Authentication

All external API calls require authentication via the X-API-Key request header. Your API key is found in Dashboard → Integrations.

Two keys, two environments

Every merchant has a test key and a live key. The key you send decides the environment of the request — there is no separate sandbox URL and no parameter to set.

  • kashia_sk_test_… — works as soon as your email is verified, before approval. Payment links and escrows it creates are test rows: no card is charged, no bank is called, no email is sent, and nothing it does ever reaches a live balance. Test payments are simulated on the checkout page.
  • kashia_sk_live_… — works once your merchant account is approved. Moves real money.
  • Include X-API-Key on every server-to-server request
  • Keep both keys secret — never expose them in frontend code or client-side apps

Request header

Header
X-API-Key: kashia_sk_test_xxxxxxxxxxxxxxxxxxxx

Telling test from live in responses

Every payment link, escrow, and webhook payload carries an environment field — "test" or "live" — so your code can never mistake a simulated event for a real one.

Error responses

Missing or invalid API key

A missing X-API-Key header and an invalid key return the same response:

json
{
  "success": false,
  "error": {
    "code": "INVALID_API_KEY",
    "message": "Invalid or inactive API key"
  }
}

See the full error reference for more error codes and HTTP status codes.