Skip to main content

Authentication

  • Store-scoped: one store per key
  • Hashed at rest (SHA-256); prefix sk_live_ with first 12 chars shown in dashboard
  • Cannot access Merchant Admin session APIs
Create keys in Get API credentials.

Default developer scopes

Use transactions:read (not legacy payments:read).

WooCommerce keys

Dedicated keys cannot access payment links, transaction list, or developer webhook management.

Scope errors

HTTP 403: