Guides/Integration

API keys

Create, protect and rotate sandbox and production credentials.

Every private endpoint expects an API key in the X-API-Key header.

Send the key

curl https://integrate.api.kyvopay.com.br/v1/balance \
  -H "X-API-Key: ky_XXXXX-XXXXX-XXXXX" \
  -H "Accept: application/json"

Security

Use API keys only from trusted backend services. Never embed a key in JavaScript shipped to browsers, mobile apps, logs, screenshots or public repositories.

Store credentials safely

Use a secret manager in production and a local environment variable during development. Restrict access to the smallest set of services and people that need it.

Rotate a key

Create the replacement key, deploy it, verify traffic with the new credential and only then revoke the old key. This overlap avoids downtime.

Common responses

  • 401 Unauthorized: the header is missing or the key is invalid/revoked.
  • 403 Forbidden: the key is valid but lacks permission or the source IP is not allowed.
  • 429 Too Many Requests: slow down and retry with exponential backoff.
Need help? Contact support
© 2026 KyvoPay