All API requests require a bearer token in the Authorization header:Authorization: Bearer sk_live_xxxxxxxx
API keys#
| Prefix | Environment | Entity |
|---|
sk_live_... | Live | Partner or Reseller (depends on the key issued) |
sk_test_... | Test | Partner or Reseller (depends on the key issued) |
The key prefix selects the environment automatically.
The key type selects the entity. Partner endpoints reject reseller keys and vice versa
(401 Unauthenticated).
Keys are matched by SHA-256 hash. Inactive entities are rejected.
Repeated invalid authentication attempts are rate-limited: 5 failures per 60 seconds → 429.
Example#
Security#
Store keys securely. Never expose them in client-side code or public repositories.
Use test keys during development; switch to live keys only in production.
Modified at 2026-07-21 11:59:45