1Overview
The HyGear Partner API lets an approved partner (for example, a CRM or membership system) create users in the HyGear platform and add them to one of the organizations the partner was approved for. Use it when a member signs up in your system, so the member can log in to HABEATS right away.
What you receive from HyGear
A personal API key (starts with hg_)
and the organization ID (accountId) of
each organization you may register users to.
What you send
One HTTPS POST per member with a JSON body: name,
email and, optionally, phone, gender, age or birthday, height
and weight.
2Quick start
- Get your API key and organization ID from your HyGear contact.
- Send a
POSTrequest to the endpoint below with the key in the body. - Check that the response has
"success": trueand save the returneduserId. - The new member receives a welcome email and can log in to the HABEATS app.
curl -X POST 'https://api.hygearfit.com/api/v1/integrations/users' \ -H 'Content-Type: application/json' \ -d '{ "key": "hg_YOUR_API_KEY", "accountId": "YOUR_ORGANIZATION_ID", "fullName": "Dana Cohen", "email": "dana@example.com", "phone": "+972541234567", "gender": "female", "birthday": "1990-05-17", "height": 168, "weight": 62 }'
3Authentication
Every request must include your API key. Send it in the
JSON body as key (recommended), or as a
?key= query parameter. HTTP headers are not used for the key.
{ "key": "hg_YOUR_API_KEY", "accountId": "...", "fullName": "...", "email": "..." }
POST https://api.hygearfit.com/api/v1/integrations/users?key=hg_YOUR_API_KEY
4Register a user
Request body: application/json. All requests must use
HTTPS. One request registers one user.
| Environment | Base URL |
|---|---|
| Production | https://api.hygearfit.com/api/v1/integrations/users |
| Testing (QA) | https://qa-api.hygearfit.com/api/v1/integrations/users |
5Request fields
| Field | Type | Description | |
|---|---|---|---|
key | required | string | Your API key (or send it as ?key=). |
accountId | required | string | The organization ID to add the user to. Your key must be approved for this organization. |
fullName | required | string | The member's full name. name is also accepted. |
email | required | string | A valid email. This is also the member's username in the app. |
phone | optional | string | 7–15 digits. A leading + is allowed, and spaces, dashes, dots and parentheses are ignored. |
gender | optional | string | male / female (also m / f). |
birthday | optional | string | Date of birth in YYYY-MM-DD format. Must be a past date. |
age | optional | number | Age in years, 1–120. Used only when birthday is not sent. |
height | optional | number | Height in centimeters, 50–250. |
weight | optional | number | Weight in kilograms, 20–300. |
birthday whenever you have it. When you send only
age, the system sets an estimated date of birth.
6Responses
Success — 200 OK
{
"success": true,
"message": "",
"data": {
"userId": "6ac3a7613a9a66c800dd7b21",
"accountId": "YOUR_ORGANIZATION_ID",
"created": true // false = the email already existed
}
}
Error
{
"success": false,
"message": "A valid email is required",
"data": { "errorCode": "INTEGRATION_USER_EMAIL_INVALID" }
}
Base your logic on the HTTP status and data.errorCode.
The message is meant for people to read and its wording may change.
7How users are handled
New email → new user (created: true)
A user is created and added to the organization. The member receives a welcome email in the organization's language, with HABEATS download links (iPhone and Android), the username (their email) and an initial password. No email verification is needed.
Existing email → added to the organization (created: false)
The existing user is added to the organization as is. Their details and password do not change, and no welcome email is sent.
userId with
created: false.
8Errors
| HTTP | errorCode | Meaning / what to do |
|---|---|---|
| 400 | INTEGRATION_USER_NAME_REQUIRED | Full name is required. |
| 400 | INTEGRATION_USER_EMAIL_INVALID | A valid email is required. |
| 400 | INTEGRATION_USER_PHONE_INVALID | Phone must contain 7–15 digits (optional leading +). |
| 400 | INTEGRATION_USER_BIRTHDAY_INVALID | Birthday must be a valid past date (YYYY-MM-DD). |
| 400 | INTEGRATION_USER_AGE_INVALID | Age must be a number between 1 and 120. |
| 400 | INTEGRATION_USER_HEIGHT_INVALID | Height must be a number in cm between 50 and 250. |
| 400 | INTEGRATION_USER_WEIGHT_INVALID | Weight must be a number in kg between 20 and 300. |
| 401 | INTEGRATION_API_KEY_INVALID | The key is missing, wrong, or no longer active. Check the key and the environment. |
| 403 | INTEGRATION_ACCOUNT_NOT_ALLOWED | Your key is not approved for this accountId, or the ID is missing or wrong. |
| 409 | INTEGRATION_USER_PROTECTED | This email belongs to an account that cannot be added through the API. Contact HyGear support. |
| 429 | INTEGRATION_RATE_LIMITED | Too many requests. Wait the number of seconds in the Retry-After header, then retry. |
| 5xx | — | Temporary server error. Retry later with exponential backoff. |
9Rate limits
Each API key may send up to 60 requests per minute.
Above that limit you get 429 with a
Retry-After header in seconds. For bulk imports, space
the requests out (for example, one per second), or contact us to
arrange a one-time migration.
userIds and send us the time of the request.
10Code examples
Node.js (18+)
const response = await fetch('https://api.hygearfit.com/api/v1/integrations/users', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ key: process.env.HYGEAR_API_KEY, accountId: process.env.HYGEAR_ACCOUNT_ID, fullName: 'Dana Cohen', email: 'dana@example.com', phone: '+972541234567', gender: 'female', age: 35, }), }) const result = await response.json() if (!result.success) { throw new Error(`HyGear ${response.status}: ${result.data?.errorCode}`) } console.log(result.data.userId, result.data.created)
Python
import os, requests response = requests.post( "https://api.hygearfit.com/api/v1/integrations/users", json={ "key": os.environ["HYGEAR_API_KEY"], "accountId": os.environ["HYGEAR_ACCOUNT_ID"], "fullName": "Dana Cohen", "email": "dana@example.com", "birthday": "1990-05-17", }, timeout=15, ) result = response.json() if not result.get("success"): raise RuntimeError(f"HyGear {response.status_code}: {result['data'].get('errorCode')}") print(result["data"]["userId"], result["data"]["created"])
11Security checklist
- Store the API key in a secret manager or an environment variable, never in source code.
- Call the API only from your backend over HTTPS.
- Do not write the key to your logs, and do not include it in support tickets or screenshots.
- Send only data the member has agreed to share with their organization.
- If the key may have leaked, ask HyGear to replace it. The old key stops working immediately.
12Support
For technical questions, a new key, approval for an additional
organization or help investigating a request, contact
support@hygearfit.com.
Please include the time of the request, the errorCode and the
member's email (never the API key).