Overview
The Luxorr API connects your platform to Luxorr gifting. Your system decides who gets a gift and when. Luxorr sources, packs and delivers it, and reports each change back.
Capabilities
Section titled “Capabilities”- Brands and campaigns: read the brands a key may use and the campaigns set up for them.
- Catalog: list gifts for a delivery country, with estimates in your currency and in EUR. Keep a local copy in sync.
- Orders: place an order with your own ID, then read, correct, cancel and message on it. Retries never create a second order.
- Personal links: send gift links in batches. The player picks the gift and enters the address on the Luxorr gift site.
- Events: receive signed webhooks, and read an event feed that replays anything you missed.
Use cases
Section titled “Use cases”| Integration | Typical flow | Guide |
|---|---|---|
| Operator shop or VIP area | Show the catalog, place an order when a player redeems | Operator shop |
| CRM or marketing automation | Send a gift when a journey reaches a step | CRM gifts |
| Platform serving many operators | One key per operator | Multi-operator platform |
How it works
Section titled “How it works”- Account. Each operator is one Luxorr account, called a tenant, with its own brands, catalog access and approval rules. See onboarding.
- Key. A key belongs to one tenant. It can be limited to some brands and to the scopes
CATALOG,ORDERSandPERSONAL_LINKS. See environments and keys. - Calls. Production:
https://api.luxorr.io/api/public/v1. Sandbox:https://api.sandbox.luxorr.io/api/public/v1. - Fulfilment. An order follows the tenant’s approval setting. Luxorr moves it to
SENTwith tracking, then toCOMPLETED. - Events. Each change to an order or a personal link is sent as an event. See webhooks and events.
Orders and links created through the API appear in the Luxorr workspace, labelled “via API” with the key name.
Conventions
Section titled “Conventions”- JSON with camelCase fields. Countries are ISO 3166-1 alpha-2 (
DE). Locales are BCP 47 (en-US). - Timestamps are UTC ISO 8601 with
Z, with up to six decimal places:2026-10-05T09:12:44.512731Z. Store them at full precision. In a query string, sendZor encode+as%2B. An unencoded+answers400 invalid_request. - Money is
{"amount": "180.00", "currency": "EUR"}. The amount is a decimal string. - Authentication:
Authorization: Bearer <key>on every call. - Every
POSTneeds anIdempotency-Keyheader. See idempotency. - Paging:
GET /catalog/products,/campaigns,/orders,/personal-linksand/eventstake?after=<nextCursor>&limit=<1..100>and return{items, nextCursor}.GET /brands,GET /catalog/categoriesand order messages return a plain array. - Errors are
application/problem+jsonwith a stable snake_casecode. See errors. - A record the key may not see answers
404, the same as a record that does not exist.
Personal data
Section titled “Personal data”No response or webhook contains a recipient’s or client’s email, phone or street address. Only the delivery country is returned.
Next steps
Section titled “Next steps”- Getting started: first calls in the sandbox.
- API reference: every endpoint, field and event.