Getting started
Authentication
How API keys, environments, and request signing work.
Every request is authenticated with a secret key sent as a Bearer token. Sandbox keys start with mk_test_, live keys with mk_live_ — they are never interchangeable.
Example request
cURL
curl https://api.merebpay.com/v1/charges \ -H "Authorization: Bearer mk_test_..." \ -H "Content-Type: application/json"Best practices
Keep secret keys server-side only. Use publishable keys for anything that runs in a browser or mobile app.
- Rotate keys from Developers → API Keys if one is ever exposed
- Use a separate sandbox key per environment (local, staging, CI)
- Never commit a live key to source control