Authentication
Every API request is authenticated with a secret key, sent as a Bearer token in the Authorization header.
Header format
Header
Authorization: Bearer sk_test_a1b2c3d4e5f6g7h8Key prefixes
Each merchant account has two key pairs — one per environment:
pk_test_ / pk_live_public keyoptional | Identifies your account for client-side use. Not used by the charges API today. |
sk_test_ / sk_live_secret keyoptional | Used to authenticate every API request. Never expose this in client-side code. |
Keep secret keys server-side
Your
sk_ key can create charges against your account. Only call the API from your backend — never from a browser or mobile app.Test vs. live mode
sk_test_ and sk_live_ keys point at different hosts — sandbox.lotifinance.com for test, live.lotifinance.com for live. Every other detail of the request (paths, fields, response shape) is identical, so switching to production is just changing the host and the key.
Authentication errors
If a request is missing a key, uses an invalid key, or the account is inactive, you'll get:
401 Unauthorized
{
"detail": "Invalid API key."
}403 Forbidden
{
"detail": "Merchant account is not active."
}- Make sure the key is sent as
Bearer {key}, not the raw key alone. - Test keys cannot be used in live mode and vice versa — double-check the prefix.