Docs / Get started
Authentication
How to authenticate with the Tranzak API: websites, API keys, the X-Api-Key header, test and live modes, and keeping secrets safe.
Every request to the Tranzak API is authenticated with an API key sent in a header.
Websites and API keys
In the dashboard, under Developer:
| Item | What it is |
|---|---|
| Website | The shop or application that takes payments. It holds your webhook URL, your optional return URL and a webhook secret (whsec_…). |
| API key | A secret that identifies a website to the API. A test key starts with tk_test_, a live key with tk_live_. |
An API key belongs to one website. Payments created with a key are visible only to that website.
Send the key
Send the key in the X-Api-Key header on every request, together with a JSON body where needed.
curl https://api.tranzak.co/api/gateway/v1/payments \
-H "X-Api-Key: $TRANZAK_API_KEY" \
-H "Accept: application/json"
const response = await fetch('https://api.tranzak.co/api/gateway/v1/payments', {
headers: {
'X-Api-Key': process.env.TRANZAK_API_KEY,
'Accept': 'application/json',
},
});
import os, requests
response = requests.get(
"https://api.tranzak.co/api/gateway/v1/payments",
headers={"X-Api-Key": os.environ["TRANZAK_API_KEY"], "Accept": "application/json"},
)
$ch = curl_init('https://api.tranzak.co/api/gateway/v1/payments');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'X-Api-Key: ' . getenv('TRANZAK_API_KEY'),
'Accept: application/json',
],
]);
$result = json_decode(curl_exec($ch), true);
Test mode and live mode
The key decides the mode. No other setting is needed.
Test key (tk_test_…) |
Live key (tk_live_…) |
|
|---|---|---|
| Money | Nothing real moves | Real payments |
| Providers | MonCash and NatCash are simulated, cards use Stripe test mode | Real MonCash, NatCash and cards |
| Events feed | Available | Not available |
| Availability | Immediately after sign-up | After identity verification |
Test data is removed by a nightly maintenance job. Do not rely on test transactions staying for more than a day.
Keep your secrets safe
Warning Anyone holding your API key can create payments in your name. Treat it like a password.
- Read keys from environment variables or your platform's secrets manager (
TRANZAK_API_KEY,TRANZAK_WEBHOOK_SECRET). - Never put a key in source code, a repository, a mobile app, a browser script, a log or a chat message.
- Call the API from your server, never from the browser. The only browser-side piece is the card widget, which uses a short-lived client secret and never your API key.
- If a key may have leaked, deactivate it in the dashboard and generate a new one.
Authentication errors
| HTTP | Error | Meaning |
|---|---|---|
| 401 | API key is required |
The X-Api-Key header is missing. |
| 401 | Invalid API key |
The key is wrong, deactivated or mistyped. Do not retry in a loop. |
| 403 | API key is not active |
The key was deactivated in the dashboard. |
| 403 | Website not found or inactive |
The website behind the key is inactive. |
| 429 | too_many_attempts |
Too many invalid keys from your IP (10 per hour). Wait before trying again. |
See Errors and rate limits for the full list.