Keys belong on your server.

Every merchant API request uses your X-API-Key header. Your customers never need this key.

Store credentials safely

Use backend environment variables or your secret manager. Do not put credentials in checkout JavaScript, query strings, screenshots or application logs.

Python · server-side
import os
import requests

response = requests.post(
    "https://api.dedyx.com/api/v1/payments",
    headers={
        "X-API-Key": os.environ["DEDYX_API_KEY"],
        "Idempotency-Key": "order-1024",
    },
    json={
        "amount": "49.00",
        "merchant_wallet": "TRzsBvFUhcvsy45ebmaKZ9EXw7zUorVkUm",
        "description": "Order #1024",
    },
    timeout=15,
)
response.raise_for_status()
payment = response.json()

Configure the required webhook before this request. HTTP errors should be handled explicitly. Retry a uncertain creation with its original idempotency key.

Rotate an API key

POST/api/v1/merchant/rotate-key

Rate limit: 5 requests / 60 seconds (API key rotation · per rotation secret). Shared counters and additional IP limits.

cURL
curl -X POST https://api.dedyx.com/api/v1/merchant/rotate-key \
  -H 'secret-key: YOUR_ROTATION_SECRET'

The response returns new_api_key. The previous API key stops working. The rotation secret, API key and webhook signing key are independent credentials. If the rotation secret is lost or compromised, contact support without sending credentials. After ownership verification, support can replace both API credentials while preserving your account and history. Read the rotation and recovery procedure.

Creation quota and rate limits

GET/api/v1/merchant/limits

Rate limit: 120 requests / 60 seconds (shared reads · per merchant). Shared counters and additional IP limits.

200 OK · selected fields
{"merchant_id":"mer_example","access_type":"beta","total_limit":100,"requests_used":3,"requests_left":97,"daily_limit":10,"daily_used":3,"daily_left":7,"creation_allowed":true,"creation_block_reason":null}

Standard beta is 30 days from explicit activation after confirmed credential receipt, 100 successful new payments in total and at most 10 per UTC day. Individual conditions may differ. Limits returns access_type, status, creation_enabled, creation_allowed, creation_block_reason, beta_duration_days, beta_started_at, beta_expires_at, total_limit, requests_used, requests_left, lifetime_requests_used, daily_limit, daily_used, daily_left, daily_reset_at, server_time and last_api_request_at. Dates are UTC; unactivated beta dates are null. Legacy accounts retain their previous total without beta expiry or a daily cap unless explicitly changed. For beta the used/remaining total applies to its package; lifetime usage stays preserved. Earlier payments on the same UTC day remain in daily history when moving to beta. Replays, reads and webhook deliveries do not consume creation quota. There is no automatic monthly reset. Extending time does not reset usage or add quota. Exhaustion, expiry and a creation pause block only new payments: existing checks, authenticated reads, cancellation, key rotation and webhooks continue while the account is active. Daily quota resets at 00:00 UTC; total quota and expiry require support. Limits never returns credentials.

Checkout links are private links

The final segment of payment_url is a public token for that payment. Share the link with the intended customer. It exposes the amount, recipient, description, status and expiry; it cannot create orders, change settings or access your account.

Do not put personal information or secrets in description. Forwarding a link does not identify the payer; canceling a payment does not revoke visibility or reverse funds. Payment link privacy.

Next: Payments