HyGear
Partner API v1 Release 3.0.4 עברית

User Registration API

Register your members directly into their organization on HyGear. Each new user gets a welcome email with download links for the HABEATS app and their login details, and can start training right away.

1Overview

The HyGear Partner API lets an approved partner (for example, a CRM or membership system) create users in the HyGear platform and add them to one of the organizations the partner was approved for. Use it when a member signs up in your system, so the member can log in to HABEATS right away.

What you receive from HyGear

A personal API key (starts with hg_) and the organization ID (accountId) of each organization you may register users to.

What you send

One HTTPS POST per member with a JSON body: name, email and, optionally, phone, gender, age or birthday, height and weight.

2Quick start

  1. Get your API key and organization ID from your HyGear contact.
  2. Send a POST request to the endpoint below with the key in the body.
  3. Check that the response has "success": true and save the returned userId.
  4. The new member receives a welcome email and can log in to the HABEATS app.
cURL
curl -X POST 'https://api.hygearfit.com/api/v1/integrations/users' \
  -H 'Content-Type: application/json' \
  -d '{
    "key": "hg_YOUR_API_KEY",
    "accountId": "YOUR_ORGANIZATION_ID",
    "fullName": "Dana Cohen",
    "email": "dana@example.com",
    "phone": "+972541234567",
    "gender": "female",
    "birthday": "1990-05-17",
    "height": 168,
    "weight": 62
  }'

3Authentication

Every request must include your API key. Send it in the JSON body as key (recommended), or as a ?key= query parameter. HTTP headers are not used for the key.

Key in the body (recommended)
{ "key": "hg_YOUR_API_KEY", "accountId": "...", "fullName": "...", "email": "..." }
Key in the query string
POST https://api.hygearfit.com/api/v1/integrations/users?key=hg_YOUR_API_KEY
Keep the key secret Call the API only from your server, never from a browser or a mobile app. If you think the key leaked, contact HyGear right away. We will issue a new key, and the old one stops working immediately.

4Register a user

POST https://api.hygearfit.com/api/v1/integrations/users

Request body: application/json. All requests must use HTTPS. One request registers one user.

EnvironmentBase URL
Productionhttps://api.hygearfit.com/api/v1/integrations/users
Testing (QA)https://qa-api.hygearfit.com/api/v1/integrations/users
Separate keys per environment Production and testing use different API keys and organization IDs. A testing key does not work in production, and a production key does not work in testing.

5Request fields

FieldTypeDescription
keyrequiredstringYour API key (or send it as ?key=).
accountIdrequiredstringThe organization ID to add the user to. Your key must be approved for this organization.
fullNamerequiredstringThe member's full name. name is also accepted.
emailrequiredstringA valid email. This is also the member's username in the app.
phoneoptionalstring7–15 digits. A leading + is allowed, and spaces, dashes, dots and parentheses are ignored.
genderoptionalstringmale / female (also m / f).
birthdayoptionalstringDate of birth in YYYY-MM-DD format. Must be a past date.
ageoptionalnumberAge in years, 1–120. Used only when birthday is not sent.
heightoptionalnumberHeight in centimeters, 50–250.
weightoptionalnumberWeight in kilograms, 20–300.
Tip Send birthday whenever you have it. When you send only age, the system sets an estimated date of birth.

6Responses

Success — 200 OK

JSON
{
  "success": true,
  "message": "",
  "data": {
    "userId": "6ac3a7613a9a66c800dd7b21",
    "accountId": "YOUR_ORGANIZATION_ID",
    "created": true   // false = the email already existed
  }
}

Error

JSON
{
  "success": false,
  "message": "A valid email is required",
  "data": { "errorCode": "INTEGRATION_USER_EMAIL_INVALID" }
}

Base your logic on the HTTP status and data.errorCode. The message is meant for people to read and its wording may change.

7How users are handled

New email → new user (created: true)

A user is created and added to the organization. The member receives a welcome email in the organization's language, with HABEATS download links (iPhone and Android), the username (their email) and an initial password. No email verification is needed.

Existing email → added to the organization (created: false)

The existing user is added to the organization as is. Their details and password do not change, and no welcome email is sent.

Safe to retry Sending the same email again does not create a duplicate user. The response returns the same userId with created: false.
Initial password The initial password follows a rule agreed with HyGear for your integration, and is sent to the member in the welcome email. Members are encouraged to change it after their first login. You do not need to send or store passwords.

8Errors

HTTPerrorCodeMeaning / what to do
400INTEGRATION_USER_NAME_REQUIREDFull name is required.
400INTEGRATION_USER_EMAIL_INVALIDA valid email is required.
400INTEGRATION_USER_PHONE_INVALIDPhone must contain 7–15 digits (optional leading +).
400INTEGRATION_USER_BIRTHDAY_INVALIDBirthday must be a valid past date (YYYY-MM-DD).
400INTEGRATION_USER_AGE_INVALIDAge must be a number between 1 and 120.
400INTEGRATION_USER_HEIGHT_INVALIDHeight must be a number in cm between 50 and 250.
400INTEGRATION_USER_WEIGHT_INVALIDWeight must be a number in kg between 20 and 300.
401INTEGRATION_API_KEY_INVALIDThe key is missing, wrong, or no longer active. Check the key and the environment.
403INTEGRATION_ACCOUNT_NOT_ALLOWEDYour key is not approved for this accountId, or the ID is missing or wrong.
409INTEGRATION_USER_PROTECTEDThis email belongs to an account that cannot be added through the API. Contact HyGear support.
429INTEGRATION_RATE_LIMITEDToo many requests. Wait the number of seconds in the Retry-After header, then retry.
5xx—Temporary server error. Retry later with exponential backoff.

9Rate limits

Each API key may send up to 60 requests per minute. Above that limit you get 429 with a Retry-After header in seconds. For bulk imports, space the requests out (for example, one per second), or contact us to arrange a one-time migration.

Request log HyGear logs every request your key sends (success or failure, with the key removed), so we can help you investigate a specific issue. Keep your userIds and send us the time of the request.

10Code examples

Node.js (18+)

JavaScript
const response = await fetch('https://api.hygearfit.com/api/v1/integrations/users', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({
    key: process.env.HYGEAR_API_KEY,
    accountId: process.env.HYGEAR_ACCOUNT_ID,
    fullName: 'Dana Cohen',
    email: 'dana@example.com',
    phone: '+972541234567',
    gender: 'female',
    age: 35,
  }),
})
const result = await response.json()
if (!result.success) {
  throw new Error(`HyGear ${response.status}: ${result.data?.errorCode}`)
}
console.log(result.data.userId, result.data.created)

Python

Python
import os, requests

response = requests.post(
    "https://api.hygearfit.com/api/v1/integrations/users",
    json={
        "key": os.environ["HYGEAR_API_KEY"],
        "accountId": os.environ["HYGEAR_ACCOUNT_ID"],
        "fullName": "Dana Cohen",
        "email": "dana@example.com",
        "birthday": "1990-05-17",
    },
    timeout=15,
)
result = response.json()
if not result.get("success"):
    raise RuntimeError(f"HyGear {response.status_code}: {result['data'].get('errorCode')}")
print(result["data"]["userId"], result["data"]["created"])

11Security checklist

  • Store the API key in a secret manager or an environment variable, never in source code.
  • Call the API only from your backend over HTTPS.
  • Do not write the key to your logs, and do not include it in support tickets or screenshots.
  • Send only data the member has agreed to share with their organization.
  • If the key may have leaked, ask HyGear to replace it. The old key stops working immediately.

12Support

For technical questions, a new key, approval for an additional organization or help investigating a request, contact support@hygearfit.com. Please include the time of the request, the errorCode and the member's email (never the API key).