Authentication and modes
API keys, test and live mode, and key security.
Authenticate every request with your secret key in the Authorization header:
Authorization: Bearer np_test_sk_...Test and live mode
| Key prefix | Mode | Money |
|---|---|---|
np_test_sk_ | test | Simulated. Use test numbers. |
np_live_sk_ | live | Real. Requires NuruPay to enable live mode for your account. |
Everything is separated by mode: collections, balances, webhook endpoints, and events created with a test key are invisible to live keys, and the reverse.
Keep keys secret
- Use keys only from your server. Never put them in a mobile app, website JavaScript, or a public repository.
- Keys are shown once when created. NuruPay stores only a hash and cannot show a key again.
- A key can be restricted to your server's IP addresses. Requests from other IPs get
403 ip_not_allowed.
Rotating a key
When you roll a key, NuruPay issues a new one and the old key keeps working for up to 24 hours, so you can deploy the new key without downtime. After that the old key returns 401 api_key_expired.
Authentication errors
| Status | Code | Meaning |
|---|---|---|
| 401 | invalid_api_key | Missing, malformed, unknown, or revoked key. |
| 401 | api_key_expired | A rolled key past its overlap window. |
| 403 | live_mode_not_enabled | Live key used before NuruPay enabled live mode. |
| 403 | merchant_suspended | Your account is suspended; contact NuruPay. |
| 403 | ip_not_allowed | Request came from an IP outside the key's allowlist. |