Request headers and service URLs
Use the authentication and API URLs supplied with your application credentials. They may differ by environment. Examples on this site use an API base URL before the /jsonapi path.
| Header | Value | When to send it |
|---|---|---|
Authorization | Bearer {access_token} | Authenticated API requests |
UserId | Assigned adviser contact identifier | Supply adviser context, particularly for writes and searches that require it |
Accept | application/vnd.api+json | JSON:API requests |
Content-Type | application/vnd.api+json | Requests with a JSON:API body, including POST and PATCH |
GET /jsonapi/contacts/1001
Authorization: Bearer {ACCESS_TOKEN}
UserId: {ADVISER_CONTACT_ID}
Accept: application/vnd.api+json
The token exchange uses application/x-www-form-urlencoded, not JSON:API. Webhook notifications use application/json and have their own payload shape. Do not apply the JSON:API envelope to every request across all services.
Preserve header values exactly. Header names are case-insensitive. Read response status and headers before assuming there is a JSON body, particularly for HEAD, 204 and rate-limit responses.
For a step-by-step adviser lookup and write example, see Update information in MyCRM.