Skip to content
Developer guide

The complete flow

Six steps from credentials to a settled charge, with the real request and response of each.

Context and key considerations

Six steps. Steps 1 and 2 happen once per session; 3 through 6 happen per charge.

1 / 6

1. Authenticate

You can send your sk_ key as the bearer on every call and skip this step entirely. Exchanging it for a token is optional and worth it at volume: the token is verified with an HMAC instead of a credential lookup.

bash
curl -X POST https://sandbox.key2pay.ai/api/v1/auth/token \
  -H "Content-Type: application/json" \
  -d '{"apiKey":"pk_test_…","secretKey":"sk_test_…"}'

Returns an accessToken valid for 1 hour and a refreshToken valid for 30 days, plus the shop the credentials belong to.

Rotating the token does not break idempotency. The idempotency scope is anchored to your merchant, not to the token, so a retry that happens after a refresh still deduplicates against the original request. Same for your rate limit: it is per merchant and reflects your tier.
Key2Pay Developer documentationAPI v1
Documentation
Dashboard