What to ask for
API credentials
An API key, a client id and a client password, for the environment you are starting in.
Dashboard access
A login for the people who will watch payments, register webhook endpoints and answer compliance requests.
The three credentials, and what each is for
The client id and password are exchanged for a token. The API key is not — it goes on every request regardless.
Your webhook endpoints
Endpoints are self-serve. You register them in the Developers section of the dashboard, and you can register more than one — each event type goes to exactly one URL, so how you split them across endpoints is your choice. Webhooks overview has the rules that govern them. There are no/v1 endpoints for any of this. The API cannot read or change an endpoint.
Register at least one before you start, because several things in the flow only ever announce themselves by webhook. An integration that waits until the end to think about webhooks will get to a payment stuck in an in-between state with nothing telling it why.
What Kira will ask you for
To provision the above, expect to supply:- Who needs dashboard access, and which role each of them starts with.
- Which environment you are starting in. Everyone starts in sandbox.
When you have it
Check the credentials work before writing anything else — that is one call, and it is the next page.Authentication
Exchange your credentials for a token and make an authenticated call.