Premiers pas
Authentication
Test and live keys, one-hour Bearer tokens, rotation and keeping secrets safe.
4 min de lecture
Les guides développeurs sont rédigés en anglais pour que le code, les noms de champs et les messages d'erreur correspondent exactement à l'API.
Sur cette page
Keys and modes
Your app has two key sets. Each is a public identifier (client_id) plus a secret (client_secret).
| Key | Mode | Use |
|---|---|---|
pk_test_… / sk_test_… | Test (sandbox) | Build and test. Test traffic never touches real money. |
pk_… / sk_… | Live | Production traffic after go-live approval. |
The pk_… keys are publishable: the only place they belong outside your server is the key field of hosted checkout. Secrets (sk_…) stay on your server, never in an app, a web page or a repository.
Getting a token
POST https://pesa-bridge.com/api/bridgepay/v1/oauth/token
Content-Type: application/json
{ "client_id": "pk_test_…", "client_secret": "sk_test_…" }{ "access_token": "at_9f3…", "token_type": "Bearer", "expires_in": 3600, "mode": "test", "sandbox": true }Send it on every other call as Authorization: Bearer <access_token>. Cache the token and reuse it until shortly before it expires; don't request a token per call.
429 Too many attempts for a few minutes, so fix the credentials rather than retrying in a loop.Rotating secrets
POST /partner/keys/rotate issues a new secret for the test or live set and revokes every existing token for that mode. The new secret is shown once. Roll it out to your servers straight away, then request a fresh token.
Rotate immediately if a secret may have leaked, and at least whenever someone with access leaves your team. You can also manage keys and teammates in the developer console.
A second factor for money out
A Bearer token is enough to collect money. For payouts and reversals you can require a second factor: an Initiator plus a SecurityCredential. Once it's configured, those calls are rejected without it. See Send money.
Authentication errors
| Status | Message | What to do |
|---|---|---|
| 401 | Unauthorized: invalid or expired token. | Request a new token; check you're using the right mode's keys. |
| 429 | Too many attempts. Try again shortly. | Stop retrying, fix the credentials, wait a few minutes. |
Nos ingénieurs répondent aux questions d'intégration. Envoyez-nous la référence de la requête et nous retrouverons l'appel exact.
Contacter le support