/v1/products, /v1/checkouts, and /v1/orders, use an API key passed in the x-api-key header.
Authentication depends on the endpoint:
See Epay signatures for its separate signing rules.
API Keys
Kyren Pay uses API keys to authenticate requests. You can manage your API keys from the Merchant Dashboard. The current backend implementation accepts live API keys:Making Authenticated Requests
Include your API key in thex-api-key header when calling a protected public merchant integration endpoint:
Environments
The current public production API accepts live API keys with the
kyren_live_ prefix.
Kyren does not currently expose self-service kyren_test_ keys in the merchant dashboard.
Use a staging base URL only when Kyren has issued matching staging credentials to you.Regenerating API Keys
If your API key is compromised, you can regenerate it from the Dashboard:- Go to Dashboard > Developer
- Click Regenerate next to the key you want to replace
- Confirm the action
Error Responses
Missing or rejected API credentials on a protected endpoint return HTTP401 Unauthorized. Authentication middleware does not guarantee a JSON response body. Check the HTTP status before attempting to parse JSON. Application-level JSON error codes are described in Errors.
Common causes:
- Missing
x-api-keyheader - Invalid or regenerated API key
- Using an API key prefix not accepted by the current environment
- A blocked merchant account or a request IP outside your configured API IP allowlist