Get started
API keys and environments
Every API request is authenticated with a secret key from your server. The key also decides whether you are working in sandbox or live.
Authenticate requests
Send the full key as a bearer token. Keys are secrets: keep them on your server and out of browser code, URLs, source control and logs.
Authorization: Bearer wgp_test_…A missing, malformed, revoked or disabled key returns 401 unauthorized. Dashboard session tokens are not API keys and are rejected.
Sandbox and live
| Key prefix | Environment | Use it for |
|---|---|---|
wgp_test_… | Sandbox | Development and acceptance testing. No money moves. |
wgp_live_… | Live | Real customer payments, after live approval. |
- The environment comes from the key. You can omit
environmenton create; if you send it, it must match. - Reads and lists only see payments of the key’s merchant and environment. Anything else returns
404. - Sandbox and live have separate webhook endpoints and signing secrets.
- Use different idempotency keys in each environment.
Create and rotate keys
In Dashboard → API Keys, enter an integration name, choose sandbox or live, and select Create API key. Use Copy to retrieve the full key; the list itself is masked and every disclosure is audited.
- Rotate: create and deploy a new key first, then revoke the old one.
- Revoke: permanent. New requests with the key fail; payments it created keep their webhook routing.
- Rename: open Key settings. Names are 1–100 characters; credentials do not change.
Each key can also use its own webhook endpoint and checkout settings. See webhooks and checkout settings.
Going live
Live access is a separate approval. Before switching keys, agree with Wegopay on supported payment methods, transaction limits, settlement and an operational contact. Then complete the sandbox acceptance checks.
Currency and limits