Authentication
API keys and session authentication
AdeyVerify supports two authentication methods. Which one applies depends on where the request comes from.
API keys (for your integration)
Every programmatic request under /api/v1 should authenticate with an API key:
Authorization: Bearer av_test_xxxxxxxxxxxxxxxxxxxxxxxx- Keys are created from the dashboard's API Keys page and belong to an organization, not an individual user — any key created by any member of the org can access that org's data.
- Keys are stored as a SHA-256 hash; the full secret is shown only once, at creation or rotation.
- A key can optionally be restricted to specific services (
BANK,MOBILE_MONEY,TRANSACTION,BUSINESS_LICENSE). Calling a service the key isn't allowed to use returns403 Forbidden. - Revoked or expired keys are rejected with
401 Unauthorized.
Session cookies (for the in-dashboard sandbox)
When you use a verification form inside the AdeyVerify dashboard itself, it authenticates with your logged-in session cookie instead of an API key — there's nothing you need to configure for this; it's only relevant if you're inspecting requests made from the dashboard UI.
Which organization am I acting as?
Every authenticated request resolves to exactly one organization:
- API key auth: the organization the key belongs to.
- Session auth: whichever organization is currently active in your dashboard session (the org switcher in the sidebar).
All data — verification records, API keys, subscriptions — is strictly isolated per organization. There is no way to read another organization's data, regardless of authentication method.