Skip to main content
Every /api/v2/* endpoint requires an API key. Pass it in the x-api-key header:
API keys are issued in the merchant dashboard. Each key is bound to a single merchant.

Live and sandbox keys

A merchant has two independent keys. The live key is issued once the domain is verified; the sandbox key is available immediately and is prefixed sk_sandbox_. The prefix is what selects the environment — the host and the paths are identical — so moving an integration between them is a one-line change. See Sandbox.

Payouts and IP allowlists

Payout endpoints (POST /api/v2/payouts, POST /api/v2/payouts/batch) require the request IP to be in the merchant’s allowed_subnets. Calls from any other IP receive 403 PAYOUTS_DISABLED. Payout requests must also carry a fresh UUIDv4 in the x-uniq-id header. The same value is rejected for 2 hours, providing idempotency for retries and accidental double-submissions.

Merchant status

Requests are rejected with 403 when the merchant is in paused, pending_verification or rejected status, or when KYC is pending / rejected. Sandbox keys are exempt from the status and KYC gates — that is the point of the sandbox — except that a rejected merchant has no access to either environment.