Authentication

The API authenticates every request with a secret API key sent as a Bearer token. There are no other auth schemes.

API keys

Create and manage keys from Business → Developers in your dashboard. A key is a string that starts with sk_live_ followed by random hex. The full secret is shown only once at creation; afterwards you can identify it by its prefix (for example sk_live_ab12cd34).

Authenticating requests

Send your key in the Authorization header using the Bearer scheme. Requests without a valid key receive 401 unauthorized.

curl "https://markgroup.app/api/v1/balance" \
  -H "Authorization: Bearer sk_live_your_key_here"

Key scopes

Each key has a scope that determines what it can do:

ScopeCan doCannot do
readGET endpoints — read balance, invoices, payment links, and payments.Create invoices or payment links.
writeEverything a read key can do, plus create invoices and payment links.—

Using a read-only key on a write endpoint returns 403 forbidden. Issue separate keys for separate jobs so a component that only needs to read data never holds write access.

Keeping keys safe

  • Only use keys from server-side code. Never ship them in a browser, mobile binary, or public repo.
  • Store them in environment variables or a secrets manager, never in source control.
  • Give each integration its own key so you can revoke one without disrupting the others.
  • Rotate a key immediately if you suspect it leaked — revoke the old one from the dashboard.

Leaked a key?

Revoke it right away in Business → Developers. Revoked keys stop working immediately and any request using them returns 401 unauthorized.

Hitting rate limits or unexpected errors? See Rate limits and Errors.