المصادقة
المفاتيح السرية والمفاتيح القابلة للنشر، والحد الفاصل بين التجريبي والفعلي.
غير متاح بعد — النطاق api.baynoy.com لا يُترجَم، لذا لن تعمل الأمثلة أدناه اليوم. هذه البنى نهائية: صمّم عليها الآن ولن يتغيّر شيء عند الانتقال إلى المفاتيح الحقيقية.
Two key types, one rule
Secret keys (sk_) authenticate your server and can do anything your role allows. Publishable keys (pk_) are safe in a browser and can only start a checkout. If a secret key can reach a browser, it is already compromised.
# server-to-server: secret key, never in a browser or an app bundle
Authorization: Bearer bk_live_...
# browser: publishable key, safe to ship, can only start a checkout
Authorization: Bearer pk_live_...Test and live are separate universes
bk_test_ keys operate on simulated money and never touch live data; bk_live_ keys move real money. There is no flag that turns one into the other, which is deliberate — the environments cannot be mixed by accident.
Scopes and rolling
Payouts, refunds and card reveal require separately scoped keys. Roll a key whenever someone leaves or a key might have been logged; rolling is designed to be routine maintenance, not an incident.