Accept your first payment in five minutes
1. Create your account
Register at dashboard.skypay.ng, verify your email, and create or select a business.
2. Generate a Sandbox key
Open Settings → API Keys, select Sandbox, and generate a key pair. Save the ssk_sand_... secret immediately; SkyPay shows it only once.
3. Initiate the payment
Amounts are integer kobo. 500000 means ₦5,000.00.
const response = await fetch('https://api.skypay.ng/api/v1/payments/initiate', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.SKYPAY_SECRET_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({
amount: 500000,
currency: 'NGN',
callbackUrl: 'https://yoursite.com/payment/callback',
idempotencyKey: crypto.randomUUID(),
}),
})
const body = await response.json()
if (!response.ok) throw new Error(body.error?.message ?? 'Payment failed')
console.log(body.data.reference, body.data.checkoutUrl)
curl --request POST 'https://api.skypay.ng/api/v1/payments/initiate' \
--header "Authorization: Bearer $SKYPAY_SECRET_KEY" \
--header 'Content-Type: application/json' \
--data '{
"amount": 500000,
"currency": "NGN",
"customerEmail": "[email protected]",
"callbackUrl": "https://yoursite.com/payment/callback",
"idempotencyKey": "order-1048-payment-1"
}'
4. Redirect the payer
Send the customer's browser to body.data.checkoutUrl. Do not open the URL from your backend. The hosted checkout handles processor selection and payment status.
5. Handle the webhook
Register an endpoint under Settings → Webhooks and subscribe to payment events. Verify X-SkyPay-Signature against the raw request body before processing an event.
6. Verify server-side
After the customer returns, and whenever your webhook changes an order, retrieve the transaction from your backend:
const response = await fetch(
`https://api.skypay.ng/api/v1/payments/${reference}`,
{ headers: { Authorization: `Bearer ${process.env.SKYPAY_SECRET_KEY}` } }
)
const body = await response.json()
if (body.data?.status === 'SUCCESS') {
// Confirm amount and currency, then fulfil the order exactly once.
}
Never deliver value based only on the browser redirect or query string. Continue with payment initiation and webhook signatures.