Skip to content
English
  • There are no suggestions because the search field is empty.

How should I protect my MerchantSpring API key?

Treat your MerchantSpring API key like a password and keep it out of ordinary email, chat and support communications.

Your MerchantSpring API key authenticates API requests and determines the organisation and data available to the authorised user. Anyone with access to the key may be able to make requests using those permissions.

API key security best practices
  • Store the key only in an approved secure credential or secret-management system
  • Do not paste the full key into email, Slack, chat or a support ticket
  • Redact the key from screenshots, cURL examples and copied requests
  • Use a placeholder such as YOUR_API_KEY in documentation and examples
  • Only share access with people and applications that are authorised to use it
What should I send to Support?

Send the endpoint, parameters, response and error details, but remove the full API key. Support can investigate most request issues without seeing the secret value.

What if my key has been exposed?

Stop sharing or using the exposed value and contact MerchantSpring Support as soon as possible so the appropriate key-rotation steps can be taken.

Need more help? Contact MerchantSpring Support at support@merchantspring.io.