Guide
5 min
Authentication
Generate API keys and authenticate requests to the YardPay Pro platform. This is the first step before making any API calls.
Prerequisites
- A YardPay Pro account (sign up at the dashboard)
- Access to the API Keys section in your account settings
1
Generate an API Key
Navigate to Settings → API Keys in your dashboard and click Create New Key. Choose the appropriate key type:
| Prefix | Environment | Use Case |
|---|---|---|
| sk_test_ | Sandbox | Development and testing — no real money is moved |
| sk_live_ | Production | Live transactions — processes real payments |
| pk_test_ | Sandbox | Client-side code (safe to expose, limited access) |
| pk_live_ | Production | Client-side code in production |
Important: Copy your secret key immediately after creation. It will not be shown again. Store it securely in an environment variable.
2
Assign Scopes
Restrict what each key can access by assigning scopes. Keys without explicit scopes have full access. Use the minimum scopes your integration needs.
payments:readView payment detailspayments:writeCreate and process paymentsinvoices:readView invoicesinvoices:writeCreate and send invoicestransfers:readView transferstransfers:writeInitiate transfersaccounts:readView accounts and balancessubscriptions:readView subscriptionssubscriptions:writeManage subscriptions3
Make Your First Request
Pass your API key in the x-api-key header with every request.
cURL
curl -X GET /v1/invoice \ -H "Content-Type: application/json" \ -H "x-api-key: sk_test_YOUR_API_KEY"
JavaScript
const response = await fetch('/v1/invoice', {
headers: {
'Content-Type': 'application/json',
'x-api-key': process.env.YARDPAYPRO_API_KEY,
},
});
const invoices = await response.json();
console.log(invoices);Python
import requests
response = requests.get(
"/v1/invoice",
headers={
"Content-Type": "application/json",
"x-api-key": "sk_test_YOUR_API_KEY",
},
)
invoices = response.json()
print(invoices)4
Handle Authentication Errors
| Status | Error | What To Do |
|---|---|---|
| 401 | invalid_api_key | Check that your key is correct and not revoked |
| 403 | insufficient_scope | Add the required scope to your API key |
| 403 | feature_not_available | Upgrade your plan to access this feature |
Security Best Practices
- Never expose secret keys (
sk_) in client-side code, git repos, or logs. - Use publishable keys (
pk_) for any client-side or browser code. - Always use
sk_test_keys during development. - Rotate keys periodically and revoke any that may have been compromised.
- Store keys in environment variables or a secrets manager.