API keys
Each key belongs to one business and one environment.
| Type | Prefix | Intended use |
|---|---|---|
| Public | spk_sand_ or spk_live_ | Identifies an integration where a documented client flow permits it |
| Secret | ssk_sand_ or ssk_live_ | Authenticates server-to-server API requests |
Secret keys belong only on your backend. Send one as a bearer credential:
Authorization: Bearer ssk_sand_your_secret_key
Generate a key
- Open Settings → API Keys in the merchant dashboard.
- Choose Sandbox or Live.
- Give the key a purpose-specific name such as
Checkout production. - Generate the pair and store the secret immediately.
SkyPay stores only a one-way hash of the secret and cannot reveal it later. If it is lost, revoke it and generate another. Each business may have up to five active keys per environment.
Rotate safely
- Generate the replacement key.
- Add it to your secret manager and deploy the consuming service.
- Confirm new requests use the replacement.
- Revoke the old key from the dashboard.
Revocation is immediate and permanent. Keep separate credentials for separate applications so one rotation does not interrupt every integration.