Skip to main content
Public merchant integration endpoints, such as /v1/products, /v1/checkouts, and /v1/orders, use an API key passed in the x-api-key header. Authentication depends on the endpoint: See Epay signatures for its separate signing rules.

API Keys

Kyren Pay uses API keys to authenticate requests. You can manage your API keys from the Merchant Dashboard. The current backend implementation accepts live API keys:

Making Authenticated Requests

Include your API key in the x-api-key header when calling a protected public merchant integration endpoint:
Keep your API keys secure.
  • Never expose API keys in client-side code (JavaScript, mobile apps)
  • Never commit API keys to version control
  • Use environment variables to store keys in your server
  • Regenerate keys immediately if they are compromised

Environments

The current public production API accepts live API keys with the kyren_live_ prefix. Kyren does not currently expose self-service kyren_test_ keys in the merchant dashboard. Use a staging base URL only when Kyren has issued matching staging credentials to you.

Regenerating API Keys

If your API key is compromised, you can regenerate it from the Dashboard:
  1. Go to Dashboard > Developer
  2. Click Regenerate next to the key you want to replace
  3. Confirm the action
Regenerating a key immediately invalidates the old key. Make sure to update all your integrations with the new key.

Error Responses

Missing or rejected API credentials on a protected endpoint return HTTP 401 Unauthorized. Authentication middleware does not guarantee a JSON response body. Check the HTTP status before attempting to parse JSON. Application-level JSON error codes are described in Errors. Common causes:
  • Missing x-api-key header
  • Invalid or regenerated API key
  • Using an API key prefix not accepted by the current environment
  • A blocked merchant account or a request IP outside your configured API IP allowlist