Getting started

Mulai integrasi dengan Sipajak API dalam hitungan menit: kenali environment staging dan production, cara autentikasi HTTP Basic, header npwp wajib, dan aturan versioning URL. Kredensial API diberikan oleh tim Sipajak, ajukan lewat tombol Minta Akses API.

2.1 Base URLs

The API is available in two environments:

EnvironmentBase URLNotes
Productionhttps://gateway-integration.sipajak.comLive DJP integration
Staginghttps://staging-gateway-integration.sipajak.comMirrors production surface; integrates with DJP non-production

Staging is the only environment available for integration testing. Do not run automated tests against production.

2.2 Authentication

The API uses HTTP Basic Authentication at the transport layer. Credentials (username and password) are issued privately by the Sipajak team after your access request is approved — there is no self-service signup and no credential is published in this documentation or in any public Postman workspace. To get credentials, use the Minta Akses API button; staging credentials come first, production credentials after your staging integration is verified. Credentials are long-lived and not rotated automatically; store them in a secret manager and rotate them yourself if your security policy requires it.

Authorization: Basic base64(username:password)

A single credential pair can serve multiple NPWPs belonging to the same client. The active NPWP for each request is selected via the npwp header (see next section). New NPWPs must be registered against the credential before they can be used, by calling POST /v1/organization (covered in a later revision).

2.3 The npwp header

Every request must include the npwp header naming the organisation the call is acting on behalf of.

npwp: 1234567890123000

Requests without this header, or with an NPWP not registered to the authenticated credential, will be rejected with HTTP 403.

2.4 URL versioning

Paths are prefixed with a version segment (/v1/, /v2/). Versions coexist; clients may mix them in the same session. Newer endpoints generally live under /v2/. Each endpoint reference in this document states its version explicitly.