Authentication
Every API request carries your secret key as a bearer token.
Authorization: Bearer sk_live_...curl https://api.skanpay.website/v1/balances \
-H "Authorization: Bearer $SKANPAY_SECRET_KEY"Your keys
| Key | Looks like | Use it for |
|---|---|---|
| Secret key | sk_live_… | Every API call. It can move money and read all your transactions, so it lives only on your server. |
| Publishable key | pk_live_… | Reserved for SkanPay's hosted checkout. No endpoint in this reference accepts it; using it returns publishable_key_not_allowed. |
There are no test keys and no sandbox. A key works only once SkanPay has approved your account for live payments.
Keys belong to connected apps
Each website or app you integrate is a connected app in the dashboard, with its own key pair and its own webhook URL. A shop and a mobile app on the same account keep separate credentials and separate notifications:
- A payment made with an app's key is reported to that app's webhook URL, never to a sibling app.
- Money you move from the dashboard yourself (a deposit, say) is reported to every app's webhook.
- Removing an app revokes its keys and switches off its webhook at once.
Rotating keys
Regenerate keys on the app issues a new pair and revokes the old pair immediately. Plan a rotation like this:
- Regenerate, and copy the new secret key (it is shown once).
- Deploy it to your server straight away. Requests with the old key fail with
invalid_api_keyfrom this moment. - Check the dashboard's “last used” time on the new key to confirm traffic moved.
Generating keys and revealing a webhook secret both ask for your dashboard password again, so an unattended browser tab is not enough to take a key away.
Restricting browser use to your domain
Each app has an option Restrict browser API access to its own domain. With it on, a request that comes from a web page (it carries an Origin or Referer header) on any other domain is refused with origin_not_allowed. Calls from your server send neither header and are unaffected.
Authentication errors
| HTTP | Code | Meaning |
|---|---|---|
| 401 | missing_api_key | No Authorization header. |
| 401 | invalid_api_key | Malformed, unknown, revoked, or its app was removed. |
| 403 | publishable_key_not_allowed | A pk_ key where sk_ is required. |
| 403 | live_mode_not_enabled | Account not yet approved for live payments. |
| 403 | merchant_suspended | Account suspended or closed. |
| 403 | origin_not_allowed | Browser request from a domain the app does not allow. |
The header may also be sent as the bare key, without Bearer ; both forms are accepted.