API Keys
Creating, rotating, and restricting API keys
API keys are managed from the dashboard's API Keys page, or programmatically via the API Keys endpoints.
Creating a key
{
"name": "Production backend",
"environment": "LIVE",
"allowedServices": ["BANK", "TRANSACTION"]
}The response includes the full secret — this is the only time it's shown:
{
"id": "cmun...",
"name": "Production backend",
"prefix": "av_live_a1b2",
"environment": "LIVE",
"secret": "av_live_a1b2c3d4e5f6...",
"allowedServices": ["BANK", "TRANSACTION"]
}Store the secret securely (a secrets manager or environment variable) — AdeyVerify cannot show it to you again. If it's lost, rotate the key instead.
Restricting a key to specific services
Pass allowedServices with any combination of BANK, MOBILE_MONEY, TRANSACTION, and
BUSINESS_LICENSE. Omit it (or pass an empty array) for a key that can call every service the
organization's subscription includes. A key used against a service it isn't allowed to call
receives 403 Forbidden.
Rotating a key
POST /api/v1/api-keys/{id}/rotate invalidates the old secret and returns a new one, without
changing the key's name, environment, or restrictions. Use this if a secret may have leaked.
Revoking a key
DELETE /api/v1/api-keys/{id} immediately invalidates the key. Revoked keys return
401 Unauthorized on every subsequent request.