The pawaPay Merchant API can only be used with an authentication token. You can read more about how this token can be used to access our API from our API docs. This functionality is available to users with the Technical Administration role. Read more about User roles.

Generating an API token

Press the “Generate Token” button to generate an API token. You can have at most 2 active API tokens at a time.
Generate Token
You can use the “Copy to clipboard” button to easily copy the API token.
Store your token safely as pawaPay does not store your token after generating it for security reasons.You need to configure your Callback URLs to be able to generate API tokens.

Active API tokens

Your active API tokens are listed together with the information about who generated them, when they were generated, and the Token ID. Note that the Token ID is not usable as the token itself but is only used for identifying a specific token when contacting our support team.
Active API Tokens

Revoking tokens

If you need to revoke an API token, you can press the “Revoke” button which is found under the “Actions” column.
Revoke Token
Revoking an API token will immediately stop all payments that use the given token to authenticate API calls!

Signed requests

You can enable pawaPay to only accept signed requests for financial calls. You will need to provide us with the public key of the key pair you are signing your requests with.

Accepted algorithms

We accept 4 kinds of encryption algorithms:

Adding a public key

1

Add your public key

You can add your public key by navigating to the Security tab and pressing on “Add public key”.
Add Public Key
2

Enter public key details

You will then be presented a window where you can:
  1. Name your public key
  2. Enter the public key itself
  3. Choose whether you want to immediately start accepting only signed requests
Add Key Details
3

And done!

After successfully adding a key you will be able to view and remove it.
View and Remove Key
You can also switch this feature on and off by using the toggle. Switching the feature off will not remove any existing keys.
Switch Feature On/Off

Signed callbacks

Enable this feature to make pawaPay sign all callbacks. You can then verify those signatures when receiving the callback to ensure they have not been tampered with and are coming from pawaPay.
Signed Callbacks
Read more about signed callbacks in our API docs.