Getting Started
This page will help you get started with Capera. You'll be up and running in a jiffy!
Authentication
Secure your API requests with proper authentication.
Overview
The Capera B2B API uses API keys to authenticate requests. You can view and manage your API keys in your Capera Dashboard.
Authentication is performed via HTTP Bearer tokens. Include your API key in the Authorization header of your requests:
Authorization: Bearer sk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxAPI Keys
Types of Keys
We provide two types of API keys:
| Environment | Key Prefix | Description |
|---|---|---|
| Live | sk_live_ | Use for production transactions |
| Test | sk_test_ | Use for development and testing |
Key Security
Important: Your API keys carry many privileges. Keep them secure!
Do:
- Store keys in environment variables
- Use different keys for different environments
- Rotate keys regularly
- Use server-side code only
Don't:
- Embed keys directly in code
- Share keys in version control
- Use keys in client-side code
- Share keys with unauthorized parties
Making Authenticated Requests
Required Header
All authenticated endpoints require the Authorization header:
curl https://api.withcapera.com/b2b/v1/transfers/initiate \
-H "Authorization: Bearer sk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"Environment Variables
Store your API key securely:
export CAPERA_API_KEY="sk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"Session Management
The API uses session-based authentication with API keys. Each authenticated request creates or validates a session containing:
Session Data
| Field | Description |
|---|---|
business_id | Unique identifier for your business |
business_branch_id | Branch identifier for multi-branch operations |
Sessions are automatically managed by the API and linked to your API key.
Endpoints Requiring Authentication
The following endpoints require authentication:
| Endpoint | Method | Description |
|---|---|---|
/v1/bank/resolve | GET | Resolve account details |
/v1/transfers/initiate | POST | Initiate NGN transfer |
/v1/transfers/{reference} | GET | Get transfer status |
Public Endpoints
These endpoints don't require authentication:
| Endpoint | Method | Description |
|---|---|---|
/v1/banks | GET | List available banks |
Error Responses
Invalid Token
{
"message": "Invalid token"
}Status Code: 401 Unauthorized
Resolution: Check that your API key is correct and properly formatted.
Expired Token
{
"message": "Expired token"
}Status Code: 401 Unauthorized
Resolution: Generate a new API key from your dashboard.
Missing Authorization
{
"message": "Authorization header required"
}Status Code: 401 Unauthorized
Resolution: Include the Authorization header in your request.
Best Practices
1. Secure Storage
- Store API keys in environment variables
- Never commit keys to version control
- Use different keys for different environments
2. Key Rotation
Rotate your API keys regularly:
- Generate a new key in your dashboard
- Update your application configuration
- Test with the new key
- Revoke the old key
3. Monitoring
Monitor API key usage in your dashboard to detect unusual activity or unauthorized access.
Rate Limiting
API keys are subject to rate limiting:
| Plan | Requests/Second | Requests/Day |
|---|---|---|
| Starter | 10 | 10,000 |
| Business | 50 | 100,000 |
| Enterprise | Custom | Custom |
Rate limit headers are included in responses:
X-RateLimit-Limit: 50
X-RateLimit-Remaining: 49
X-RateLimit-Reset: 1640995200Troubleshooting
Common Issues
-
"Invalid token" error
- Verify API key is correct
- Check for extra spaces or characters
- Ensure using correct environment (live vs test)
-
"Expired token" error
- Generate a new API key
- Update your application configuration
-
"Session not found" error
- Ensure Authorization header is included
- Check that the session hasn't expired
Getting Help
If you continue to experience authentication issues:
- Check the API Status Page
- Review your API key settings in the dashboard
- Contact support at
[email protected]with:- Your merchant ID
- Request ID from error response
- Description of the issue
Updated 4 months ago