Ìbẹ̀rẹ̀
Authentication
Test and live keys, one-hour Bearer tokens, rotation and keeping secrets safe.
Ìṣẹ́jú 4 láti kà
A kọ àwọn ìtọ́sọ́nà olùgbéṣẹ́ ní èdè Gẹ̀ẹ́sì kí kóòdù, orúkọ àwọn pápá àti àwọn ìfiránṣẹ́ àṣìṣe lè bá API mu gẹ́lẹ́.
Lórí ojú-ìwé yìí
Keys and modes
Your app has two key sets. Each is a public identifier (client_id) plus a secret (client_secret).
| Key | Mode | Use |
|---|---|---|
pk_test_… / sk_test_… | Test (sandbox) | Build and test. Test traffic never touches real money. |
pk_… / sk_… | Live | Production traffic after go-live approval. |
The pk_… keys are publishable: the only place they belong outside your server is the key field of hosted checkout. Secrets (sk_…) stay on your server, never in an app, a web page or a repository.
Getting a token
POST https://pesa-bridge.com/api/bridgepay/v1/oauth/token
Content-Type: application/json
{ "client_id": "pk_test_…", "client_secret": "sk_test_…" }{ "access_token": "at_9f3…", "token_type": "Bearer", "expires_in": 3600, "mode": "test", "sandbox": true }Send it on every other call as Authorization: Bearer <access_token>. Cache the token and reuse it until shortly before it expires; don't request a token per call.
429 Too many attempts for a few minutes, so fix the credentials rather than retrying in a loop.Rotating secrets
POST /partner/keys/rotate issues a new secret for the test or live set and revokes every existing token for that mode. The new secret is shown once. Roll it out to your servers straight away, then request a fresh token.
Rotate immediately if a secret may have leaked, and at least whenever someone with access leaves your team. You can also manage keys and teammates in the developer console.
A second factor for money out
A Bearer token is enough to collect money. For payouts and reversals you can require a second factor: an Initiator plus a SecurityCredential. Once it's configured, those calls are rejected without it. See Send money.
Authentication errors
| Status | Message | What to do |
|---|---|---|
| 401 | Unauthorized: invalid or expired token. | Request a new token; check you're using the right mode's keys. |
| 429 | Too many attempts. Try again shortly. | Stop retrying, fix the credentials, wait a few minutes. |
Àwọn onímọ̀-ẹ̀rọ wa ń dáhùn ìbéèrè nípa ìsopọ̀. Fi nọ́mbà ìtọ́kasí ìbéèrè náà ránṣẹ́ sí wa, a ó sì rí ìpè náà gẹ́lẹ́.
Kàn sí ìrànlọ́wọ́