Skip to main content

Authentication

PayConnect provides two authentication methods to suit different integration scenarios.

API Key Authentication​

API keys are used for legacy endpoints (Transactions, Subscriptions Legacy). Include your API key in the Authorization header.

Example​

curl -X GET https://dev.payconnect.us/api/invoices \
-H "Authorization: Api-Key YOUR_API_KEY"
warning

Never expose your API key in client-side code, public repositories, or browser requests. API keys grant full access to your account.

Session Token Authentication​

Session tokens are used for current endpoint implementations (Invoices, Subscriptions, Subscription Plans, Customers, Payment). Create a session token by exchanging your API key, then use it for subsequent requests.

Creating a Session Token​

Exchange your API key for a session token:

curl -X POST https://dev.payconnect.us/api/auth/session \
-H "Authorization: Api-Key YOUR_API_KEY" \
-H "Content-Type: application/json"

Response:

{
"sessionToken": "eyJhbGciOiJIUzI1NiIs...",
"expiresAt": "2026-07-31T12:30:00.000Z"
}

Using the Session Token​

Include the token in the x-session-token header:

curl -X GET https://dev.payconnect.us/api/invoices \
-H "x-session-token: YOUR_SESSION_TOKEN"

Token Expiration​

  • Session tokens expire 30 minutes after creation
  • Requests do not extend the lifetime; create a new token when it expires
  • When a token expires, create a new one using your API key

Endpoint Authentication Requirements​

Endpoint GroupAuthentication Method
AuthenticationAPI Key
Transactions (Legacy)API Key
Subscriptions (Legacy)API Key
InvoicesSession Token
SubscriptionsSession Token
Subscription PlansSession Token
CustomersSession Token
Payment IntentionSession Token

Security Best Practices​

  1. Store API keys securely — use environment variables or a secrets manager, never hardcode them
  2. Use session tokens for client-side — create short-lived session tokens for browser-based applications
  3. Rotate keys regularly — contact support to rotate your API key if you suspect it has been compromised
  4. Use HTTPS only — all API requests must use HTTPS; HTTP requests will be rejected
  5. Restrict by IP — contact support to set up IP allowlisting for your API key