Authentication
Merchant key, access token and security
Each merchant has its own key pair: clientId (public, starts with sp_) and clientSecret (secret, sk_).
We store only a hash of the secret, so a lost secret cannot be recovered: issue a new key instead.
Token
The response contains accessToken and expiresIn (seconds, 3600 by default). Send the token with every request:
Authorization: Bearer <accessToken>Cache the token until it expires. On a 401 with code -10002, request a new one.
Revocation
A revoked key, a disabled merchant or a suspended business stop working immediately, even if the token has not expired yet. To rotate a key without downtime, issue a new one, switch your integration over, and only then revoke the old key.
Storage
- Keep
clientSecreton your server only, never in a mobile app or a browser. - Do not log card numbers, SMS codes or secrets.