Skip to content

Getting Started

This page covers the path from no credentials to your first successful API call in the sandbox.

1. Request sandbox access

Contact your sales representative or email techsupport@northcapital.com to request sandbox access. You will get a login for the sandbox Transact Portal.

2. Find your API credentials

In the Transact Portal, open the Administrative tab to find your Client ID and API key. Keep the API key secret. Load it from an environment variable or a secrets store, and never commit it to source control.

Sandbox and production each have their own Client ID and API keys, and their own API base URL:

Environment API base URL
Sandbox https://api-sandboxdash.norcapsecurities.com/v3/
Production https://api.norcapsecurities.com/v3/

Everything in this guide uses the sandbox. You receive production credentials after Pre-Live Certification; see step 5.

3. Make your first request

Send your credentials on every request in the Authorization header, as a Bearer token made of your Client ID and API key separated by a colon:

Authorization: Bearer {clientID}:{apiKey}

GET requests have no body, so send their credentials in this header. See Authorization Headers for details and examples in other languages.

Every example in this documentation reads the host and credentials from three environment variables, so export them once and the examples run as written. TAPI_HOST is the host only — each example spells out its own path:

export TAPI_HOST=https://api-sandboxdash.norcapsecurities.com
export TAPI_CLIENT_ID=NC00000
printf 'API key: ' && read -rs TAPI_API_KEY && export TAPI_API_KEY

Running the Examples covers this for Windows, for .env files, and how to keep the key out of your shell history and source control.

Call ping to confirm the API is reachable and your credentials are valid:

curl -X GET "$TAPI_HOST/v3/ping" \
  -H "Authorization: Bearer $TAPI_CLIENT_ID:$TAPI_API_KEY"

A valid key returns:

{
  "status": "ok"
}

Any other response carries a statusCode. Look it up in Error Codes. See Health Check for details on ping.

ping is a resource-style endpoint. TransactAPI also has older method-style endpoints that name an operation in the path, such as POST /v3/getTrade. When both exist, use the resource-style one. See Endpoint Styles.

4. Build your integration

The Developer Guide follows a typical integration in order:

  1. Set up an offering
  2. Register webhooks
  3. Onboard investors
  4. Qualify investors with KYC/AML, suitability, and accreditation checks
  5. Create the trade and send subscription documents
  6. Collect payment
  7. Settle and manage the offering

The API Reference documents every endpoint.

5. Go live

When your sandbox integration is complete, schedule a Pre-Live Certification to get production keys. See Obtaining Production Keys. Production use is billed. See the Fee Schedule.