Create an API key
curl --request POST \
--url https://api.example.com/v1/api-keys \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"name": "Storefront integration (test)",
"mode": "test",
"scopes": [
"payment_intents:write",
"payment_intents:read"
]
}
'import requests
url = "https://api.example.com/v1/api-keys"
payload = {
"name": "Storefront integration (test)",
"mode": "test",
"scopes": ["payment_intents:write", "payment_intents:read"]
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Storefront integration (test)',
mode: 'test',
scopes: ['payment_intents:write', 'payment_intents:read']
})
};
fetch('https://api.example.com/v1/api-keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/v1/api-keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Storefront integration (test)',
'mode' => 'test',
'scopes' => [
'payment_intents:write',
'payment_intents:read'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/v1/api-keys"
payload := strings.NewReader("{\n \"name\": \"Storefront integration (test)\",\n \"mode\": \"test\",\n \"scopes\": [\n \"payment_intents:write\",\n \"payment_intents:read\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/v1/api-keys")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Storefront integration (test)\",\n \"mode\": \"test\",\n \"scopes\": [\n \"payment_intents:write\",\n \"payment_intents:read\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/v1/api-keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Storefront integration (test)\",\n \"mode\": \"test\",\n \"scopes\": [\n \"payment_intents:write\",\n \"payment_intents:read\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"id": "ckkey001",
"orgId": "ckorg001",
"name": "Storefront integration (test)",
"keyPrefix": "pk_test_8Qk2pXr0aB9cD3eF7gH1iJ4k",
"testMode": true,
"scopes": [
"payment_intents:write",
"payment_intents:read"
],
"lastUsedAt": null,
"revokedAt": null,
"createdAt": "2026-06-30T12:00:00.000Z",
"secret": "pk_test_8Qk2pXr0aB9cD3eF7gH1iJ4k.s3cr3tValueShownOnceNeverAgainAbcdEfgh"
}{
"statusCode": 400,
"error": "ProductionAccessNotApproved",
"message": "Live mode is not enabled for this organization. Approved production access is required to create a live-mode key."
}API keys
Create an API key
Mint a new API key for the caller organization. The response’s secret field carries the full plaintext key pk_<mode>_<id>.<secret> and is shown EXACTLY ONCE — store it now; it is never retrievable again (only the prefix and an HMAC of the secret are persisted). Creating a live-mode key requires approved production access.
POST
/
v1
/
api-keys
Create an API key
curl --request POST \
--url https://api.example.com/v1/api-keys \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"name": "Storefront integration (test)",
"mode": "test",
"scopes": [
"payment_intents:write",
"payment_intents:read"
]
}
'import requests
url = "https://api.example.com/v1/api-keys"
payload = {
"name": "Storefront integration (test)",
"mode": "test",
"scopes": ["payment_intents:write", "payment_intents:read"]
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Storefront integration (test)',
mode: 'test',
scopes: ['payment_intents:write', 'payment_intents:read']
})
};
fetch('https://api.example.com/v1/api-keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/v1/api-keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Storefront integration (test)',
'mode' => 'test',
'scopes' => [
'payment_intents:write',
'payment_intents:read'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/v1/api-keys"
payload := strings.NewReader("{\n \"name\": \"Storefront integration (test)\",\n \"mode\": \"test\",\n \"scopes\": [\n \"payment_intents:write\",\n \"payment_intents:read\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/v1/api-keys")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Storefront integration (test)\",\n \"mode\": \"test\",\n \"scopes\": [\n \"payment_intents:write\",\n \"payment_intents:read\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/v1/api-keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Storefront integration (test)\",\n \"mode\": \"test\",\n \"scopes\": [\n \"payment_intents:write\",\n \"payment_intents:read\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"id": "ckkey001",
"orgId": "ckorg001",
"name": "Storefront integration (test)",
"keyPrefix": "pk_test_8Qk2pXr0aB9cD3eF7gH1iJ4k",
"testMode": true,
"scopes": [
"payment_intents:write",
"payment_intents:read"
],
"lastUsedAt": null,
"revokedAt": null,
"createdAt": "2026-06-30T12:00:00.000Z",
"secret": "pk_test_8Qk2pXr0aB9cD3eF7gH1iJ4k.s3cr3tValueShownOnceNeverAgainAbcdEfgh"
}{
"statusCode": 400,
"error": "ProductionAccessNotApproved",
"message": "Live mode is not enabled for this organization. Approved production access is required to create a live-mode key."
}Authorizations
apiKeybearer
Body
application/json
Required string length:
1 - 80Available options:
test, live Maximum array length:
32Available options:
payment_intents:write, payment_intents:read, invoices:write, invoices:read, webhooks:write, webhooks:read, api_keys:write, connected_accounts:write, connected_accounts:read, buyer_kyc:write, buyer_kyc:read Response
API key created — secret carries the full key pk_<mode>_<id>.<secret> and is returned this one time only.
⌘I