System settings
API keys
Create API keys for your website or app, and choose what each key may do.
API keys let your website, app or another system use the Payment API to create payments, check them and refund them. Each key belongs to one Brand, and payments made with it belong to that Brand.
How to call the API, with code samples and a live playground, is in the API reference.
Create a key
Start a key
Go to System Settings → API Settings and click New API Key.
Fill in the details
| Field | Meaning |
|---|---|
| Name | What the key is for, such as Website or Mobile app. |
| Abilities | What the key may do. Only the selected abilities are accepted. |
| Expires at | An optional last day the key works. Leave it empty for no expiry. |
| Is active | Whether the key works. |
Copy the key
The new key is shown straight away. Copy it into your website's or app's configuration.
Abilities
| Ability | Allows |
|---|---|
| Payment Checkout | Creating payments |
| Payment Verify | Checking a payment's status |
| Payment Refund | Refunding payments |
Give each key only what it needs. A website that only takes payments doesn't need Payment Refund.
Managing keys
The list shows each key's Name, Abilities, Expires At, Status, Last Used and Created At. Keys are shown partly hidden. From a key's menu:
| Action | What it does |
|---|---|
| View | Shows the full key, so you can copy it again. |
| Edit | Changes the name, abilities, expiry or status. The key itself stays the same. |
| Disable / Enable | Switches the key off or on. A disabled key stops working at once but isn't deleted. |
| Delete | Removes the key for good. |
Last Used shows when the key last made a successful request, which helps you find keys nothing uses any more.
Keep keys secret
Anyone with a key can use the API with that key's abilities. Keep keys on your server, never in a web page or a mobile app's code that customers can read. If a key may have leaked, disable or delete it and create a new one.
Your API address
Click Show API Endpoints to see the full addresses of the API on your installation, such as https://pay.example.com/api/checkout. API Documentation opens the API reference.
When a key is refused
| Reason | Fix |
|---|---|
| The key is missing or wrong | Check your configuration has the whole key. |
| The key is disabled | Enable it, or use another key. |
| The key has expired | Edit its expiry, or create a new key. |
| The Brand is suspended | Activate the Brand. |
| The key doesn't have the ability | Edit the key and add the ability. |
| The license isn't active | Creating payments needs an active license. |
The exact error codes are listed in the API reference.
Permissions
Viewing, creating, updating and deleting API keys each have their own permission. See Staff and roles.