AdeyVerify

Authentication

API keys and session authentication

AdeyVerify supports two authentication methods. Which one applies depends on where the request comes from.

API keys (for your integration)

Every programmatic request under /api/v1 should authenticate with an API key:

Authorization: Bearer av_test_xxxxxxxxxxxxxxxxxxxxxxxx
  • Keys are created from the dashboard's API Keys page and belong to an organization, not an individual user — any key created by any member of the org can access that org's data.
  • Keys are stored as a SHA-256 hash; the full secret is shown only once, at creation or rotation.
  • A key can optionally be restricted to specific services (BANK, MOBILE_MONEY, TRANSACTION, BUSINESS_LICENSE). Calling a service the key isn't allowed to use returns 403 Forbidden.
  • Revoked or expired keys are rejected with 401 Unauthorized.

Session cookies (for the in-dashboard sandbox)

When you use a verification form inside the AdeyVerify dashboard itself, it authenticates with your logged-in session cookie instead of an API key — there's nothing you need to configure for this; it's only relevant if you're inspecting requests made from the dashboard UI.

Which organization am I acting as?

Every authenticated request resolves to exactly one organization:

  • API key auth: the organization the key belongs to.
  • Session auth: whichever organization is currently active in your dashboard session (the org switcher in the sidebar).

All data — verification records, API keys, subscriptions — is strictly isolated per organization. There is no way to read another organization's data, regardless of authentication method.

On this page