Requesting access
1
Submit your request
Email support@getsafepay.com with your business details, use cases, and projected volume.
2
Safepay review
Safepay provisions your aggregator and performs due diligence.
3
Receive credentials
You receive:
{{aggregator_id}}(include in every API path)- At least one
{{secret_key}}scoped to an environment - Dashboard access, if requested
Do not embed your secret key in mobile or web apps. Keep it in a server-side secret manager and rotate it immediately if compromised.
Authentication
All Raast API endpoints use theapiKey security scheme defined in the OpenAPI spec. Send X-SFPY-AGGREGATOR-SECRET-KEY: {{secret_key}} with every request. Safepay rejects requests that rely on the deprecated Authorization: Bearer header.
Credential hygiene
- Maintain separate secrets per environment and workload (for example, one for payouts, another for pay-ins).
- Rotate keys proactively or whenever staff changes. Safepay can issue new keys through the Create access key endpoint.
- Use the Rotate access key endpoint to refresh keys without downtime.
- Monitor access with List access keys and disable unused keys with Delete access key.