Skip to main content

Authentication

Every request must carry an Authorization: Bearer <token> header.
The public API accepts API keys only. Dashboard sign-in tokens are refused with 401 invalid_token_format.

Key format

New keys use the format ck_live_<prefix>_<secret>. Keys issued earlier in the format cope_sk_live_<key_id>_<secret> keep working unchanged. You do not need to replace them. Live keys produce real side effects. Test-mode keys are reserved for the future public sandbox and are not accepted yet.

Getting a key

  1. Sign in to the COPE vendor dashboard.
  2. Open Settings → API Keys.
  3. Click Create API key, give the key a name, and copy the secret token that appears.
  4. The secret is shown only once — store it securely. It cannot be retrieved later.

Rotation and revocation

  • Issue a new integration, switch the client to the new key, then deactivate the previous one from the same dashboard view.
  • Deactivated and deleted keys stop authenticating within 60 seconds.
  • Keys are scoped to one business. Use separate integrations for separate businesses rather than sharing a key across them.

Failure modes