Developer guide
CloudRaker exposes its whole platform through a single REST API served by a thin gateway at https://api.cloudraker.com. The gateway authenticates your request, resolves your tenant, and authorizes the action. It then dispatches to the domain services behind it. You get one base URL, one auth header, and JSON everywhere.
One key, one org. A CloudRaker organization API key is a machine credential scoped to a single organization (tenant). Create one under Admin → API keys. Send it as a bearer token. Every call then runs against that org’s data. See Authentication.
What you can build
Base URL
Every call goes to one base URL:
That is the gateway. It is the only base URL to build against. CloudRaker runs internal environments for its own development. They are not available to API users. Production is your environment.
How the gateway works
- Authentication — every request carries
Authorization: Bearer <token>. The gateway accepts an organization API key (the developer path) or a session JWT. See Authentication. - Tenant scoping — your token’s organization is your tenant. You never pass a tenant id. The gateway resolves it and scopes every call automatically.
- Authorization — the gateway decides what a caller may do before it dispatches. Org keys satisfy admin and org-level gates. Only a human’s session token satisfies some per-user resource permissions.
- Errors — failures come back as JSON
{ "error": "<snake_case_code>" }with a matching HTTP status. The capability endpoints use a richer{ code, message, retryable, requestId, docUrl }envelope. See Errors. - Rate limits — the
/v1API guarantees at least 67 requests per minute per organization, shared across every endpoint. Above that, you get429with aRetry-Afterheader. See Rate limits.