Skip to content

Authentication

Authenticate with a secret key, scope it per resource, and keep it safe.

Send your secret key as a bearer token in the Authorization header. A key belongs to one business, and every request made with it acts as that business. The same key works on both of the API's base URLs.

Authenticated request
curl "https://api.402pay.co/api/v1/payments?limit=1" \
  -H "Authorization: Bearer $PAY402_SECRET_KEY"

Key types

PrefixKindUse
402s_live_SecretServer-side requests. Every payment it creates is real.
402p_…PublishableReserved for browser-side use later. Nothing accepts it today: an endpoint that needs a key answers it with 401 invalid_api_key, so you can ignore it for now.
Keep secret keys on your server and out of source control. Only a hash is stored, so a lost secret can't be shown again: create a new key, then revoke the old one.

In the dashboard: Create and manage API keys.

Restricted keys

A secret key has full access, or a level per resource: none, read or write. GET requests need read and every other method needs write, so a key that only reports on payments can't create one.

ResourceCovers
PaymentsPayments and metrics.
LinksPayment links.
CustomersCustomer records.
WalletBalances, addresses and notes.
WebhooksEndpoints, deliveries and test events.
EventsThe event log. Read only.
Checkout settingsAccepted coins, rails and redirects.
Money never moves on an API key. Sends from your wallet happen in the dashboard, signed in your browser with your encryption password.

Errors

StatusCodeWhen
401unauthenticatedNo key was sent. The response has a WWW-Authenticate: Bearer header.
401invalid_api_keyThe key is invalid or revoked, or it's a publishable key.
401invalid_api_keyThe Authorization header isn't Bearer, a space and the key, such as when the Bearer prefix is missing.
403business_forbiddenThe request also sent a 402pay-Business header naming another business. A key acts only as its own business, so leave the header out.
403permission_deniedA restricted key doesn't have the access the route needs.
403session_requiredThe route is for the dashboard only, such as managing API keys or sending from your wallet.