Skip to content

Authentication

Server-to-server endpoints are authenticated with your account API token, sent as a Bearer token:

GET /api/transaction/99101 HTTP/1.1
Host: api.creditcore.io
Authorization: Bearer <YOUR_API_TOKEN>
  • An admin user of your account generates the token in the platform, from the profile menu → API Token (see Users & access). Generating a new token replaces the previous one.
  • All data returned is limited to the account that owns the token.
  • Deactivated tokens are rejected.

The checkout itself is submitted from the browser by the Payment SDK and doesn’t use your API token. It’s authorized by the session ID your server created, which:

  • expires after 5 minutes,
  • is bound to the domain you specified,
  • belongs to your account, so the payment is recorded under it.

A missing, invalid or inactive token returns 401:

{ "error": "UNAUTHORIZED", "status": 401 }