Skip to content
Paybob

System settings

API keys

Create API keys for your website or app, and choose what each key may do.

API keys let your website, app or another system use the Payment API to create payments, check them and refund them. Each key belongs to one Brand, and payments made with it belong to that Brand.

How to call the API, with code samples and a live playground, is in the API reference.

Create a key

Start a key

Go to System Settings → API Settings and click New API Key.

Fill in the details

FieldMeaning
NameWhat the key is for, such as Website or Mobile app.
AbilitiesWhat the key may do. Only the selected abilities are accepted.
Expires atAn optional last day the key works. Leave it empty for no expiry.
Is activeWhether the key works.

Copy the key

The new key is shown straight away. Copy it into your website's or app's configuration.

Abilities

AbilityAllows
Payment CheckoutCreating payments
Payment VerifyChecking a payment's status
Payment RefundRefunding payments

Give each key only what it needs. A website that only takes payments doesn't need Payment Refund.

Managing keys

The list shows each key's Name, Abilities, Expires At, Status, Last Used and Created At. Keys are shown partly hidden. From a key's menu:

ActionWhat it does
ViewShows the full key, so you can copy it again.
EditChanges the name, abilities, expiry or status. The key itself stays the same.
Disable / EnableSwitches the key off or on. A disabled key stops working at once but isn't deleted.
DeleteRemoves the key for good.

Last Used shows when the key last made a successful request, which helps you find keys nothing uses any more.

Keep keys secret

Anyone with a key can use the API with that key's abilities. Keep keys on your server, never in a web page or a mobile app's code that customers can read. If a key may have leaked, disable or delete it and create a new one.

Your API address

Click Show API Endpoints to see the full addresses of the API on your installation, such as https://pay.example.com/api/checkout. API Documentation opens the API reference.

When a key is refused

ReasonFix
The key is missing or wrongCheck your configuration has the whole key.
The key is disabledEnable it, or use another key.
The key has expiredEdit its expiry, or create a new key.
The Brand is suspendedActivate the Brand.
The key doesn't have the abilityEdit the key and add the ability.
The license isn't activeCreating payments needs an active license.

The exact error codes are listed in the API reference.

Permissions

Viewing, creating, updating and deleting API keys each have their own permission. See Staff and roles.