Authorization HTTP header. There are no sessions, cookies, or OAuth flows — every request is authenticated independently using the key you provide. Your keys are scoped to your merchant account and grant access to all resources within it, so keeping them secure is essential.
Get your API keys
Log in to the merchant dashboard and navigate to Dashboard → API Keys at merchant.paydios.io/dashboard/api-keys. You will find two types of credential: Secret Key (sk_live_xxxxxxxxx) — your secret key grants full server-side access to all API resources: creating products, opening checkout sessions, verifying payments, and more. Use this key only on your server. Never expose it in frontend code, browser-side JavaScript, mobile apps, or public repositories.
Publishable Key — your publishable key is safe to include in client-side code and is intended for browser or mobile-based checkout flows only. It does not grant access to server-side resources.
You will also find your Merchant ID on the same page. Some API endpoints (such as checkout session creation and verification) require your Merchant ID in the URL path alongside your secret key in the header.
Authenticate requests
Pass your secret key as a Bearer token in theAuthorization header of every request:
curl to list your products:
With the PHP SDK
The PHP SDK handles authentication automatically. Set your secret key as an environment variable and the SDK picks it up on initialisation — you do not need to pass it in every call. Add your key to your.env file:
config/services.php and pass them to the client:
Security best practices
Follow these practices to keep your keys secure:- Store keys in environment variables, not hard-coded in source files. Use
.envlocally and your hosting provider’s secret management in production. - Add
.envto.gitignoreso it is never committed to version control. - Use the publishable key for client-side checkout — it is scoped to checkout-only operations and is safe to include in browser code.
- Rotate your secret key immediately if you suspect it has been compromised. Generate a new key in the dashboard at merchant.paydios.io/dashboard/api-keys and update all server environments.
- Restrict access to the server processes and team members that genuinely need the secret key.