> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dekhq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How to send your DEKHQ id and password with PromoStandards SOAP requests and JSON requests.

Every request to the DEKHQ PromoStandards API carries your credentials: an **id** and a **password**. There are no tokens or sessions to manage. You send the same credentials with each request.

## Get credentials

Ask the decorator you work with for access. They arrange an id and a password for you.

<Warning>
  Treat your password like any other secret. Store it in your system's secret storage, don't put it in URLs or shared documents, and don't send it by email. If you think it has been exposed, contact your decorator.
</Warning>

## SOAP requests

PromoStandards puts the credentials inside the request itself, not in HTTP headers. Add these three elements to the request element of every call:

| Element | What to send |
| - | - |
| `wsVersion` | The service version: `1.0.0`. |
| `id` | Your id. |
| `password` | Your password. |

This example shows where the credentials go in an Order Status request. Replace `YOUR_ID` and `YOUR_PASSWORD` with your own credentials.

```bash theme={null}
curl -X POST https://partners.dekhq.com/api/promostandards/order-status \
  -H "Content-Type: text/xml; charset=utf-8" \
  --data '<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"
    xmlns:ns="http://www.promostandards.org/WSDL/OrderStatusService/1.0.0/">
  <soapenv:Body>
    <ns:GetOrderStatusDetailsRequest>
      <ns:wsVersion>1.0.0</ns:wsVersion>
      <ns:id>YOUR_ID</ns:id>
      <ns:password>YOUR_PASSWORD</ns:password>
      <ns:queryType>1</ns:queryType>
      <ns:referenceNumber>PO-12345</ns:referenceNumber>
    </ns:GetOrderStatusDetailsRequest>
  </soapenv:Body>
</soapenv:Envelope>'
```

The Order Shipment Notification service takes the same three elements.

## JSON requests

The [JSON endpoints](/api/overview#soap-and-json) use standard HTTP Basic authentication: your id is the username and your password is the password. Most HTTP tools and libraries handle this for you.

```bash theme={null}
curl -u "YOUR_ID:YOUR_PASSWORD" \
  "https://partners.dekhq.com/api/partners/v1/orders/status?QUERY_PARAMETERS"
```

Replace `QUERY_PARAMETERS` with the parameters for your lookup. A full reference for the JSON parameters is coming soon.

## If authentication fails

| What you sent | What you get back |
| - | - |
| SOAP request with a wrong id or password | HTTP `500` with a SOAP fault: `faultcode` `soap:Client`, `faultstring` `Invalid id or password` |
| JSON request with a wrong id or password | HTTP `401` with `{"error":"Invalid id or password"}` |
| JSON request with no credentials | HTTP `401` with `{"error":"Missing credentials — use HTTP Basic auth (id:password)"}` |

For security, the message doesn't say whether the id or the password was wrong. Check both. If they still don't work, contact your decorator.

***

<sub>Verified against DEKHQ 41cdde7 on 2026-10-09</sub>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.