Authentication and keys
Call without a key or with a free key, create the key in the 221 Pay dashboard, quotas and authentication errors.
The key is optional. Data routes can be called without a key, within a daily limit per IP address; a free key widens that quota and ties your calls to a project (usage, log).
Quotas with and without a key
| Call | Daily quota | Counted per |
|---|---|---|
| Without a key | 100 calls | IP address |
| With a key | 1,000 calls | key |
The counter resets at midnight GMT (Senegal time). Each counted response
carries RateLimit-Limit (quota), RateLimit-Remaining (calls left) and
RateLimit-Reset (seconds before the reset). Beyond that, the API answers
429 QUOTA_EXCEEDED (members limit and reset_at) with the Retry-After
header.
Create a key
Sign in to the 221 Pay dashboard
Open the 221 Pay dashboard and sign in, or create an account.
Pick a project
A key belongs to a project. You can have up to three projects.
Create the key
Give it a name and a validity period: never, 30 days, 90 days or 1 year.
Copy the secret
Shown only once
The secret starts with sk_221_pay_test_ or sk_221_pay_live_, depending on its mode. It is shown only at creation: copy it into
your server's secret manager. If lost, it cannot be recovered: revoke the key
and create another one.
Send the key
Add the Authorization header to every call:
Authorization: Bearer sk_221_pay_test_…Keep the key on the server: never in code run by the browser nor in a published mobile app. The API only allows the hub's origin in CORS; your app calls your server, which calls the API.
Authentication errors
| Status | Code | Cause |
|---|---|---|
| 401 | INVALID_API_KEY | Unknown or malformed key. Check it, or call without a key. |
| 401 | API_KEY_EXPIRED, API_KEY_REVOKED | Expired or revoked key. Create a new one. |
| 429 | QUOTA_EXCEEDED | Daily quota reached. Wait Retry-After seconds. |
A key can be revoked by its owner at any time, or disabled by an administrator in case of abuse.