Skip to content
Developer guide

Host-to-Host overview

Server-to-server integration: your backend calls ours directly. No hosted page, no redirect, no JS on your checkout.

Context and key considerations

In a host-to-host integration your server talks to ours. You authenticate with a secret key, you create the charge, and we hand you back the data your buyer needs to pay — a CLABE, a barcode, a QR string, or a redirect URL for rails that require one. You render it in your own UI. We never inject a script into your checkout and your buyer never leaves your domain unless the rail itself demands it.

1 / 4

What host-to-host means here

Concretely: every call in this section is made from your backend, with a secret key that never reaches a browser. That single constraint is what makes the model work — it is why the API can trust the caller with money movement, buyer data and payouts.

Secret keys only. Every endpoint in this section requires an sk_live_ / sk_test_ key (or a bearer token minted from one). Publishable keys (pk_*) are safe to expose in a browser or mobile app precisely because they cannot create charges, issue refunds, read customer data or send payouts. A publishable key on any of these calls returns 403 key_kind_not_allowed.
Key2Pay Developer documentationAPI v1
Documentation
Dashboard