Authentication
The New Accounts API authenticates requests with an API key made up of two values: a key ID and a key value. Each key is scoped to a single cobrand in a single environment and cannot be used for other cobrands. Our team provisions your key and delivers it to you securely.
Sandbox and production keys
Sandbox and production are separate environments, each with its own key. Your sandbox key is issued during the implementation process. Once you certify your integration, production keys are granted.
How you receive your key
Our team grants sandbox access. Once your test environment is set up, you receive:
- Your sandbox credentials
- The API key for your test environment
- If you are using the Partial Application Submit API for merchant onboarding, you also receive your custom field mapping list for testing purposes
When you are ready to go live, your production credentials and configuration are provisioned the same way.
Your API key
Your key has two values:
| Value | Description |
|---|---|
| Key ID | Identifies the key |
| Key value | The secret paired with the key ID |
Store your key value immediatelyStore both values in a secure, server-side location as soon as you receive them. Key values cannot be recovered, so a lost value means a new key. Keys do not expire.
Authenticating your requests
How you pass your key depends on the endpoint. Some New Accounts endpoints expect both values in the request headers; others expect them in the request body. Check the API Reference for the endpoint you are calling to confirm which method it expects, and send the values only in that location.
| Header | Value |
|---|---|
X-AuthenticationKeyId | Your key ID |
X-AuthenticationKeyValue | Your key value |
{
"X-AuthenticationKeyId": "YOUR_KEY_ID",
"X-AuthenticationKeyValue": "YOUR_KEY_VALUE"
}| Parameter | Value |
|---|---|
authenticationKeyId | Your key ID |
authenticationKeyValue | Your key value |
{
"authenticationKeyId": "YOUR_KEY_ID",
"authenticationKeyValue": "YOUR_KEY_VALUE"
}These two values sit alongside the other fields the endpoint requires. See the API Reference for the full request body.
Securing your key
Treat your key value like a password.
Never expose your key value
- Store it in a secrets manager or an environment variable. Never hardcode it in source code.
- Never expose it in client-side code, mobile applications, or browser requests.
- Keep it out of logs, error messages, and URL query strings.
If you think a key value has been exposed, contact us on the Customer Support Portal.
Managing your keys
You can have multiple keys active at the same time. To add, rotate, or revoke a key, contact us on the Customer Support Portal.
Add a key
Generate a new key to support additional integrations, environments, or applications without disrupting your existing keys.
Useful when onboarding a new system or separating access by use case.
Rotate a key
Replace an existing key with a new one while retiring the old one.
Teams typically do this on a regular schedule as a security best practice, or after a key may have been exposed.
Revoke a key
Permanently disable a key that is no longer needed.
Commonly done when decommissioning an integration, offboarding a team member with key access, or responding to a suspected compromise.
NOTE: Infinicept reserves the right to revoke a client's API key at our discretion in cases of misuse, security concerns, or other special circumstances, in order to protect the integrity of our systems and services.
Errors
Requests with a missing, misplaced, or incorrect value return a 401 Unauthorized. For a list of status codes, see New Accounts API Status Codes.
Support
Have a question? Contact us on the Customer Support Portal.
Learn about updates in our Changelog.
Updated about 2 months ago
