API keys & credentials
Each application in your Pesepay account (see Onboarding) has two keys:
| Key | Used for |
|---|---|
| Integration key | Sent as the authorization header on every API request |
| Encryption key | Encrypting requests and decrypting responses — see the Encryption Guide |
Sandbox vs live keys
Section titled “Sandbox vs live keys”Sandbox and production are separate accounts with separate applications, so you hold two pairs of keys. A pair only works against the environment it was issued for:
| Keys from | Base URL they work against |
|---|---|
| Sandbox | https://api.test.sandbox.pesepay.com/payments-engine/... |
| Live | https://api.pesepay.com/api/payments-engine/... |
Label them unmistakably in your configuration — PESEPAY_SANDBOX_* and
PESEPAY_LIVE_* rather than one PESEPAY_KEY that changes meaning per
deploy — and never let a sandbox key reach a production build, or the
reverse.
Keep requests server-side
Section titled “Keep requests server-side”If a key is compromised
Section titled “If a key is compromised”Deactivate the affected key from the Merchant Control Panel and issue a new one immediately, then update it everywhere it’s used. There’s no grace period — treat any suspected exposure as urgent.
Rotating keys
Section titled “Rotating keys”Rotating a key changes what your live servers need to encrypt/decrypt with — plan rotations as a deploy, not a dashboard-only change:
- Generate the new key in the Merchant Control Panel.
- Deploy your servers with the new key.
- Confirm new transactions encrypt/decrypt correctly.
- Deactivate the old key.