Skip to main content
Paydios uses API keys to authenticate every request you make to the Merchant API. You have two types of key — a secret key for server-side calls and a publishable key for client-side checkout flows. This page explains the difference, how to create and manage your keys, and how to keep them secure.

Key types

Secret Key

Prefixed sk_live_. Grants full server-side access to all API resources — products, checkout sessions, verifications, and more. Never expose this in frontend code.

Publishable Key

Safe to include in browser JavaScript and mobile apps. Scoped to client-side checkout operations only and does not grant access to server-side resources.

Finding your API keys

Log in to the Paydios dashboard and navigate to Dashboard → API Keys. Both keys are displayed on this page alongside your Merchant ID.

Using your secret key in API requests

Pass your secret key as a Bearer token in the Authorization header of every server-side request:
Here is a complete example using curl to list your products:
And an example that creates a checkout session (which also requires your Merchant ID in the path):

Setting up your secret key as an environment variable

Store your secret key in an environment variable rather than hard-coding it in source files. The Paydios PHP SDK reads this variable automatically. Add the following to your .env file:
Never commit your .env file to version control. Add it to .gitignore immediately and check that it has not already been committed before pushing to a remote repository.

Using your secret key with the PHP SDK

Once PAYDIOS_SECRET_KEY is set in your environment, create the client without any arguments:
You can also pass the key explicitly if you prefer:
In a Laravel application, register the key in config/services.php:
Then pass the config array to the client:

Rotating your API keys

Rotate your secret key immediately if you suspect it has been compromised, or as part of a scheduled security review.
1

Open the API Keys page

2

Generate a new secret key

Click Generate new key. Your new sk_live_ key is displayed once — copy it immediately because it will not be shown again.
3

Update all environments

Replace the old key with the new one in every environment where it is used: local development, staging, and production. Update your hosting provider’s secret management, CI/CD environment variables, and any other locations where the key is stored.
4

Revoke the old key

Once all environments are updated and verified, revoke the old key from the dashboard. Requests using the revoked key will immediately return 401 Unauthorized.
There is no grace period after revoking a key. Make sure all environments are updated before you revoke the old key to avoid service disruption.

Security rules

Follow these practices to keep your keys and account secure:
  • Use environment variables — store PAYDIOS_SECRET_KEY in .env locally and your hosting provider’s secret manager in production. Never hard-code key values in source files.
  • Keep .env out of version control — add .env to .gitignore and audit your repository history if you are unsure whether a key was previously committed.
  • Use the publishable key for client-side code — never use your secret key in browser JavaScript, mobile apps, or any code that runs on a customer’s device.
  • Limit access — only the server processes and team members that genuinely need the secret key should have access to it.
  • Rotate on suspicion — if you see unexpected API activity or believe the key may have been exposed, rotate it immediately.

Authentication errors