SplitPay

Authentication

Merchant key, access token and security

Keys for requests

Paste your merchant keys: the token goes into the requests below.

Each merchant has its own key pair: clientId (public, starts with sp_) and clientSecret (secret, sk_). We store only a hash of the secret, so a lost secret cannot be recovered: issue a new key instead.

Token

The response contains accessToken and expiresIn (seconds, 3600 by default). Send the token with every request:

Authorization: Bearer <accessToken>

Cache the token until it expires. On a 401 with code -10002, request a new one.

Revocation

A revoked key, a disabled merchant or a suspended business stop working immediately, even if the token has not expired yet. To rotate a key without downtime, issue a new one, switch your integration over, and only then revoke the old key.

Storage

  • Keep clientSecret on your server only, never in a mobile app or a browser.
  • Do not log card numbers, SMS codes or secrets.

On this page