Authentication
CamelPay supports two authentication methods: JWT bearer tokens for account management and API keys for programmatic payment processing.
CamelPay supports two authentication methods depending on the operation you're performing. A third category of endpoint — checkout and payment status — needs neither, since those are hit by your customer, not you.
JWT Bearer Tokens
Used for account/dashboard operations: creating developer apps, generating API keys, submitting KYC documents, managing payment pages and payouts by hand, and registering a webhook URL.
Authorization: Bearer <your_jwt_token>API Key Authentication
Used for the programmatic developer API, all under /v1/*: checking balance, listing transactions, and creating/reading payment pages and payouts from your own backend.
X-API-Key: cp_live_your_api_key_hereAPI keys are scoped — each key only unlocks the /v1/* endpoints matching its granted scopes (see API Keys) — and environment-specific (cp_test_ vs cp_live_ prefix), and can be rotated without affecting your account.
No auth required
The checkout flow itself — POST /v1/payments/checkout and GET /v1/payments/{reference}/status — is public. Your customer's browser or your redirect hits these directly; they aren't scoped to your account at all beyond the payment page's slug.
