Authentication

Authenticate API requests using API keys. All requests to the YardPay Pro API must include a valid API key.

API Key Authentication

Include your API key in the x-api-key header with every request.

GET /v1/invoice HTTP/1.1
Content-Type: application/json
x-api-key: sk_live_aBcDeFgHiJkLmNoPqRsTuVwXyZ123456
Key Types
PrefixEnvironmentDescription
sk_live_ProductionLive API key — processes real transactions
sk_test_SandboxTest API key — no real money is moved
pk_live_ / pk_test_BothPublishable key — safe to expose in client-side code (limited access)
API Key Scopes

Restrict API keys to specific operations by assigning scopes. Keys without explicit scopes have full access.

ScopeDescription
payments:readView payment details and history
payments:writeCreate and process payments
invoices:readView invoices
invoices:writeCreate, update, and send invoices
transfers:readView transfer details and history
transfers:writeInitiate and manage transfers
accounts:readView accounts and balances
subscriptions:readView subscription plans and features
subscriptions:writeManage subscription plans and features

API Key Management

Endpoints for creating, listing, and revoking API keys.

GET
/v1/apikey
List API Keys

Retrieve all API keys for your account. Only the key prefix is returned, not the full key.

Response

{
  "value": [
    {
      "id": "key_01H8...",
      "name": "Production Key",
      "prefix": "sk_live_aBcD",
      "scopes": ["payments:write", "invoices:read"],
      "createdAt": "2024-03-15T10:00:00Z",
      "lastUsedAt": "2024-03-28T14:30:00Z",
      "expiresAt": null,
      "isActive": true
    }
  ]
}
DELETE
/v1/apikey/{id}
Revoke API Key

Permanently revoke an API key. This action cannot be undone — any integrations using this key will immediately stop working.

Path Parameters

NameTypeRequiredDescription
idstring
Required
API key ID

Response

// 204 No Content
Authentication Errors
StatusErrorMeaning
401invalid_api_keyAPI key is missing, malformed, or revoked
403insufficient_scopeAPI key does not have the required scope for this endpoint
403feature_not_availableYour subscription plan does not include this feature

Usage Examples

cURL
bash
curl -X GET /v1/invoice \
  -H "Content-Type: application/json" \
  -H "x-api-key: sk_live_aBcDeFgHiJkLmNoPqRsTuVwXyZ123456"
JavaScript / Node.js
TypeScript
const axios = require('axios');

const client = axios.create({
  baseURL: window.location.origin,
  headers: {
    'Content-Type': 'application/json',
    'x-api-key': process.env.YARDPAYPRO_API_KEY,
  },
});

// List invoices
const { data } = await client.get('/v1/invoice');

// Create a payment
const payment = await client.post('/api/payment/payinvoice', {
  invoiceIdentifier: 'INV-2024-001',
  paymentOptionId: 1,
  card: {
    name: 'John Doe',
    cardNumber: '4111111111111111',
    expiryDate: '12/26',
    cvv: '123',
  },
});
Python
Python
import requests

API_KEY = "sk_live_aBcDeFgHiJkLmNoPqRsTuVwXyZ123456"
BASE_URL = ""

headers = {
    "Content-Type": "application/json",
    "x-api-key": API_KEY,
}

# List invoices
response = requests.get(f"{BASE_URL}/v1/invoice", headers=headers)
invoices = response.json()

# Create a payment
payment = requests.post(f"{BASE_URL}/api/payment/payinvoice", headers=headers, json={
    "invoiceIdentifier": "INV-2024-001",
    "paymentOptionId": 1,
})
Security Best Practices
  • 1. Never expose secret keys (sk_) in client-side code, git repos, or logs.
  • 2. Use the minimum required scopes for each key.
  • 3. Use sk_test_ keys during development and testing.
  • 4. Rotate keys periodically and revoke any that may have been compromised.
  • 5. Store keys in environment variables or a secrets manager, not in source code.