Skip to content
API referenceAPI v1admin-sdk 1.1.52Search docs⌘K
API reference · Authentication
API reference / Overview

Authentication

Every request carries a bearer credential. Which one depends on who is calling.

CredentialUse it for
sk_test_…Your own server, on the test API.
sk_live_…Your own server, live. The business taking payments must be verified first.
pk_test_… / pk_live_…Publishable keys, for storefront calls from a browser.
inka_…An app acting for a merchant who installed it, within the scopes they approved. Lasts an hour. OAuth and scopes.

Secret keys belong on your server. Never put them in a browser, an app bundle or a repository.

Acting for one of your merchants

An organisation key can act for one of its merchants by adding Client-Id: m-<merchant username>. The Node SDK sets it from the username option and the Elixir SDK from merchant_username.

When a credential is refused

A missing or wrong credential, a test key on the live API (or a live key on the test API), and an app token without the scope all get 401 with result.reason "You're not authorised to access this resource."