Authentication
Authenticate API requests using API keys. All requests to the YardPay Pro API must include a valid API key.
API Key Authentication
Include your API key in the x-api-key header with every request.
GET /v1/invoice HTTP/1.1 Content-Type: application/json x-api-key: sk_live_aBcDeFgHiJkLmNoPqRsTuVwXyZ123456
Key Types
| Prefix | Environment | Description |
|---|---|---|
| sk_live_ | Production | Live API key — processes real transactions |
| sk_test_ | Sandbox | Test API key — no real money is moved |
| pk_live_ / pk_test_ | Both | Publishable key — safe to expose in client-side code (limited access) |
API Key Scopes
Restrict API keys to specific operations by assigning scopes. Keys without explicit scopes have full access.
| Scope | Description |
|---|---|
| payments:read | View payment details and history |
| payments:write | Create and process payments |
| invoices:read | View invoices |
| invoices:write | Create, update, and send invoices |
| transfers:read | View transfer details and history |
| transfers:write | Initiate and manage transfers |
| accounts:read | View accounts and balances |
| subscriptions:read | View subscription plans and features |
| subscriptions:write | Manage subscription plans and features |
API Key Management
Endpoints for creating, listing, and revoking API keys.
GET
/v1/apikeyList API Keys
Retrieve all API keys for your account. Only the key prefix is returned, not the full key.
Response
{
"value": [
{
"id": "key_01H8...",
"name": "Production Key",
"prefix": "sk_live_aBcD",
"scopes": ["payments:write", "invoices:read"],
"createdAt": "2024-03-15T10:00:00Z",
"lastUsedAt": "2024-03-28T14:30:00Z",
"expiresAt": null,
"isActive": true
}
]
}DELETE
/v1/apikey/{id}Revoke API Key
Permanently revoke an API key. This action cannot be undone — any integrations using this key will immediately stop working.
Path Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| id | string | Required | API key ID |
Response
// 204 No Content
Authentication Errors
| Status | Error | Meaning |
|---|---|---|
| 401 | invalid_api_key | API key is missing, malformed, or revoked |
| 403 | insufficient_scope | API key does not have the required scope for this endpoint |
| 403 | feature_not_available | Your subscription plan does not include this feature |
Usage Examples
cURL
bash
curl -X GET /v1/invoice \ -H "Content-Type: application/json" \ -H "x-api-key: sk_live_aBcDeFgHiJkLmNoPqRsTuVwXyZ123456"
JavaScript / Node.js
TypeScript
const axios = require('axios');
const client = axios.create({
baseURL: window.location.origin,
headers: {
'Content-Type': 'application/json',
'x-api-key': process.env.YARDPAYPRO_API_KEY,
},
});
// List invoices
const { data } = await client.get('/v1/invoice');
// Create a payment
const payment = await client.post('/api/payment/payinvoice', {
invoiceIdentifier: 'INV-2024-001',
paymentOptionId: 1,
card: {
name: 'John Doe',
cardNumber: '4111111111111111',
expiryDate: '12/26',
cvv: '123',
},
});Python
Python
import requests
API_KEY = "sk_live_aBcDeFgHiJkLmNoPqRsTuVwXyZ123456"
BASE_URL = ""
headers = {
"Content-Type": "application/json",
"x-api-key": API_KEY,
}
# List invoices
response = requests.get(f"{BASE_URL}/v1/invoice", headers=headers)
invoices = response.json()
# Create a payment
payment = requests.post(f"{BASE_URL}/api/payment/payinvoice", headers=headers, json={
"invoiceIdentifier": "INV-2024-001",
"paymentOptionId": 1,
})Security Best Practices
- 1. Never expose secret keys (
sk_) in client-side code, git repos, or logs. - 2. Use the minimum required scopes for each key.
- 3. Use
sk_test_keys during development and testing. - 4. Rotate keys periodically and revoke any that may have been compromised.
- 5. Store keys in environment variables or a secrets manager, not in source code.