LotiFinanceDocs

Authentication

Every API request is authenticated with a secret key, sent as a Bearer token in the Authorization header.

Header format

Header
Authorization: Bearer sk_test_a1b2c3d4e5f6g7h8

Key prefixes

Each merchant account has two key pairs — one per environment:

pk_test_ / pk_live_
public keyoptional
Identifies your account for client-side use. Not used by the charges API today.
sk_test_ / sk_live_
secret keyoptional
Used to authenticate every API request. Never expose this in client-side code.

Keep secret keys server-side

Your sk_ key can create charges against your account. Only call the API from your backend — never from a browser or mobile app.

Test vs. live mode

sk_test_ and sk_live_ keys point at different hosts — sandbox.lotifinance.com for test, live.lotifinance.com for live. Every other detail of the request (paths, fields, response shape) is identical, so switching to production is just changing the host and the key.

Authentication errors

If a request is missing a key, uses an invalid key, or the account is inactive, you'll get:

401 Unauthorized
{
  "detail": "Invalid API key."
}
403 Forbidden
{
  "detail": "Merchant account is not active."
}
  • Make sure the key is sent as Bearer {key}, not the raw key alone.
  • Test keys cannot be used in live mode and vice versa — double-check the prefix.