Key types
Secret Key
Prefixed
sk_live_. Grants full server-side access to all API resources — products, checkout sessions, verifications, and more. Never expose this in frontend code.Publishable Key
Safe to include in browser JavaScript and mobile apps. Scoped to client-side checkout operations only and does not grant access to server-side resources.
Finding your API keys
Log in to the Paydios dashboard and navigate to Dashboard → API Keys. Both keys are displayed on this page alongside your Merchant ID.Using your secret key in API requests
Pass your secret key as a Bearer token in theAuthorization header of every server-side request:
curl to list your products:
Setting up your secret key as an environment variable
Store your secret key in an environment variable rather than hard-coding it in source files. The Paydios PHP SDK reads this variable automatically. Add the following to your.env file:
Using your secret key with the PHP SDK
OncePAYDIOS_SECRET_KEY is set in your environment, create the client without any arguments:
config/services.php:
Rotating your API keys
Rotate your secret key immediately if you suspect it has been compromised, or as part of a scheduled security review.1
Open the API Keys page
Log in to merchant.paydios.io/dashboard/api-keys.
2
Generate a new secret key
Click Generate new key. Your new
sk_live_ key is displayed once — copy it immediately because it will not be shown again.3
Update all environments
Replace the old key with the new one in every environment where it is used: local development, staging, and production. Update your hosting provider’s secret management, CI/CD environment variables, and any other locations where the key is stored.
4
Revoke the old key
Once all environments are updated and verified, revoke the old key from the dashboard. Requests using the revoked key will immediately return
401 Unauthorized.There is no grace period after revoking a key. Make sure all environments are updated before you revoke the old key to avoid service disruption.
Security rules
Follow these practices to keep your keys and account secure:- Use environment variables — store
PAYDIOS_SECRET_KEYin.envlocally and your hosting provider’s secret manager in production. Never hard-code key values in source files. - Keep
.envout of version control — add.envto.gitignoreand audit your repository history if you are unsure whether a key was previously committed. - Use the publishable key for client-side code — never use your secret key in browser JavaScript, mobile apps, or any code that runs on a customer’s device.
- Limit access — only the server processes and team members that genuinely need the secret key should have access to it.
- Rotate on suspicion — if you see unexpected API activity or believe the key may have been exposed, rotate it immediately.