Skip to content
AuthKit

API Keys

How API Keys works in Paycux, what it is for, and the smallest setup that gets it running.

Introduction

API Keys is part of the Paycux platform. This page explains what it does, when to reach for it, and the smallest working setup you can ship.

Everything below applies to both environments. Build and test in staging, then promote the same configuration to production without changing your code — only the API key and client ID differ.

Configuring API keys

Every API request is authenticated with a bearer token in the Authorization header. Keys are scoped to a single environment and are shown once at creation — store them in a secret manager, not in source control.

1curl -X GET 'https://api.paycux.com/v1/organizations' \
2 -H 'Authorization: Bearer $PAYCUX_API_KEY'

Setting up role permissions

Roles are defined once per project and assigned per organization membership, so the same person can be an admin in one organization and a viewer in another.

Check permissions on the server, in the request path, using the permission slug rather than the role name. Role names change; slugs are stable.

Configuring available permissions

Configuring available permissions controls what the credential is allowed to do. Grant the narrowest set that lets the integration work, and widen it deliberately.

Scopes are evaluated at the API boundary, so an over-broad token is a real risk even if your own code never uses the extra capability.

API key management in your application

API key management in your application applies specifically to API Keys. It behaves the same in both environments, and the values it depends on are visible in the dashboard for the environment you have selected.

If the behaviour you see does not match this description, check which environment your API key belongs to before anything else — a staging key against production data is the most common cause.

Using the API Keys Widget

Using the API Keys Widget applies specifically to API Keys. It behaves the same in both environments, and the values it depends on are visible in the dashboard for the environment you have selected.

If the behaviour you see does not match this description, check which environment your API key belongs to before anything else — a staging key against production data is the most common cause.

Managing API keys via the API

Managing API keys via the API applies specifically to API Keys. It behaves the same in both environments, and the values it depends on are visible in the dashboard for the environment you have selected.

If the behaviour you see does not match this description, check which environment your API key belongs to before anything else — a staging key against production data is the most common cause.

Validating API keys

Validating API keys applies specifically to API Keys. It behaves the same in both environments, and the values it depends on are visible in the dashboard for the environment you have selected.

If the behaviour you see does not match this description, check which environment your API key belongs to before anything else — a staging key against production data is the most common cause.