Skip to content

Authentication and keys

Call without a key or with a free key, create the key in the 221 Pay dashboard, quotas and authentication errors.

The key is optional. Data routes can be called without a key, within a daily limit per IP address; a free key widens that quota and ties your calls to a project (usage, log).

Quotas with and without a key

CallDaily quotaCounted per
Without a key100 callsIP address
With a key1,000 callskey

The counter resets at midnight GMT (Senegal time). Each counted response carries RateLimit-Limit (quota), RateLimit-Remaining (calls left) and RateLimit-Reset (seconds before the reset). Beyond that, the API answers 429 QUOTA_EXCEEDED (members limit and reset_at) with the Retry-After header.

Create a key

Sign in to the 221 Pay dashboard

Open the 221 Pay dashboard and sign in, or create an account.

Pick a project

A key belongs to a project. You can have up to three projects.

Create the key

Give it a name and a validity period: never, 30 days, 90 days or 1 year.

Copy the secret

Shown only once

The secret starts with sk_221_pay_test_ or sk_221_pay_live_, depending on its mode. It is shown only at creation: copy it into your server's secret manager. If lost, it cannot be recovered: revoke the key and create another one.

Send the key

Add the Authorization header to every call:

Header
Authorization: Bearer sk_221_pay_test_…

Keep the key on the server: never in code run by the browser nor in a published mobile app. The API only allows the hub's origin in CORS; your app calls your server, which calls the API.

Authentication errors

StatusCodeCause
401INVALID_API_KEYUnknown or malformed key. Check it, or call without a key.
401API_KEY_EXPIRED, API_KEY_REVOKEDExpired or revoked key. Create a new one.
429QUOTA_EXCEEDEDDaily quota reached. Wait Retry-After seconds.

A key can be revoked by its owner at any time, or disabled by an administrator in case of abuse.

What next?