API keys
Nuvion authenticates requests using API keys passed as Bearer tokens in theAuthorization header.
No real funds move in sandbox. Always use sandbox keys during development and testing.
Getting your API keys
Sandbox and production keys are managed separately.Sandbox keys
Create and manage sandbox keys from the Nuvion sandbox dashboard.
Production keys
Create and manage production keys from the Nuvion production dashboard.
Key scopes
Each API key is assigned an access role when it’s created. The role determines which parts of the API the key can use.Making authenticated requests
Pass your API key in theAuthorization header on every request.
401 error:
403 error:
Keeping keys secure
- Store keys in environment variables or a secrets manager, never hardcode them.
- Rotate keys immediately if you suspect they have been compromised. You can do this from your dashboard without downtime by creating a new key before deleting the old one.
- Delete keys that are no longer in use.
