Get started

Authentication

CamelPay supports two authentication methods: JWT bearer tokens for account management and API keys for programmatic payment processing.

CamelPay supports two authentication methods depending on the operation you're performing. A third category of endpoint — checkout and payment status — needs neither, since those are hit by your customer, not you.

JWT Bearer Tokens

Used for account/dashboard operations: creating developer apps, generating API keys, submitting KYC documents, managing payment pages and payouts by hand, and registering a webhook URL.

Authorization: Bearer <your_jwt_token>
JWT tokens expire after 1 hour. Re-authenticate to get a new one.

API Key Authentication

Used for the programmatic developer API, all under /v1/*: checking balance, listing transactions, and creating/reading payment pages and payouts from your own backend.

X-API-Key: cp_live_your_api_key_here

API keys are scoped — each key only unlocks the /v1/* endpoints matching its granted scopes (see API Keys) — and environment-specific (cp_test_ vs cp_live_ prefix), and can be rotated without affecting your account.

No auth required

The checkout flow itself — POST /v1/payments/checkout and GET /v1/payments/{reference}/status — is public. Your customer's browser or your redirect hits these directly; they aren't scoped to your account at all beyond the payment page's slug.