API basics
Base URL, authentication and the shape of every request and response.
The Heizen API is JSON over HTTPS.
https://api.interviewer.heizen.tech/api/v1Authentication
Send your key as a bearer token on every request:
curl https://api.interviewer.heizen.tech/api/v1/me \
-H "Authorization: Bearer $HEIZEN_API_KEY"A missing, malformed or revoked key gets 401 invalid_api_key. A valid key without the scope an endpoint needs gets 403 missing_scope, and the error names the scope. API keys lists the scopes.
Requests
- Send bodies as JSON with
Content-Type: application/json. The one exception is candidate import, which ismultipart/form-data. - Field names are
snake_case. Fields the endpoint does not define are ignored, so check spelling if a value seems to have no effect. - Timestamps are ISO 8601 in UTC, like
2026-10-01T09:30:00.000Z. - Ids carry a type prefix, like
inv_3f9c…. Treat them as opaque strings.
Responses
Every object has an id and an object field naming its type, and live or test data carries livemode. Lists use the list envelope. Deleting returns { "id": "…", "object": "…", "deleted": true }.
Useful response headers:
| Header | Meaning |
|---|---|
Request-Id | Unique per request. Quote it to support. |
RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset | Your rate limit window |
Idempotent-Replayed | true when this is a stored response to a repeated idempotent request |