Authentication
The API authenticates every request with a secret API key sent as a Bearer token. There are no other auth schemes.
API keys
Create and manage keys from Business → Developers in your dashboard. A key is a string that starts with sk_live_ followed by random hex. The full secret is shown only once at creation; afterwards you can identify it by its prefix (for example sk_live_ab12cd34).
Authenticating requests
Send your key in the Authorization header using the Bearer scheme. Requests without a valid key receive 401 unauthorized.
Key scopes
Each key has a scope that determines what it can do:
| Scope | Can do | Cannot do |
|---|---|---|
read | GET endpoints — read balance, invoices, payment links, and payments. | Create invoices or payment links. |
write | Everything a read key can do, plus create invoices and payment links. | — |
Using a read-only key on a write endpoint returns 403 forbidden. Issue separate keys for separate jobs so a component that only needs to read data never holds write access.
Keeping keys safe
- Only use keys from server-side code. Never ship them in a browser, mobile binary, or public repo.
- Store them in environment variables or a secrets manager, never in source control.
- Give each integration its own key so you can revoke one without disrupting the others.
- Rotate a key immediately if you suspect it leaked — revoke the old one from the dashboard.
Leaked a key?
Revoke it right away in Business → Developers. Revoked keys stop working immediately and any request using them returns401 unauthorized.Hitting rate limits or unexpected errors? See Rate limits and Errors.