Skip to content

API keys & credentials

Each application in your Pesepay account (see Onboarding) has two keys:

KeyUsed for
Integration keySent as the authorization header on every API request
Encryption keyEncrypting requests and decrypting responses — see the Encryption Guide

Sandbox and production are separate accounts with separate applications, so you hold two pairs of keys. A pair only works against the environment it was issued for:

Keys fromBase URL they work against
Sandboxhttps://api.test.sandbox.pesepay.com/payments-engine/...
Livehttps://api.pesepay.com/api/payments-engine/...

Label them unmistakably in your configuration — PESEPAY_SANDBOX_* and PESEPAY_LIVE_* rather than one PESEPAY_KEY that changes meaning per deploy — and never let a sandbox key reach a production build, or the reverse.

Deactivate the affected key from the Merchant Control Panel and issue a new one immediately, then update it everywhere it’s used. There’s no grace period — treat any suspected exposure as urgent.

Rotating a key changes what your live servers need to encrypt/decrypt with — plan rotations as a deploy, not a dashboard-only change:

  1. Generate the new key in the Merchant Control Panel.
  2. Deploy your servers with the new key.
  3. Confirm new transactions encrypt/decrypt correctly.
  4. Deactivate the old key.