Skip to main content

API keys

Nuvion authenticates requests using API keys passed as Bearer tokens in the Authorization header.
API keys are environment-specific. No real funds move in sandbox. Always use sandbox keys during development and testing.

Getting your API keys

Sandbox and production keys are managed separately.

Sandbox keys

Create and manage sandbox keys from the Nuvion sandbox dashboard.

Production keys

Create and manage production keys from the Nuvion production dashboard.

Key scopes

Each API key is assigned an access role when it’s created. The role determines which parts of the API the key can use.
Create dedicated API keys for each service or integration, scoped to the minimum role it needs. This limits the blast radius if a key is compromised and makes it easier to audit which service made a given request.

Making authenticated requests

Pass your API key in the Authorization header on every request.
Requests without a valid key return a 401 error:
Requests made with a key that lacks the required permissions return a 403 error:
See Errors for the full error object schema and error type reference.

Keeping keys secure

API keys carry the same privileges as your account credentials. Never expose them in client-side code, public repositories, or logs.
  • Store keys in environment variables or a secrets manager, never hardcode them.
  • Rotate keys immediately if you suspect they have been compromised. You can do this from your dashboard without downtime by creating a new key before deleting the old one.
  • Delete keys that are no longer in use.

IP allowlisting

For webhook endpoints, Nuvion supports IP allowlisting to restrict inbound delivery to Nuvion’s IP ranges only. Contact support to obtain the list of Nuvion IP addresses and configuration details. See Verifying webhook signatures for another way to confirm inbound requests genuinely originate from Nuvion.