Skip to main content
API keys allow merchants to authenticate server-to-server integrations without using Bearer tokens. Each key consists of a key ID and a secret.

Create API Key

string
required
Bearer token.

Request Body

string
required
A descriptive label for the API key (e.g., Production Server).
string[]
List of permission scopes. Defaults to all permissions. Options: payments:read, payments:write, settlements:read, settlements:write, webhooks:manage.

Example Request

Example Response (201)

The apiSecret is returned only once at creation time. Store it securely — it cannot be retrieved again.

List API Keys

Returns all API keys for the authenticated merchant. Secrets are not included in the response.

Example Response (200)


Revoke API Key

Permanently revokes an API key. This action cannot be undone.

Path Parameters

string
required
The API key identifier (e.g., key_abc123).

Example Response (200)

Error Responses

404 Not Found