Authentication

API Key Authentication

All API requests must be authenticated using your private API key. This key is provided in your merchant dashboard under API Settings.

⚠️ Security Warning: Never expose your private key in client-side code, public repositories, or unsecured locations. Always keep it confidential and store it securely on your server.

Getting Your API Keys

  1. Login to your merchant dashboard
  2. Navigate to API Settings
  3. Copy your Private Key
  4. Optionally configure IP whitelist for added security

Making Authenticated Requests

Include your API key in the Authorization header using Bearer token format:

Authorization: Bearer YOUR_PRIVATE_KEY
Example Request
curl -X GET https://genesyspay.com/api/v2/wallets \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer sk_live_abc123xyz456..."

Security Features

IP Whitelisting

For enhanced security, you can configure IP whitelisting in your API Settings. When enabled, only requests from whitelisted IP addresses will be accepted.

// If IP whitelisting is enabled and your IP is not whitelisted:
{
  "status": "error",
  "message": "IP address not whitelisted",
  "error_code": "IP_NOT_ALLOWED"
}
API Access Control

API access can be disabled for maintenance or security reasons. If disabled, you'll receive:

{
  "status": "error",
  "message": "API access is disabled for this business. Please contact support.",
  "error_code": "INVALID_TOKEN"
}

Authentication Error Codes

Error Code HTTP Status Description
MISSING_TOKEN 401 No authentication token provided in the request
INVALID_TOKEN 401 The provided API key is invalid or API access is disabled
IP_NOT_ALLOWED 403 Your IP address is not in the whitelist

Testing Authentication

Use the wallets endpoint to test your authentication:

curl -X GET https://genesyspay.com/api/v2/wallets \
  -H "Authorization: Bearer YOUR_PRIVATE_KEY"

Successful authentication response:

{
  "status": "success",
  "data": [
    {
      "currency": "XOF",
      "balance": "10000.00",
      "available_balance": "10000.00"
    }
  ]
}

Best Practices

  • Store API keys in environment variables, not in code
  • Use different keys for testing and production
  • Rotate your API keys periodically
  • Enable IP whitelisting when possible
  • Monitor your API usage for suspicious activity
  • Never log or expose your API keys in error messages