PesaBridge
दस्तावेज़/शुरुआत/Authentication

शुरुआत

Authentication

Test and live keys, one-hour Bearer tokens, rotation and keeping secrets safe.

4 मिनट में पढ़ें

डेवलपर गाइड अंग्रेज़ी में लिखी गई हैं ताकि कोड, फ़ील्ड के नाम और त्रुटि संदेश API से बिल्कुल मेल खाएं।

इस पेज पर
  1. Keys and modes
  2. Getting a token
  3. Rotating secrets
  4. A second factor for money out
  5. Authentication errors

Keys and modes

Your app has two key sets. Each is a public identifier (client_id) plus a secret (client_secret).

KeyModeUse
pk_test_… / sk_test_…Test (sandbox)Build and test. Test traffic never touches real money.
pk_… / sk_…LiveProduction traffic after go-live approval.

The pk_… keys are publishable: the only place they belong outside your server is the key field of hosted checkout. Secrets (sk_…) stay on your server, never in an app, a web page or a repository.

Getting a token

HTTP
POST https://pesa-bridge.com/api/bridgepay/v1/oauth/token
Content-Type: application/json

{ "client_id": "pk_test_…", "client_secret": "sk_test_…" }
JSON
{ "access_token": "at_9f3…", "token_type": "Bearer", "expires_in": 3600, "mode": "test", "sandbox": true }

Send it on every other call as Authorization: Bearer <access_token>. Cache the token and reuse it until shortly before it expires; don't request a token per call.

Token requests are rate-limited per key. Repeated failures return 429 Too many attempts for a few minutes, so fix the credentials rather than retrying in a loop.

Rotating secrets

POST /partner/keys/rotate issues a new secret for the test or live set and revokes every existing token for that mode. The new secret is shown once. Roll it out to your servers straight away, then request a fresh token.

Rotate immediately if a secret may have leaked, and at least whenever someone with access leaves your team. You can also manage keys and teammates in the developer console.

A second factor for money out

A Bearer token is enough to collect money. For payouts and reversals you can require a second factor: an Initiator plus a SecurityCredential. Once it's configured, those calls are rejected without it. See Send money.

Authentication errors

StatusMessageWhat to do
401Unauthorized: invalid or expired token.Request a new token; check you're using the right mode's keys.
429Too many attempts. Try again shortly.Stop retrying, fix the credentials, wait a few minutes.

हमारे इंजीनियर इंटीग्रेशन से जुड़े सवालों के जवाब देते हैं। अनुरोध का रेफ़रेंस भेजें, हम ठीक वही कॉल ढूंढ लेंगे।

सपोर्ट से संपर्क करें