Getting Started

This page will help you get started with Capera. You'll be up and running in a jiffy!

Authentication

Secure your API requests with proper authentication.

Overview

The Capera B2B API uses API keys to authenticate requests. You can view and manage your API keys in your Capera Dashboard.

Authentication is performed via HTTP Bearer tokens. Include your API key in the Authorization header of your requests:

Authorization: Bearer sk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

API Keys

Types of Keys

We provide two types of API keys:

EnvironmentKey PrefixDescription
Livesk_live_Use for production transactions
Testsk_test_Use for development and testing

Key Security

Important: Your API keys carry many privileges. Keep them secure!

Do:

  • Store keys in environment variables
  • Use different keys for different environments
  • Rotate keys regularly
  • Use server-side code only

Don't:

  • Embed keys directly in code
  • Share keys in version control
  • Use keys in client-side code
  • Share keys with unauthorized parties

Making Authenticated Requests

Required Header

All authenticated endpoints require the Authorization header:

curl https://api.withcapera.com/b2b/v1/transfers/initiate \
  -H "Authorization: Bearer sk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"

Environment Variables

Store your API key securely:

export CAPERA_API_KEY="sk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"

Session Management

The API uses session-based authentication with API keys. Each authenticated request creates or validates a session containing:

Session Data

FieldDescription
business_idUnique identifier for your business
business_branch_idBranch identifier for multi-branch operations

Sessions are automatically managed by the API and linked to your API key.

Endpoints Requiring Authentication

The following endpoints require authentication:

EndpointMethodDescription
/v1/bank/resolveGETResolve account details
/v1/transfers/initiatePOSTInitiate NGN transfer
/v1/transfers/{reference}GETGet transfer status

Public Endpoints

These endpoints don't require authentication:

EndpointMethodDescription
/v1/banksGETList available banks

Error Responses

Invalid Token

{
  "message": "Invalid token"
}

Status Code: 401 Unauthorized

Resolution: Check that your API key is correct and properly formatted.

Expired Token

{
  "message": "Expired token"
}

Status Code: 401 Unauthorized

Resolution: Generate a new API key from your dashboard.

Missing Authorization

{
  "message": "Authorization header required"
}

Status Code: 401 Unauthorized

Resolution: Include the Authorization header in your request.

Best Practices

1. Secure Storage

  • Store API keys in environment variables
  • Never commit keys to version control
  • Use different keys for different environments

2. Key Rotation

Rotate your API keys regularly:

  1. Generate a new key in your dashboard
  2. Update your application configuration
  3. Test with the new key
  4. Revoke the old key

3. Monitoring

Monitor API key usage in your dashboard to detect unusual activity or unauthorized access.

Rate Limiting

API keys are subject to rate limiting:

PlanRequests/SecondRequests/Day
Starter1010,000
Business50100,000
EnterpriseCustomCustom

Rate limit headers are included in responses:

X-RateLimit-Limit: 50
X-RateLimit-Remaining: 49
X-RateLimit-Reset: 1640995200

Troubleshooting

Common Issues

  1. "Invalid token" error

    • Verify API key is correct
    • Check for extra spaces or characters
    • Ensure using correct environment (live vs test)
  2. "Expired token" error

    • Generate a new API key
    • Update your application configuration
  3. "Session not found" error

    • Ensure Authorization header is included
    • Check that the session hasn't expired

Getting Help

If you continue to experience authentication issues:

  1. Check the API Status Page
  2. Review your API key settings in the dashboard
  3. Contact support at [email protected] with:
    • Your merchant ID
    • Request ID from error response
    • Description of the issue

What’s Next

Did this page help you?