Authentication
PayConnect provides two authentication methods to suit different integration scenarios.
API Key Authentication
API keys are used for legacy endpoints (Transactions, Subscriptions Legacy). Include your API key in the Authorization header.
Example
curl -X GET https://dev.payconnect.us/api/invoices \
-H "Authorization: Api-Key YOUR_API_KEY"
warning
Never expose your API key in client-side code, public repositories, or browser requests. API keys grant full access to your account.
Session Token Authentication
Session tokens are used for current endpoint implementations (Invoices, Subscriptions, Subscription Plans, Customers, Payment). Create a session token by exchanging your API key, then use it for subsequent requests.
Creating a Session Token
Exchange your API key for a session token:
curl -X POST https://dev.payconnect.us/api/auth/session \
-H "Authorization: Api-Key YOUR_API_KEY" \
-H "Content-Type: application/json"
Response:
{
"sessionToken": "eyJhbGciOiJIUzI1NiIs...",
"expiresAt": "2026-07-31T12:30:00.000Z"
}
Using the Session Token
Include the token in the x-session-token header:
curl -X GET https://dev.payconnect.us/api/invoices \
-H "x-session-token: YOUR_SESSION_TOKEN"
Token Expiration
- Session tokens expire 30 minutes after creation
- Requests do not extend the lifetime; create a new token when it expires
- When a token expires, create a new one using your API key
Endpoint Authentication Requirements
| Endpoint Group | Authentication Method |
|---|---|
| Authentication | API Key |
| Transactions (Legacy) | API Key |
| Subscriptions (Legacy) | API Key |
| Invoices | Session Token |
| Subscriptions | Session Token |
| Subscription Plans | Session Token |
| Customers | Session Token |
| Payment Intention | Session Token |
Security Best Practices
- Store API keys securely — use environment variables or a secrets manager, never hardcode them
- Use session tokens for client-side — create short-lived session tokens for browser-based applications
- Rotate keys regularly — contact support to rotate your API key if you suspect it has been compromised
- Use HTTPS only — all API requests must use HTTPS; HTTP requests will be rejected
- Restrict by IP — contact support to set up IP allowlisting for your API key