations remains with the user.

© 2026 Reguly. Made in Düsseldorf · EU compliance for brands.