AdeyVerify

API Keys

Creating, rotating, and restricting API keys

API keys are managed from the dashboard's API Keys page, or programmatically via the API Keys endpoints.

Creating a key

POST /api/v1/api-keys
{
  "name": "Production backend",
  "environment": "LIVE",
  "allowedServices": ["BANK", "TRANSACTION"]
}

The response includes the full secret — this is the only time it's shown:

201 Created
{
  "id": "cmun...",
  "name": "Production backend",
  "prefix": "av_live_a1b2",
  "environment": "LIVE",
  "secret": "av_live_a1b2c3d4e5f6...",
  "allowedServices": ["BANK", "TRANSACTION"]
}

Store the secret securely (a secrets manager or environment variable) — AdeyVerify cannot show it to you again. If it's lost, rotate the key instead.

Restricting a key to specific services

Pass allowedServices with any combination of BANK, MOBILE_MONEY, TRANSACTION, and BUSINESS_LICENSE. Omit it (or pass an empty array) for a key that can call every service the organization's subscription includes. A key used against a service it isn't allowed to call receives 403 Forbidden.

Rotating a key

POST /api/v1/api-keys/{id}/rotate invalidates the old secret and returns a new one, without changing the key's name, environment, or restrictions. Use this if a secret may have leaked.

Revoking a key

DELETE /api/v1/api-keys/{id} immediately invalidates the key. Revoked keys return 401 Unauthorized on every subsequent request.

On this page