openapi: 3.2.0 info: title: Parlay Key API description: Real-time sports odds aggregation from **33 books and data sources** updated every 2-120 seconds depending on source cadence. version: 3.2.0 x-credit-currency: credits x-credit-cost-catalogue-url: /v1/meta/credit-costs x-pricing-url: /v1/pricing x-usage-url: /v1/usage contact: name: ParlayAPI support url: https://parlay-api.com/support email: support@parlay-api.com license: name: ParlayAPI Terms of Service url: https://parlay-api.com/terms termsOfService: https://parlay-api.com/terms servers: - url: https://parlay-api.com description: Production (primary; HTTP/2, TLS 1.3). - url: https://api.parlay-api.com description: Production (high-volume; bypasses Cloudflare edge for trading bots above 30 req/min). Same origin, same auth, same endpoints. tags: - name: Key paths: /v1/key/successor: get: summary: Key Successor description: 'Collect the replacement for the key you are calling with. When we rotate a key (because it was exposed, or on request), the old key keeps working for a grace window and a successor is minted immediately. This endpoint hands that successor to whoever holds the current key, once, so a client can swap itself without a human copying a string out of an email: r = requests.get(BASE + "/v1/key/successor", headers={"X-API-Key": current_key}) if r.status_code == 200: save(r.json()["new_key"]) # use it from the next call onward The secret is wiped on collection, so it exists at rest only between rotation and pickup. Free: rotating a credential should never cost credits. 200 with the new key, or 404 when there is nothing to collect (the normal case, so polling this is harmless).' operationId: key_successor_v1_key_successor_get responses: '200': description: Successful Response content: application/json: schema: {} tags: - Key components: securitySchemes: apiKeyHeader: type: apiKey in: header name: X-API-Key description: API key passed in the X-API-Key header. Recommended. apiKeyQuery: type: apiKey in: query name: apiKey description: API key passed as the ?apiKey= query parameter. Useful for browser fetch() and webhooks where header control is limited. Equivalent to X-API-Key. bearerAuth: type: http scheme: bearer bearerFormat: APIKey description: 'API key passed via Authorization: Bearer . Equivalent to X-API-Key for compatibility with auth libraries that expect bearer tokens.'