PayoFlux
Developers

Authentication
API Keys Done Right

Authenticate payment requests with live and test API keys, path-aware enforcement, and credential rotation from the merchant portal.

Overview

Keys that match the environment you intend to call

PayoFlux issues separate live and test secret keys per merchant. The API layer enforces that test keys cannot call live paths and live keys cannot call test paths. Merchants can rotate credentials and manage related secrets such as encryption keys and webhook hashes from their account.

What you get
  • Live secret keys
  • Test secret keys
  • Path-aware enforcement
  • Credential rotation
  • Related webhook/encryption secrets
How It Works

How API authentication works

01

Generate credentials

Create or view API credentials in the merchant portal after your account is ready for integration.

02

Attach key to requests

Include the correct secret key when calling charge, status, hosted, or related payment endpoints.

03

Environment enforcement

If a key/path mismatch occurs, the request is rejected — protecting you from accidental live charges during testing.

04

Rotate when needed

Rotate keys after staffing changes, suspected exposure, or routine security policy intervals.

Business Value

Why merchants use this

Safer defaults

Environment mismatch protection reduces costly operational mistakes.

Merchant-controlled secrets

Rotate credentials without waiting on opaque provider support processes.

Use Cases

Where this fits your business

Multi-stage deployments

Keep staging on test keys and production on live keys with clear separation.

Security incidents

Rotate keys quickly if a secret may have leaked from a repository or log.

Related

Continue exploring

Simplify Payments with PayoFlux

One platform to accept, manage, and scale your payment operations.

Get started with PayoFlux