NuruPay Docs

Authentication and modes

API keys, test and live mode, and key security.

Authenticate every request with your secret key in the Authorization header:

Authorization: Bearer np_test_sk_...

Test and live mode

Key prefixModeMoney
np_test_sk_testSimulated. Use test numbers.
np_live_sk_liveReal. Requires NuruPay to enable live mode for your account.

Everything is separated by mode: collections, balances, webhook endpoints, and events created with a test key are invisible to live keys, and the reverse.

Keep keys secret

  • Use keys only from your server. Never put them in a mobile app, website JavaScript, or a public repository.
  • Keys are shown once when created. NuruPay stores only a hash and cannot show a key again.
  • A key can be restricted to your server's IP addresses. Requests from other IPs get 403 ip_not_allowed.

Rotating a key

When you roll a key, NuruPay issues a new one and the old key keeps working for up to 24 hours, so you can deploy the new key without downtime. After that the old key returns 401 api_key_expired.

Authentication errors

StatusCodeMeaning
401invalid_api_keyMissing, malformed, unknown, or revoked key.
401api_key_expiredA rolled key past its overlap window.
403live_mode_not_enabledLive key used before NuruPay enabled live mode.
403merchant_suspendedYour account is suspended; contact NuruPay.
403ip_not_allowedRequest came from an IP outside the key's allowlist.

On this page