DevelopersStart
Authentication
Authenticate v1 requests with your app id and secret over HTTP Basic, read the 401, and roll or disable a secret safely.
Every v1 request carries your application's app id and app secret in one HTTP Basic header. There are no other credentials: no bearer tokens and no publishable key.
The header
Authorization: Basic base64(app_id:app_secret)| Credential | Prefix | Where it lives |
|---|---|---|
| App id | fian_app_ | Your server's environment, as FIANTO_APP_ID for the SDK and CLI |
| App secret | fian_sk_live_ | Your server's environment, as FIANTO_APP_SECRET. Never in a browser |
The secret starts with fian_sk_live_ on every deployment, devnet included. The prefix does not tell
you which cluster the key belongs to.
curl --user builds the Basic header from app_id:app_secret for you.
curl https://api.fianto.xyz/v1/application \
--user "$FIANTO_APP_ID:$FIANTO_APP_SECRET"When authentication fails
Every credential problem gets the same answer: a malformed header, an unknown, revoked or expired secret, a disabled application, or a merchant account that is not approved and active. Fianto does not say which one it was.
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Basic realm="fianto"{
"statusCode": 401,
"error": "Unauthorized",
"code": "invalid_api_credentials",
"message": "Invalid API credentials. Send \"Authorization: Basic base64(app_id:app_secret)\".",
"request_id": "req_…"
}In the SDK this is an AuthenticationError.
Credentials stop working when the account does
Your keys work only while your merchant account is approved and active. If it is not, for example
after an admin deactivates it, every v1 request answers 401 invalid_api_credentials, even
with the right secret.
Applications
- A merchant can have up to 10 active applications and 100 in total.
- Creating an application needs your password, plus your two-factor code. Its secret is shown once: copy it straight away.
Roll a secret
Roll a secret in the dashboard, for example when it may have leaked. Rolling needs your password and two-factor code, and shows the new secret once.
You choose when the current secret stops working: immediately, in 1 hour (preselected) or in 24 hours. Until then, both secrets work, so you can deploy the new one before the old one stops. At most two secrets are valid at a time.
Rolling immediately breaks every server still on the old secret
With "Immediately", requests that send the old secret fail with 401 as soon as the roll finishes. Pick a grace period unless the old secret has leaked.
Disable an application
Disabling an application is permanent. It revokes its secrets, disables its webhook endpoint and cancels its pending webhook deliveries. To connect again, create a new application.
See also
Was this page helpful? Tell us