Skip to main content
Every SeerBit API is authenticated with the public key and secret key from your dashboard, under Settings > API Keys. What differs is the form those keys take on the request.
Security Note: Only the public key belongs in client-side code. The secret key authenticates requests as you — keep it on your server, never in a browser or mobile app, and never in source control.

Which credential do I need?

Find the API you are integrating, and use the mechanism on that row. If you are only collecting payments online, the bearer token is the only one you need.

Bearer token

Most collection APIs authenticate with a bearer token generated from your two keys, joined by a full stop, secret key first. POST

Request

Response

Take the token from data.EncryptedSecKey.encryptedKey and send it on subsequent calls:
Generate the token on your server. Because it is derived from your secret key, a token in client-side code is as exposed as the key itself.

Signing a request body

The in-store and payout APIs do not use a bearer token alone. They require a signature over the exact bytes of the request body, computed with your secret key and sent in a header — Hash for in-store, X-Seerbit-Signature for payout.
Compute it in your own code rather than calling an endpoint, so the signed bytes are the bytes you actually transmit. Whitespace or key-order differences between what you hash and what you send produce a mismatch. Worked examples in seven languages are on the pages that need them:

In-store request hashing

Python, Node, Java, PHP, C#, Ruby and Go, with the Hash header.

Payout signatures

Generating X-Seerbit-Signature for single and bulk payouts.

Hash endpoint

SeerBit also exposes an endpoint that returns a hash for a payload, for cases where computing one locally is impractical. POST
Post the payload you intend to send, and the response carries the transaction result for it.
Note: Prefer computing signatures locally where you can. A round trip to hash a body means the signed bytes and the transmitted bytes are produced separately, which is the usual cause of signature mismatches.

Next steps

Quickstart

Use a bearer token to take a test payment end to end.

Test and live modes

Which key pair you are using, and how to tell.