Skip to content

Get started

API keys and environments

Every API request is authenticated with a secret key from your server. The key also decides whether you are working in sandbox or live.

Authenticate requests

Send the full key as a bearer token. Keys are secrets: keep them on your server and out of browser code, URLs, source control and logs.

Header
Authorization: Bearer wgp_test_…

A missing, malformed, revoked or disabled key returns 401 unauthorized. Dashboard session tokens are not API keys and are rejected.

Sandbox and live

Key prefixEnvironmentUse it for
wgp_test_…SandboxDevelopment and acceptance testing. No money moves.
wgp_live_…LiveReal customer payments, after live approval.
  • The environment comes from the key. You can omit environment on create; if you send it, it must match.
  • Reads and lists only see payments of the key’s merchant and environment. Anything else returns 404.
  • Sandbox and live have separate webhook endpoints and signing secrets.
  • Use different idempotency keys in each environment.

Create and rotate keys

In Dashboard → API Keys, enter an integration name, choose sandbox or live, and select Create API key. Use Copy to retrieve the full key; the list itself is masked and every disclosure is audited.

  • Rotate: create and deploy a new key first, then revoke the old one.
  • Revoke: permanent. New requests with the key fail; payments it created keep their webhook routing.
  • Rename: open Key settings. Names are 1–100 characters; credentials do not change.

Each key can also use its own webhook endpoint and checkout settings. See webhooks and checkout settings.

Going live

Live access is a separate approval. Before switching keys, agree with Wegopay on supported payment methods, transaction limits, settlement and an operational contact. Then complete the sandbox acceptance checks.

Currency and limits

Payments are in USD, from 500 to 100,000,000 cents ($5 to $1,000,000). Your agreed limits may be lower.