Partner API
Provision partner accounts
Create an isolated tenant, confirmed administrator, and tenant API token.
POST
/
api
/
partner
/
v1
/
accounts
Provision a managed tenant account
curl --request POST \
--url https://spitshake.io/api/partner/v1/accounts \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Acme Legal",
"external_id": "firm-8675309",
"plan": "business",
"admin_email": "admin@acme.example",
"admin_first_name": "Ada",
"admin_last_name": "Lovelace",
"locale": "en",
"timezone": "America/New_York",
"generate_identity_handoff_secret": true
}
'import requests
url = "https://spitshake.io/api/partner/v1/accounts"
payload = {
"name": "Acme Legal",
"external_id": "firm-8675309",
"plan": "business",
"admin_email": "admin@acme.example",
"admin_first_name": "Ada",
"admin_last_name": "Lovelace",
"locale": "en",
"timezone": "America/New_York",
"generate_identity_handoff_secret": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Acme Legal',
external_id: 'firm-8675309',
plan: 'business',
admin_email: 'admin@acme.example',
admin_first_name: 'Ada',
admin_last_name: 'Lovelace',
locale: 'en',
timezone: 'America/New_York',
generate_identity_handoff_secret: true
})
};
fetch('https://spitshake.io/api/partner/v1/accounts', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://spitshake.io/api/partner/v1/accounts",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Acme Legal',
'external_id' => 'firm-8675309',
'plan' => 'business',
'admin_email' => 'admin@acme.example',
'admin_first_name' => 'Ada',
'admin_last_name' => 'Lovelace',
'locale' => 'en',
'timezone' => 'America/New_York',
'generate_identity_handoff_secret' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://spitshake.io/api/partner/v1/accounts"
payload := strings.NewReader("{\n \"name\": \"Acme Legal\",\n \"external_id\": \"firm-8675309\",\n \"plan\": \"business\",\n \"admin_email\": \"admin@acme.example\",\n \"admin_first_name\": \"Ada\",\n \"admin_last_name\": \"Lovelace\",\n \"locale\": \"en\",\n \"timezone\": \"America/New_York\",\n \"generate_identity_handoff_secret\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://spitshake.io/api/partner/v1/accounts")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Acme Legal\",\n \"external_id\": \"firm-8675309\",\n \"plan\": \"business\",\n \"admin_email\": \"admin@acme.example\",\n \"admin_first_name\": \"Ada\",\n \"admin_last_name\": \"Lovelace\",\n \"locale\": \"en\",\n \"timezone\": \"America/New_York\",\n \"generate_identity_handoff_secret\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://spitshake.io/api/partner/v1/accounts")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Acme Legal\",\n \"external_id\": \"firm-8675309\",\n \"plan\": \"business\",\n \"admin_email\": \"admin@acme.example\",\n \"admin_first_name\": \"Ada\",\n \"admin_last_name\": \"Lovelace\",\n \"locale\": \"en\",\n \"timezone\": \"America/New_York\",\n \"generate_identity_handoff_secret\": true\n}"
response = http.request(request)
puts response.read_body{
"account": {
"id": 412,
"name": "Acme Legal",
"external_id": "firm-8675309",
"plan": "business",
"created_at": "2026-07-22T18:20:00Z"
},
"admin": {
"id": 991,
"email": "admin@acme.example"
},
"api_token": "9df52c0b6b3c...",
"identity_handoff_secret": "a62f81f0c0e9..."
}Provisioning creates the account, confirmed admin, tenant API token, audit event, and optional
identity-handoff secret in one transaction. Use an idempotency key because returned secrets are
otherwise shown only once.
curl -X POST https://spitshake.io/api/partner/v1/accounts \
-H "Authorization: Bearer $SPITSHAKE_PARTNER_KEY" \
-H "Idempotency-Key: provision-firm-8675309" \
-H "Content-Type: application/json" \
-d '{
"name": "Acme Legal",
"external_id": "firm-8675309",
"plan": "business",
"admin_email": "admin@acme.example",
"admin_first_name": "Ada",
"admin_last_name": "Lovelace",
"locale": "en",
"timezone": "America/New_York",
"generate_identity_handoff_secret": true
}'
201
{
"account": {
"id": 412,
"name": "Acme Legal",
"external_id": "firm-8675309",
"plan": "business",
"created_at": "2026-07-22T18:20:00Z"
},
"admin": {
"id": 991,
"email": "admin@acme.example"
},
"api_token": "9df52c0b6b3c...",
"identity_handoff_secret": "a62f81f0c0e9..."
}
name and admin_email are required. Email is trimmed and lowercased. plan defaults to
business; it must be both active and present in the partner’s operator-configured allowlist.
The identity secret is omitted unless explicitly requested.
Errors
401
{ "error": "Unauthorized" }
403
{ "error": "Plan is not authorized for this partner" }
409
{ "error": "admin_email already exists" }
409 also covers a duplicate external_id within the same partner and uniqueness races.
422
{ "error": "Plan is missing or inactive" }
422 also covers missing fields and reuse of an idempotency key with a different body.Authorizations
Operator-issued partner key. Accepted only under /api/partner/v1.
Headers
Retained for 24 hours. Reuse only with the exact same request body.
Maximum string length:
255Body
application/json
Response
Tenant account provisioned
⌘I
Provision a managed tenant account
curl --request POST \
--url https://spitshake.io/api/partner/v1/accounts \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Acme Legal",
"external_id": "firm-8675309",
"plan": "business",
"admin_email": "admin@acme.example",
"admin_first_name": "Ada",
"admin_last_name": "Lovelace",
"locale": "en",
"timezone": "America/New_York",
"generate_identity_handoff_secret": true
}
'import requests
url = "https://spitshake.io/api/partner/v1/accounts"
payload = {
"name": "Acme Legal",
"external_id": "firm-8675309",
"plan": "business",
"admin_email": "admin@acme.example",
"admin_first_name": "Ada",
"admin_last_name": "Lovelace",
"locale": "en",
"timezone": "America/New_York",
"generate_identity_handoff_secret": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Acme Legal',
external_id: 'firm-8675309',
plan: 'business',
admin_email: 'admin@acme.example',
admin_first_name: 'Ada',
admin_last_name: 'Lovelace',
locale: 'en',
timezone: 'America/New_York',
generate_identity_handoff_secret: true
})
};
fetch('https://spitshake.io/api/partner/v1/accounts', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://spitshake.io/api/partner/v1/accounts",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Acme Legal',
'external_id' => 'firm-8675309',
'plan' => 'business',
'admin_email' => 'admin@acme.example',
'admin_first_name' => 'Ada',
'admin_last_name' => 'Lovelace',
'locale' => 'en',
'timezone' => 'America/New_York',
'generate_identity_handoff_secret' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://spitshake.io/api/partner/v1/accounts"
payload := strings.NewReader("{\n \"name\": \"Acme Legal\",\n \"external_id\": \"firm-8675309\",\n \"plan\": \"business\",\n \"admin_email\": \"admin@acme.example\",\n \"admin_first_name\": \"Ada\",\n \"admin_last_name\": \"Lovelace\",\n \"locale\": \"en\",\n \"timezone\": \"America/New_York\",\n \"generate_identity_handoff_secret\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://spitshake.io/api/partner/v1/accounts")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Acme Legal\",\n \"external_id\": \"firm-8675309\",\n \"plan\": \"business\",\n \"admin_email\": \"admin@acme.example\",\n \"admin_first_name\": \"Ada\",\n \"admin_last_name\": \"Lovelace\",\n \"locale\": \"en\",\n \"timezone\": \"America/New_York\",\n \"generate_identity_handoff_secret\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://spitshake.io/api/partner/v1/accounts")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Acme Legal\",\n \"external_id\": \"firm-8675309\",\n \"plan\": \"business\",\n \"admin_email\": \"admin@acme.example\",\n \"admin_first_name\": \"Ada\",\n \"admin_last_name\": \"Lovelace\",\n \"locale\": \"en\",\n \"timezone\": \"America/New_York\",\n \"generate_identity_handoff_secret\": true\n}"
response = http.request(request)
puts response.read_body{
"account": {
"id": 412,
"name": "Acme Legal",
"external_id": "firm-8675309",
"plan": "business",
"created_at": "2026-07-22T18:20:00Z"
},
"admin": {
"id": 991,
"email": "admin@acme.example"
},
"api_token": "9df52c0b6b3c...",
"identity_handoff_secret": "a62f81f0c0e9..."
}
