API Keys
Authenticate your server-to-server requests and POS integrations.
⚠️
Test environment only
These are sk_test_* keys for the sandbox — they cannot move real money. Live keys (sk_live_*) are only accessible from your backend dashboard and are never surfaced in the browser.
Active keys 2
Revoked keys
Send your key in the X-API-Key header on every request. Never include it in client-side code, URLs, or commit it to version control. See the API Reference for authentication examples.