Skip to content
Developer guide

Integration security

Credentials, isolation, signatures and transport — with the honest state of each control.

Context and key considerations

This section is written for the person who has to sign off on the integration. Every control below is one you can verify from the outside.

1 / 5

Credentials

Two kinds, and only one moves money

Each shop holds four credentials: a publishable and a secret key, in sandbox and in production. Only secret keys can create charges, refund, read buyer data or send payouts. A publishable key on any of those returns 403 key_kind_not_allowed. The only endpoint that accepts either is GET /ping, which exists so you can validate a credential and has no side effects.

At rest

Keys are stored encrypted with AES-256-GCM, keyed from a master key held in the environment, never in the database. Secrets are truncated in logs (first 10 characters and last 4) and never written to an error record.

Tokens

The bearer token is HS256, signed with a key derived specifically for this purpose. Verification recomputes the HMAC unconditionally and never reads the alg header, so algorithm-confusion and alg:none are not reachable. Comparison is constant-time.

Key2Pay Developer documentationAPI v1
Documentation
Dashboard