Skip to content

Overview

The Luxorr API connects your platform to Luxorr gifting. Your system decides who gets a gift and when. Luxorr sources, packs and delivers it, and reports each change back.

  • Brands and campaigns: read the brands a key may use and the campaigns set up for them.
  • Catalog: list gifts for a delivery country, with estimates in your currency and in EUR. Keep a local copy in sync.
  • Orders: place an order with your own ID, then read, correct, cancel and message on it. Retries never create a second order.
  • Personal links: send gift links in batches. The player picks the gift and enters the address on the Luxorr gift site.
  • Events: receive signed webhooks, and read an event feed that replays anything you missed.
Integration Typical flow Guide
Operator shop or VIP area Show the catalog, place an order when a player redeems Operator shop
CRM or marketing automation Send a gift when a journey reaches a step CRM gifts
Platform serving many operators One key per operator Multi-operator platform
  1. Account. Each operator is one Luxorr account, called a tenant, with its own brands, catalog access and approval rules. See onboarding.
  2. Key. A key belongs to one tenant. It can be limited to some brands and to the scopes CATALOG, ORDERS and PERSONAL_LINKS. See environments and keys.
  3. Calls. Production: https://api.luxorr.io/api/public/v1. Sandbox: https://api.sandbox.luxorr.io/api/public/v1.
  4. Fulfilment. An order follows the tenant’s approval setting. Luxorr moves it to SENT with tracking, then to COMPLETED.
  5. Events. Each change to an order or a personal link is sent as an event. See webhooks and events.

Orders and links created through the API appear in the Luxorr workspace, labelled “via API” with the key name.

  • JSON with camelCase fields. Countries are ISO 3166-1 alpha-2 (DE). Locales are BCP 47 (en-US).
  • Timestamps are UTC ISO 8601 with Z, with up to six decimal places: 2026-10-05T09:12:44.512731Z. Store them at full precision. In a query string, send Z or encode + as %2B. An unencoded + answers 400 invalid_request.
  • Money is {"amount": "180.00", "currency": "EUR"}. The amount is a decimal string.
  • Authentication: Authorization: Bearer <key> on every call.
  • Every POST needs an Idempotency-Key header. See idempotency.
  • Paging: GET /catalog/products, /campaigns, /orders, /personal-links and /events take ?after=<nextCursor>&limit=<1..100> and return {items, nextCursor}. GET /brands, GET /catalog/categories and order messages return a plain array.
  • Errors are application/problem+json with a stable snake_case code. See errors.
  • A record the key may not see answers 404, the same as a record that does not exist.

No response or webhook contains a recipient’s or client’s email, phone or street address. Only the delivery country is returned.