How are security and authentication handled?
Updated
Short answer
API requests are authenticated with your secret key as a bearer token: sk_test_ on staging, sk_live_ in production. Publishable pk_ keys are used only by the Checkout SDK. Webhooks are signed with an HMAC-SHA512 x-payluk-signature header. You can also whitelist the server IPs allowed to use your live key, and requests from any other IP are rejected.
API keys
- Secret keys (sk_test_ and sk_live_) go in the Authorization: Bearer header from your server only. Never put them in a browser or mobile app.
- Publishable keys (pk_test_ and pk_live_) are used by the Checkout SDK in the browser.
- Test keys are rejected in production and live keys are rejected on staging.
- You can regenerate your live secret key from the dashboard if it is ever exposed. Update your webhook verification at the same time, because the same key signs webhooks.
IP whitelisting
Add your server IPs in the dashboard. Once the list has any entries, live API calls from IPs not on the list are rejected.
Other protections
- Rate limits per API key, with standard RateLimit response headers
- Two-factor authentication and PIN checks for sensitive account actions
- Webhook delivery to private or internal network addresses is blocked