Guides/Integration
API keys
Create, protect and rotate sandbox and production credentials.
Every private endpoint expects an API key in the X-API-Key header.
Send the key
curl https://integrate.api.kyvopay.com.br/v1/balance \
-H "X-API-Key: ky_XXXXX-XXXXX-XXXXX" \
-H "Accept: application/json"Security
Use API keys only from trusted backend services. Never embed a key in JavaScript shipped to browsers, mobile apps, logs, screenshots or public repositories.
Store credentials safely
Use a secret manager in production and a local environment variable during development. Restrict access to the smallest set of services and people that need it.
Rotate a key
Create the replacement key, deploy it, verify traffic with the new credential and only then revoke the old key. This overlap avoids downtime.
Common responses
401 Unauthorized: the header is missing or the key is invalid/revoked.403 Forbidden: the key is valid but lacks permission or the source IP is not allowed.429 Too Many Requests: slow down and retry with exponential backoff.