인증

시크릿 키, 퍼블리셔블 키, 그리고 테스트와 실거래를 가르는 경계.

아직 사용할 수 없습니다 — api.baynoy.com 도메인이 조회되지 않으므로 아래 예제는 지금 실행되지 않습니다. 이 형식은 확정되었습니다. 지금 이대로 설계하시면 라이브 키로 전환할 때 달라지는 것이 없습니다.

Two key types, one rule

Secret keys (sk_) authenticate your server and can do anything your role allows. Publishable keys (pk_) are safe in a browser and can only start a checkout. If a secret key can reach a browser, it is already compromised.

cURL
# server-to-server: secret key, never in a browser or an app bundle
Authorization: Bearer bk_live_...

# browser: publishable key, safe to ship, can only start a checkout
Authorization: Bearer pk_live_...

Test and live are separate universes

bk_test_ keys operate on simulated money and never touch live data; bk_live_ keys move real money. There is no flag that turns one into the other, which is deliberate — the environments cannot be mixed by accident.

Scopes and rolling

Payouts, refunds and card reveal require separately scoped keys. Roll a key whenever someone leaves or a key might have been logged; rolling is designed to be routine maintenance, not an incident.