Create and manage API keys
Create secret keys for your integrations, see when each was last used, and rename or revoke them.
Secret keys let your servers use the 402pay API. Find them in Developers → API keys.
- 1Mode. Test keys start here. Live keys accept real payments; keep them on your server.
- 2Access. Full access, or Restricted to the resources an integration uses.
Create a secret key
- Select Create secret key.
- Name it after what will use it, such as “Store backend”.
- Choose Test or Live, and Full access or Restricted.
- Confirm it's you, then copy the secret and store it in your server's secrets.
You'll only see it once
We store only a hash of each secret, so it can't be shown again. Lose it and you'll need a new key. Never put a secret key in a browser, an app or a public repository.
Manage your keys
The list shows each key's name, mode, access, the end of its secret and when it was created and last used. From a key's menu, Rename it, Edit access or Revoke it. Revoking stops it at once and can't be undone.
What a key can't do
No API key can move money out of your wallet. Sends only happen in the dashboard, signed in your browser. See the authentication docs for how to use a key.
Was this article helpful?