PesaBridge
文档/入门/Authentication

入门

Authentication

Test and live keys, one-hour Bearer tokens, rotation and keeping secrets safe.

阅读约 4 分钟

开发者指南以英文撰写,以确保代码、字段名和错误信息与 API 完全一致。

本页内容
  1. Keys and modes
  2. Getting a token
  3. Rotating secrets
  4. A second factor for money out
  5. Authentication errors

Keys and modes

Your app has two key sets. Each is a public identifier (client_id) plus a secret (client_secret).

KeyModeUse
pk_test_… / sk_test_…Test (sandbox)Build and test. Test traffic never touches real money.
pk_… / sk_…LiveProduction traffic after go-live approval.

The pk_… keys are publishable: the only place they belong outside your server is the key field of hosted checkout. Secrets (sk_…) stay on your server, never in an app, a web page or a repository.

Getting a token

HTTP
POST https://pesa-bridge.com/api/bridgepay/v1/oauth/token
Content-Type: application/json

{ "client_id": "pk_test_…", "client_secret": "sk_test_…" }
JSON
{ "access_token": "at_9f3…", "token_type": "Bearer", "expires_in": 3600, "mode": "test", "sandbox": true }

Send it on every other call as Authorization: Bearer <access_token>. Cache the token and reuse it until shortly before it expires; don't request a token per call.

Token requests are rate-limited per key. Repeated failures return 429 Too many attempts for a few minutes, so fix the credentials rather than retrying in a loop.

Rotating secrets

POST /partner/keys/rotate issues a new secret for the test or live set and revokes every existing token for that mode. The new secret is shown once. Roll it out to your servers straight away, then request a fresh token.

Rotate immediately if a secret may have leaked, and at least whenever someone with access leaves your team. You can also manage keys and teammates in the developer console.

A second factor for money out

A Bearer token is enough to collect money. For payouts and reversals you can require a second factor: an Initiator plus a SecurityCredential. Once it's configured, those calls are rejected without it. See Send money.

Authentication errors

StatusMessageWhat to do
401Unauthorized: invalid or expired token.Request a new token; check you're using the right mode's keys.
429Too many attempts. Try again shortly.Stop retrying, fix the credentials, wait a few minutes.

我们的工程师解答集成问题。把请求参考号发给我们,我们会找到那次调用。

联系支持