For the complete documentation index, see llms.txt. This page is also available as Markdown.

Authentication

Every request must include a valid API key. Requests without one, or with an invalid key, return HTTP 401 Unauthorized.

Your API key

Your API key is provisioned by your Cover Genius CSE. You receive separate keys for staging and production. Do not use your production key while testing.

Your API key is sent in the X_API_KEY header of your request.

curl --location 'https://api-staging.rentalcover.com/insurances/quote' \
--header 'Content-Type: application/json' \
--header 'x-api-key: XXXXXXXXXXXXXXXXXXXXXXXXXX' \
--data-raw '
{
    "FromDate": "2027-08-01 23:59:59",
    "ToDate": "2027-08-01 23:59:59",
    "DestinationCountry": "GB",
    "CustomerAge": 52,
    "FirstName": "John",
    "LastName": "Doe",
    "Email": "[email protected]",
    "Country": "FR",
    "LanguageCode": "fr",
    "Currency": "GBP"
}

Security requirements

  • Use HTTPS for all requests. HTTP calls fail in production.

  • Store your API key in an environment variable or secrets manager. Never hard-code it.

  • Do not expose your API key in client-side JavaScript, public repositories, or logs.

  • Contact your CSE immediately if you believe your key has been compromised.

Last updated

Was this helpful?