DevelopersStart

Authentication

Authenticate v1 requests with your app id and secret over HTTP Basic, read the 401, and roll or disable a secret safely.

2 min read

Every v1 request carries your application's app id and app secret in one HTTP Basic header. There are no other credentials: no bearer tokens and no publishable key.

The header

Authorization: Basic base64(app_id:app_secret)
CredentialPrefixWhere it lives
App idfian_app_Your server's environment, as FIANTO_APP_ID for the SDK and CLI
App secretfian_sk_live_Your server's environment, as FIANTO_APP_SECRET. Never in a browser

The secret starts with fian_sk_live_ on every deployment, devnet included. The prefix does not tell you which cluster the key belongs to.

curl --user builds the Basic header from app_id:app_secret for you.

curl https://api.fianto.xyz/v1/application \
  --user "$FIANTO_APP_ID:$FIANTO_APP_SECRET"

When authentication fails

Every credential problem gets the same answer: a malformed header, an unknown, revoked or expired secret, a disabled application, or a merchant account that is not approved and active. Fianto does not say which one it was.

HTTP/1.1 401 Unauthorized
WWW-Authenticate: Basic realm="fianto"
{
  "statusCode": 401,
  "error": "Unauthorized",
  "code": "invalid_api_credentials",
  "message": "Invalid API credentials. Send \"Authorization: Basic base64(app_id:app_secret)\".",
  "request_id": "req_…"
}

In the SDK this is an AuthenticationError.

Credentials stop working when the account does

Your keys work only while your merchant account is approved and active. If it is not, for example after an admin deactivates it, every v1 request answers 401 invalid_api_credentials, even with the right secret.

Applications

  • A merchant can have up to 10 active applications and 100 in total.
  • Creating an application needs your password, plus your two-factor code. Its secret is shown once: copy it straight away.

Roll a secret

Roll a secret in the dashboard, for example when it may have leaked. Rolling needs your password and two-factor code, and shows the new secret once.

You choose when the current secret stops working: immediately, in 1 hour (preselected) or in 24 hours. Until then, both secrets work, so you can deploy the new one before the old one stops. At most two secrets are valid at a time.

Rolling immediately breaks every server still on the old secret

With "Immediately", requests that send the old secret fail with 401 as soon as the roll finishes. Pick a grace period unless the old secret has leaked.

Disable an application

Disabling an application is permanent. It revokes its secrets, disables its webhook endpoint and cancels its pending webhook deliveries. To connect again, create a new application.

See also

Was this page helpful? Tell us

On this page