Skip to content
SkanPay Docs

Authentication

Every API request carries your secret key as a bearer token.

Request header
Authorization: Bearer sk_live_...
curl https://api.skanpay.website/v1/balances \
  -H "Authorization: Bearer $SKANPAY_SECRET_KEY"

Your keys

KeyLooks likeUse it for
Secret keysk_live_…Every API call. It can move money and read all your transactions, so it lives only on your server.
Publishable keypk_live_…Reserved for SkanPay's hosted checkout. No endpoint in this reference accepts it; using it returns publishable_key_not_allowed.

There are no test keys and no sandbox. A key works only once SkanPay has approved your account for live payments.

Keys belong to connected apps

Each website or app you integrate is a connected app in the dashboard, with its own key pair and its own webhook URL. A shop and a mobile app on the same account keep separate credentials and separate notifications:

  • A payment made with an app's key is reported to that app's webhook URL, never to a sibling app.
  • Money you move from the dashboard yourself (a deposit, say) is reported to every app's webhook.
  • Removing an app revokes its keys and switches off its webhook at once.

Rotating keys

Regenerate keys on the app issues a new pair and revokes the old pair immediately. Plan a rotation like this:

  1. Regenerate, and copy the new secret key (it is shown once).
  2. Deploy it to your server straight away. Requests with the old key fail with invalid_api_key from this moment.
  3. Check the dashboard's “last used” time on the new key to confirm traffic moved.

Generating keys and revealing a webhook secret both ask for your dashboard password again, so an unattended browser tab is not enough to take a key away.

Restricting browser use to your domain

Each app has an option Restrict browser API access to its own domain. With it on, a request that comes from a web page (it carries an Origin or Referer header) on any other domain is refused with origin_not_allowed. Calls from your server send neither header and are unaffected.

Authentication errors

HTTPCodeMeaning
401missing_api_keyNo Authorization header.
401invalid_api_keyMalformed, unknown, revoked, or its app was removed.
403publishable_key_not_allowedA pk_ key where sk_ is required.
403live_mode_not_enabledAccount not yet approved for live payments.
403merchant_suspendedAccount suspended or closed.
403origin_not_allowedBrowser request from a domain the app does not allow.

The header may also be sent as the bare key, without Bearer ; both forms are accepted.