API reference · Authentication
API reference / Overview
Authentication
Every request carries a bearer credential. Which one depends on who is calling.
| Credential | Use it for |
|---|---|
sk_test_… | Your own server, on the test API. |
sk_live_… | Your own server, live. The business taking payments must be verified first. |
pk_test_… / pk_live_… | Publishable keys, for storefront calls from a browser. |
inka_… | An app acting for a merchant who installed it, within the scopes they approved. Lasts an hour. OAuth and scopes. |
Secret keys belong on your server. Never put them in a browser, an app bundle or a repository.
Acting for one of your merchants
An organisation key can act for one of its merchants by adding Client-Id: m-<merchant username>. The Node SDK sets it from the username option and the Elixir SDK from merchant_username.
When a credential is refused
A missing or wrong credential, a test key on the live API (or a live key on the test API), and an app token without the scope all get 401 with result.reason "You're not authorised to access this resource."