Skip to main content
PayX uses API keys to authenticate server-side requests. You can view and manage your API keys in the PayX Dashboard.

API Keys (v2)

PayX uses version 2 (v2) API keys for all merchant integrations. Legacy keys (px_live_... or px_test_... without _v2_) are rejected. Every account has two sets of keys:
  1. Test Keys (px_test_v2_<uuid>): Use these in sandbox and development environments. No real funds are moved.
  2. Live Keys (px_live_v2_<uuid>): Use these in production environments. Real money will be moved.
Never expose Secret Keys in client-side code. Secret API keys (px_live_v2_... / px_test_v2_...) must never be embedded in browser JavaScript, mobile applications, or public code repositories.To accept payments securely in the browser, your backend must call POST /api/v1/checkout to generate a 30-minute scoped token (px_checkout_...). See PayX JS Checkout for details.

Authenticating Requests

All API requests must be made over HTTPS. To authenticate, include your Secret Key in the x-api-key header or the standard Authorization: Bearer header.

Option 2: Authorization: Bearer Header