Authentication & Credentials
DigetPay uses different credentials depending on the API or product you are integrating with. Always use the credential required by the API you are calling, and store all credentials securely.
Authentication at a Glance
| API / Product | Credential | Header / Method | Used For |
|---|---|---|---|
| Payment APIs | Merchant API Key | x-api-key | Hosted Checkout, embedded payments, transaction status, refunds |
| Merchant Portal APIs | Portal Bearer Token | Authorization: Bearer <token> | Merchant account management, API credentials, webhook management, SDK-token management |
| SoftPOS / SmartPOS / Mobile SDKs | SDK Token | Product-specific | SDK authentication and provisioning |
Important: Payment API keys and Portal Bearer tokens are different credentials and must not be interchanged. A
401 Unauthorizedresponse can occur when the wrong credential or environment is used.
1. Payment API Authentication
Payment APIs are authenticated using the merchant API key in the x-api-key request header.
Get Your Merchant API Key
- Complete Merchant Onboarding.
- Sign in to the DigetPay staging or production dashboard.
- Navigate to Settings → API Credentials.
- Copy the API key for the required environment.
- Store the key securely in your server-side secrets manager.
Never expose your API key in frontend code, mobile applications, browser JavaScript, or public repositories.
Example Request
curl -X POST "https://api.digetpay.com/v1/payment/checkout/intiate" \
-H "Content-Type: application/json" \
-H "x-api-key: YOUR_STAGING_API_KEY" \
-d '{
"merchantOrderId": "ORDER-1001",
"amount": 0.20,
"currency": "SAR",
"customerPhone": "501223324",
"successUrl": "https://merchant.example.com/payment/success",
"failureUrl": "https://merchant.example.com/payment/failure"
}'A successful request returns HTTP 201 and includes the transaction id and redirectUrl.
2. Merchant Portal API Authentication
Merchant Portal APIs use a Portal Bearer Token.
Include the token in the Authorization header:
Authorization: Bearer YOUR_PORTAL_TOKENPortal Bearer tokens are used for operations such as:
- Managing merchant API credentials
- Managing webhooks
- Managing SDK tokens
- Accessing merchant account management APIs
- Other Merchant Portal operations
Important: A Merchant API Key cannot be used as a Portal Bearer Token, and a Portal Bearer Token cannot be used as the
x-api-keyfor payment APIs.
3. Obtain a Portal Bearer Token
Before calling Merchant Portal APIs, the merchant or authorized integration must obtain a valid Portal Bearer Token through the DigetPay Portal authentication flow.
Authentication Flow
- Open the appropriate DigetPay Portal environment.
- Authenticate using the merchant/partner Portal credentials.
- Call the Portal authentication endpoint.
- Receive the Portal Bearer Token from the authentication response.
- Store the token securely.
- Include the token in the
Authorizationheader for subsequent Portal API requests.
Portal Authentication Endpoint
Implementation note: Use the authentication endpoint provided by the DigetPay Portal API/Swagger documentation.
POST <PORTAL_AUTHENTICATION_ENDPOINT>Example request structure:
{
"username": "YOUR_PORTAL_USERNAME",
"password": "YOUR_PORTAL_PASSWORD"
}The authentication response provides the Portal Bearer Token required to access protected Merchant Portal APIs.
Do not hard-code Portal credentials or tokens in source code. Use a secure secrets manager or equivalent credential store.
Use the Token in Portal API Requests
Once the token is obtained, include it in every protected Portal API request:
curl -X GET "https://fin-api.digetpay.com/v1/merchant/account/credentials" \
-H "Authorization: Bearer YOUR_PORTAL_TOKEN"4. Refresh a Portal Bearer Token
Portal Bearer Tokens may need to be refreshed or re-issued when they expire or become invalid.
The integration should:
- Monitor the token lifetime or authentication response.
- Request a new token using the DigetPay Portal authentication/refresh mechanism.
- Replace the expired token in the secure credential store.
- Retry the Portal API request using the new token.
Token Refresh Endpoint
Implementation note: Use the actual refresh/re-authentication endpoint and request format defined by the DigetPay Portal API/Swagger documentation.
POST <PORTAL_TOKEN_REFRESH_ENDPOINT>If the Portal authentication implementation does not provide a dedicated refresh-token endpoint, perform the documented Portal authentication flow again to obtain a new Bearer Token.
Recommended Token Handling
Merchant / Integration
|
v
Authenticate with DigetPay Portal
|
v
Obtain Portal Bearer Token
|
v
Store Token Securely
|
v
Call Merchant Portal APIs
|
v
Token Expired / Invalid?
|
Yes
|
v
Refresh / Re-authenticate
|
v
Store New Token
|
v
Continue API RequestsDo not implement token refresh logic based on assumed endpoints or response fields. Always follow the authentication contract provided by the DigetPay Portal API.
5. Portal API Example
The following example shows how a valid Portal Bearer Token is used to access merchant credentials:
GET /merchant/account/credentials
Host: fin-api.digetpay.com
Authorization: Bearer YOUR_PORTAL_TOKENThe Portal Bearer Token authenticates the request, while the merchant API key returned by the credentials API is used separately when calling Payment APIs.
6. Environments and Credentials
Credentials are environment-specific. Do not use staging credentials against production APIs or production credentials against staging APIs.
| Environment | Payment API | Dashboard | Credential |
|---|---|---|---|
| Staging | https://fin-api.digetpay.com/v1 | https://fin-admin.digetpay.com | Staging credentials |
| Production | https://api.digetpay.com/v1 | https://admin.digetpay.com | Production credentials |
Environment Rule
Staging Dashboard
↓
Staging Credentials
↓
Staging API
Production Dashboard
↓
Production Credentials
↓
Production APINever mix credentials between environments.
7. API Key Rotation
Merchant API keys should be rotated periodically and immediately if a credential is suspected to be compromised.
Recommended Rotation Process
- Generate or request a replacement API key through the DigetPay Dashboard or authorized Portal API.
- Store the new key securely.
- Update the integration's secret configuration.
- Deploy the updated configuration.
- Verify that API requests are successful.
- Revoke the old key when it is no longer required.
Merchant Portal
|
v
Generate / Rotate API Key
|
v
New API Credential
|
v
Update Secrets Manager
|
v
Deploy Integration
|
v
Verify API Requests
|
v
Revoke Old CredentialImportant: API key rotation is separate from Portal Bearer Token refresh. Payment API keys authenticate Payment APIs, while Portal Bearer Tokens authenticate Merchant Portal APIs.
8. Authentication Errors
| HTTP Status | Error Scenario | Possible Cause |
|---|---|---|
401 | Missing API key | x-api-key header was not provided |
401 | Invalid API key | Incorrect, inactive, or wrong-environment API key |
401 | Missing Bearer token | Authorization header was not provided |
401 | Invalid Bearer token | Portal token is expired, invalid, or revoked |
401 | Wrong credential type | Payment API key used for Portal API or vice versa |
401 | Wrong environment | Staging credential used against production or vice versa |
401 | Merchant not found | Merchant record is missing or not synchronized |
Troubleshooting Checklist
When receiving 401 Unauthorized:
- Confirm that the correct authentication header is being sent.
- Confirm that the credential belongs to the requested environment.
- For Payment APIs, verify the
x-api-key. - For Portal APIs, verify the
Authorization: Bearer <token>header. - Check whether the Portal Bearer Token has expired or been revoked.
- Refresh or re-authenticate to obtain a new Portal Bearer Token when required.
- Confirm that the merchant has access to the requested API.
- Retry the request after correcting the credential.
9. Security Best Practices
- Keep API keys and Portal Bearer Tokens server-side.
- Never expose credentials in frontend applications.
- Never commit credentials to source control.
- Store credentials in environment variables or a secure secrets manager.
- Use separate credentials for staging and production.
- Rotate compromised credentials immediately.
- Do not log complete API keys or Bearer Tokens.
- Mask credentials in application logs and monitoring systems.
- Limit access to credentials to authorized systems and personnel.
- Do not share credentials through email, chat, screenshots, or public documentation.
- Treat Portal Bearer Tokens as sensitive credentials.
- Re-authenticate or refresh Portal tokens according to their actual expiration policy.
10. Quick Reference
Payment API
x-api-key: YOUR_MERCHANT_API_KEYUse for:
- Payment initiation
- Hosted Checkout
- Embedded payments
- Transaction status
- Refunds
Merchant Portal API
Authorization: Bearer YOUR_PORTAL_TOKENUse for:
- Merchant account management
- API credential management
- Webhook management
- SDK-token management
Related Guides
- Merchant Signup & KYC
- Account Activation
- Environments Overview
- API Key Management
- Dashboard API Credentials
- Merchant Portal API Reference
- Webhooks
- SDK Authentication
Integration note: The exact Portal authentication and token-refresh endpoint, request body, response fields, expiration behavior, and refresh-token mechanism must match the currently deployed DigetPay Portal API. Replace the placeholders in Sections 3 and 4 with the actual Swagger/API contract before publishing this page.
Updated about 1 month ago

