Authentication

The New Accounts API authenticates requests with an API key made up of two values: a key ID and a key value. Each key is scoped to a single cobrand in a single environment and cannot be used for other cobrands. Our team provisions your key and delivers it to you securely.

Sandbox and production keys

Sandbox and production are separate environments, each with its own key. Your sandbox key is issued during the implementation process. Once you certify your integration, production keys are granted.

How you receive your key

Our team grants sandbox access. Once your test environment is set up, you receive:

  • Your sandbox credentials
  • The API key for your test environment
  • If you are using the Partial Application Submit API for merchant onboarding, you also receive your custom field mapping list for testing purposes

When you are ready to go live, your production credentials and configuration are provisioned the same way.

Your API key

Your key has two values:

ValueDescription
Key IDIdentifies the key
Key valueThe secret paired with the key ID
🚧

Store your key value immediately

Store both values in a secure, server-side location as soon as you receive them. Key values cannot be recovered, so a lost value means a new key. Keys do not expire.

Authenticating your requests

How you pass your key depends on the endpoint. Some New Accounts endpoints expect both values in the request headers; others expect them in the request body. Check the API Reference for the endpoint you are calling to confirm which method it expects, and send the values only in that location.

HeaderValue
X-AuthenticationKeyIdYour key ID
X-AuthenticationKeyValueYour key value
{
  "X-AuthenticationKeyId": "YOUR_KEY_ID",
  "X-AuthenticationKeyValue": "YOUR_KEY_VALUE"
}

Securing your key

Treat your key value like a password.

❗️

Never expose your key value

  • Store it in a secrets manager or an environment variable. Never hardcode it in source code.
  • Never expose it in client-side code, mobile applications, or browser requests.
  • Keep it out of logs, error messages, and URL query strings.

If you think a key value has been exposed, contact us on the Customer Support Portal.

Managing your keys

You can have multiple keys active at the same time. To add, rotate, or revoke a key, contact us on the Customer Support Portal.

NOTE: Infinicept reserves the right to revoke a client's API key at our discretion in cases of misuse, security concerns, or other special circumstances, in order to protect the integrity of our systems and services.

Errors

Requests with a missing, misplaced, or incorrect value return a 401 Unauthorized. For a list of status codes, see New Accounts API Status Codes.


Support

Have a question? Contact us on the Customer Support Portal.

Learn about updates in our Changelog.






Did this page help you?