API basics

API basics

Base URL, authentication and the shape of every request and response.

The Heizen API is JSON over HTTPS.

https://api.interviewer.heizen.tech/api/v1

Authentication

Send your key as a bearer token on every request:

curl https://api.interviewer.heizen.tech/api/v1/me \
  -H "Authorization: Bearer $HEIZEN_API_KEY"

A missing, malformed or revoked key gets 401 invalid_api_key. A valid key without the scope an endpoint needs gets 403 missing_scope, and the error names the scope. API keys lists the scopes.

Requests

  • Send bodies as JSON with Content-Type: application/json. The one exception is candidate import, which is multipart/form-data.
  • Field names are snake_case. Fields the endpoint does not define are ignored, so check spelling if a value seems to have no effect.
  • Timestamps are ISO 8601 in UTC, like 2026-10-01T09:30:00.000Z.
  • Ids carry a type prefix, like inv_3f9c…. Treat them as opaque strings.

Responses

Every object has an id and an object field naming its type, and live or test data carries livemode. Lists use the list envelope. Deleting returns { "id": "…", "object": "…", "deleted": true }.

Useful response headers:

HeaderMeaning
Request-IdUnique per request. Quote it to support.
RateLimit-Limit, RateLimit-Remaining, RateLimit-ResetYour rate limit window
Idempotent-Replayedtrue when this is a stored response to a repeated idempotent request