PartnerApi backs the panel at https://panel.hular.dev. Everything it exposes is scoped to one partner: your keys, your orders, your referral earnings. It is a separate service from HularApi and uses session tokens rather than API keys.

Signing in

There is no password. Request a code by email, then exchange it for a session. Requesting a code requires a Cloudflare Turnstile token, minted by the widget on the panel’s sign-in form.
Requesting codes in quick succession is throttled: a second request inside a minute is rejected rather than sending another email. Turnstile tokens are single-use and short-lived, so each request needs a fresh one; deployments without a configured Turnstile secret skip the check. Every other PartnerApi call needs the token in an authorization: Bearer header. An expired or unknown token returns UNAUTHENTICATED. Logout invalidates the session immediately.

API keys

The key value is returned on the key objects, so a partner can retrieve an existing key rather than rotating when it is misplaced. Treat it as a secret regardless: it carries your rate limit and your attribution. Key changes are cached briefly on the API side, so a new or revoked key takes a few seconds to take effect. See API keys.

Usage

The Usage tab charts your API traffic per key: requests over time split by status (ok, rate limited, error), rate limit points consumed, and a per-method breakdown of calls and errors. Use it to see which methods are eating your budget and whether you are hitting the limit. The same data is available programmatically:
See GetPartnerApiStats for the bounds on range and step, and API keys for how points and costs work.

Sessions

The Sessions tab lists every live sign-in on the account: the device it came from, every IP it has been used from with a best-effort location, when it was created, when it was last active, and when it expires.
A session can revoke the account’s other sessions only once it is at least 6 hours old, so a freshly stolen token cannot immediately evict you; can_revoke on the listing says whether yours qualifies. Revoking your own current session is Logout.

Your orders

ListPartnerOrders returns orders attributed to your keys, newest first, cursor-paginated.
api_key_name is what makes this useful across surfaces: issue one key per application and the attribution comes back for free.

Referrals and vouchers

See Referral program for what the voucher is and how redemption works on each chain.
Do not embed a partner session token in a client application. It grants key management and claiming. Sessions belong in the panel or in a backend you control.