Authentication
All external API calls require authentication via the X-API-Key request header. Your API key is found in Dashboard → Integrations.
Two keys, two environments
Every merchant has a test key and a live key. The key you send decides the environment of the request — there is no separate sandbox URL and no parameter to set.
kashia_sk_test_…— works as soon as your email is verified, before approval. Payment links and escrows it creates are test rows: no card is charged, no bank is called, no email is sent, and nothing it does ever reaches a live balance. Test payments are simulated on the checkout page.kashia_sk_live_…— works once your merchant account isapproved. Moves real money.- Include
X-API-Keyon every server-to-server request - Keep both keys secret — never expose them in frontend code or client-side apps
Request header
Header
X-API-Key: kashia_sk_test_xxxxxxxxxxxxxxxxxxxxTelling test from live in responses
Every payment link, escrow, and webhook payload carries an environment field — "test" or "live" — so your code can never mistake a simulated event for a real one.
Error responses
Missing or invalid API key
A missing X-API-Key header and an invalid key return the same response:
json
{
"success": false,
"error": {
"code": "INVALID_API_KEY",
"message": "Invalid or inactive API key"
}
}See the full error reference for more error codes and HTTP status codes.