Guide
5 min

Authentication

Generate API keys and authenticate requests to the YardPay Pro platform. This is the first step before making any API calls.

Prerequisites
  • A YardPay Pro account (sign up at the dashboard)
  • Access to the API Keys section in your account settings
1

Generate an API Key

Navigate to Settings → API Keys in your dashboard and click Create New Key. Choose the appropriate key type:

PrefixEnvironmentUse Case
sk_test_SandboxDevelopment and testing — no real money is moved
sk_live_ProductionLive transactions — processes real payments
pk_test_SandboxClient-side code (safe to expose, limited access)
pk_live_ProductionClient-side code in production

Important: Copy your secret key immediately after creation. It will not be shown again. Store it securely in an environment variable.

2

Assign Scopes

Restrict what each key can access by assigning scopes. Keys without explicit scopes have full access. Use the minimum scopes your integration needs.

payments:readView payment details
payments:writeCreate and process payments
invoices:readView invoices
invoices:writeCreate and send invoices
transfers:readView transfers
transfers:writeInitiate transfers
accounts:readView accounts and balances
subscriptions:readView subscriptions
subscriptions:writeManage subscriptions
3

Make Your First Request

Pass your API key in the x-api-key header with every request.

cURL

curl -X GET /v1/invoice \
  -H "Content-Type: application/json" \
  -H "x-api-key: sk_test_YOUR_API_KEY"

JavaScript

const response = await fetch('/v1/invoice', {
  headers: {
    'Content-Type': 'application/json',
    'x-api-key': process.env.YARDPAYPRO_API_KEY,
  },
});

const invoices = await response.json();
console.log(invoices);

Python

import requests

response = requests.get(
    "/v1/invoice",
    headers={
        "Content-Type": "application/json",
        "x-api-key": "sk_test_YOUR_API_KEY",
    },
)

invoices = response.json()
print(invoices)
4

Handle Authentication Errors

StatusErrorWhat To Do
401invalid_api_keyCheck that your key is correct and not revoked
403insufficient_scopeAdd the required scope to your API key
403feature_not_availableUpgrade your plan to access this feature
Security Best Practices
  • Never expose secret keys (sk_) in client-side code, git repos, or logs.
  • Use publishable keys (pk_) for any client-side or browser code.
  • Always use sk_test_ keys during development.
  • Rotate keys periodically and revoke any that may have been compromised.
  • Store keys in environment variables or a secrets manager.