Security Note: Only the public key belongs in client-side code. The secret key authenticates requests as you — keep it on your server, never in a browser or mobile app, and never in source control.
Which credential do I need?
Find the API you are integrating, and use the mechanism on that row.
If you are only collecting payments online, the bearer token is the only one you need.
Bearer token
Most collection APIs authenticate with a bearer token generated from your two keys, joined by a full stop, secret key first. POSTRequest
Response
data.EncryptedSecKey.encryptedKey and send it on subsequent calls:
Signing a request body
The in-store and payout APIs do not use a bearer token alone. They require a signature over the exact bytes of the request body, computed with your secret key and sent in a header —Hash for in-store, X-Seerbit-Signature for payout.
In-store request hashing
Python, Node, Java, PHP, C#, Ruby and Go, with the
Hash header.Payout signatures
Generating
X-Seerbit-Signature for single and bulk payouts.Hash endpoint
SeerBit also exposes an endpoint that returns a hash for a payload, for cases where computing one locally is impractical. POSTNote: Prefer computing signatures locally where you can. A round trip to hash a body means the signed bytes and the transmitted bytes are produced separately, which is the usual cause of signature mismatches.
Next steps
Quickstart
Use a bearer token to take a test payment end to end.
Test and live modes
Which key pair you are using, and how to tell.