Skip to content
FanakDocs
WebsiteDashboard

Integrate

Authentication

Every API request carries two credentials. Keep both on your server.

Header Value Identifies
X-API-Key pk_ + 64 hex characters The application
Authorization Bearer + access token Your organization

Send Accept: application/json too, and Content-Type: application/json with a body.

Terminal window
curl https://pay.fanak.ly/api/v1/payment-intents/4d893346-bd5e-482f-8347-3f509a877f1a \
-H "X-API-Key: $FANAK_API_KEY" \
-H "Authorization: Bearer $FANAK_ACCESS_TOKEN" \
-H "Accept: application/json"
  • One access token works with the API key of every application in your organization.
  • The API key must belong to an active application of that organization.
  • Another application’s intent returns 403, even in your organization.

Owners and developers manage them in the dashboard.

Credential Where
API key (pk_...) Applications → roll the API key
Webhook secret (whsec_...) Applications → roll the webhook secret (webhooks)
Access token Access tokens → create

Each value is shown once; Fanak keeps only a hash of the API key.

Credential How
API key Rolling stops the old key at once (401). Deploy right after.
Webhook secret Applies at once. See Secret rotation.
Access token Create, deploy, then revoke the old one.

The API answers 401:

Problem Response body
Missing, invalid, revoked or expired token {"message": "Unauthenticated."}
Missing X-API-Key {"error": "Missing X-API-Key header."}
Unknown key, another organization’s key, inactive application {"error": "Invalid API key or inactive application."}