Skip to content
HILLS API v1 Early access

API reference

Account

Check a key: the client account behind it, its scopes, plan and rate limit.

Check a key: the client account behind it, its scopes, plan and rate limit.

Base URL https://app.hillsmusic.com/api/v1. Every request sends an API key: Authorization: Bearer hm_live_… (production) or hm_test_… (sandbox).

  • Who am I
  • Connection check

Who am I

GET /api/v1/me · Any valid key

The client account the key belongs to, and the key’s own name, scopes and expiry. Handy to check a key works.

Example request

curl "https://app.hillsmusic.com/api/v1/me" \
  -H "Authorization: Bearer $HILLS_API_KEY"

Response 200

{
  "partner": {
    "id": 12,
    "name": "Nova Records",
    "email": "ops@novarecords.com"
  },
  "environment": "production",
  "key": {
    "id": 3,
    "name": "ERP sync",
    "prefix": "hm_live_ab12cd34",
    "environment": "production",
    "scopes": [
      "catalog:read",
      "earnings:read"
    ],
    "expires_at": null,
    "created_at": "2026-10-01T09:00:00Z"
  }
}

Errors

Status When
401 unauthenticated, invalid_key, key_revoked or key_expired.
403 account_inactive or api_not_in_plan.
429 rate_limited: wait Retry-After seconds.

Connection check

GET /api/v1/ping · Any valid key

Any valid key: the account, plan, the key’s scopes, the rate limit left and the server time. The call shows up on the DDEX delivery page (Connection, Activity).

Example request

curl "https://app.hillsmusic.com/api/v1/ping" \
  -H "Authorization: Bearer $HILLS_API_KEY"

Response 200

{
  "ok": true,
  "environment": "production",
  "server_time": "2026-10-07T09:00:00.000Z",
  "account": {
    "id": 12,
    "name": "Nova Records",
    "email": "ops@novarecords.com"
  },
  "plan": {
    "included": true,
    "plan": "enterprise",
    "rate": 120
  },
  "key": {
    "prefix": "hm_live_ab12cd34",
    "scopes": [
      "ddex:write"
    ]
  },
  "rate_limit": {
    "limit": 120,
    "remaining": 119
  }
}

Errors

Status When
401 unauthenticated, invalid_key, key_revoked or key_expired.
403 account_inactive or api_not_in_plan.
429 rate_limited: wait Retry-After seconds.

Ready to integrate?

Request API access and we get back to you within 1–3 business days.