Skip to content
Developer guide

Authentication

Two-credential token flow — apiKey + secretKey → Bearer access token.

Context and key considerations

Authentication is a two-credential flow. You exchange your apiKey + secretKey pair for a short-lived Bearer access token, then send that token on every API call. Requiring both halves of the pair means a single leak (e.g. a stray log line, a shared screen) doesn't hand an attacker a working credential.

1 / 5

Your credentials

Each merchant gets two pairs — one for sandbox, one for production:

Key kindPrefixAllowed usage
Secret · productionsk_live_…Server-side only. Full access.
Secret · sandboxsk_test_…Server-side only. Sandbox cascade.
Publishable · productionpk_live_…Browser/native client. Hosted checkout only.
Publishable · sandboxpk_test_…Browser/native client. Sandbox checkout only.
The secretKey grants full API access. Store it in a secret manager — never commit it or expose it in client-side code. If a key is exposed, rotate the pair from your dashboard.
Key2Pay Developer documentationAPI v1
Documentation
Dashboard