Tranzak Docs
tranzak.co Dashboard
Docs  /  Get started

Authentication

How to authenticate with the Tranzak API: websites, API keys, the X-Api-Key header, test and live modes, and keeping secrets safe.

Every request to the Tranzak API is authenticated with an API key sent in a header.

Websites and API keys

In the dashboard, under Developer:

Item What it is
Website The shop or application that takes payments. It holds your webhook URL, your optional return URL and a webhook secret (whsec_…).
API key A secret that identifies a website to the API. A test key starts with tk_test_, a live key with tk_live_.

An API key belongs to one website. Payments created with a key are visible only to that website.

Send the key

Send the key in the X-Api-Key header on every request, together with a JSON body where needed.

curl https://api.tranzak.co/api/gateway/v1/payments \
  -H "X-Api-Key: $TRANZAK_API_KEY" \
  -H "Accept: application/json"
const response = await fetch('https://api.tranzak.co/api/gateway/v1/payments', {
  headers: {
    'X-Api-Key': process.env.TRANZAK_API_KEY,
    'Accept': 'application/json',
  },
});
import os, requests

response = requests.get(
    "https://api.tranzak.co/api/gateway/v1/payments",
    headers={"X-Api-Key": os.environ["TRANZAK_API_KEY"], "Accept": "application/json"},
)
$ch = curl_init('https://api.tranzak.co/api/gateway/v1/payments');
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => [
        'X-Api-Key: ' . getenv('TRANZAK_API_KEY'),
        'Accept: application/json',
    ],
]);
$result = json_decode(curl_exec($ch), true);

Test mode and live mode

The key decides the mode. No other setting is needed.

Test key (tk_test_…) Live key (tk_live_…)
Money Nothing real moves Real payments
Providers MonCash and NatCash are simulated, cards use Stripe test mode Real MonCash, NatCash and cards
Events feed Available Not available
Availability Immediately after sign-up After identity verification

Test data is removed by a nightly maintenance job. Do not rely on test transactions staying for more than a day.

Keep your secrets safe

Warning Anyone holding your API key can create payments in your name. Treat it like a password.

  • Read keys from environment variables or your platform's secrets manager (TRANZAK_API_KEY, TRANZAK_WEBHOOK_SECRET).
  • Never put a key in source code, a repository, a mobile app, a browser script, a log or a chat message.
  • Call the API from your server, never from the browser. The only browser-side piece is the card widget, which uses a short-lived client secret and never your API key.
  • If a key may have leaked, deactivate it in the dashboard and generate a new one.

Authentication errors

HTTP Error Meaning
401 API key is required The X-Api-Key header is missing.
401 Invalid API key The key is wrong, deactivated or mistyped. Do not retry in a loop.
403 API key is not active The key was deactivated in the dashboard.
403 Website not found or inactive The website behind the key is inactive.
429 too_many_attempts Too many invalid keys from your IP (10 per hour). Wait before trying again.

See Errors and rate limits for the full list.