Primeros pasos
Authentication
Test and live keys, one-hour Bearer tokens, rotation and keeping secrets safe.
4 min de lectura
Las guías para desarrolladores están en inglés para que el código, los nombres de campos y los mensajes de error coincidan exactamente con la API.
En esta página
Keys and modes
Your app has two key sets. Each is a public identifier (client_id) plus a secret (client_secret).
| Key | Mode | Use |
|---|---|---|
pk_test_… / sk_test_… | Test (sandbox) | Build and test. Test traffic never touches real money. |
pk_… / sk_… | Live | Production traffic after go-live approval. |
The pk_… keys are publishable: the only place they belong outside your server is the key field of hosted checkout. Secrets (sk_…) stay on your server, never in an app, a web page or a repository.
Getting a token
POST https://pesa-bridge.com/api/bridgepay/v1/oauth/token
Content-Type: application/json
{ "client_id": "pk_test_…", "client_secret": "sk_test_…" }{ "access_token": "at_9f3…", "token_type": "Bearer", "expires_in": 3600, "mode": "test", "sandbox": true }Send it on every other call as Authorization: Bearer <access_token>. Cache the token and reuse it until shortly before it expires; don't request a token per call.
429 Too many attempts for a few minutes, so fix the credentials rather than retrying in a loop.Rotating secrets
POST /partner/keys/rotate issues a new secret for the test or live set and revokes every existing token for that mode. The new secret is shown once. Roll it out to your servers straight away, then request a fresh token.
Rotate immediately if a secret may have leaked, and at least whenever someone with access leaves your team. You can also manage keys and teammates in the developer console.
A second factor for money out
A Bearer token is enough to collect money. For payouts and reversals you can require a second factor: an Initiator plus a SecurityCredential. Once it's configured, those calls are rejected without it. See Send money.
Authentication errors
| Status | Message | What to do |
|---|---|---|
| 401 | Unauthorized: invalid or expired token. | Request a new token; check you're using the right mode's keys. |
| 429 | Too many attempts. Try again shortly. | Stop retrying, fix the credentials, wait a few minutes. |
Nuestros ingenieros responden dudas de integración. Envíanos la referencia de la solicitud y encontraremos la llamada exacta.
Contactar con soporte