Émettre une nouvelle paire de clés
curl --request POST \
--url https://guichet.apidjonanko.tech/v1/merchants/me/credentials \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--header 'x-api-secret: <api-key>' \
--data '
{
"label": "backend production 2026-10",
"environment": "live"
}
'const options = {
method: 'POST',
headers: {
'x-api-key': '<api-key>',
'x-api-secret': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({label: 'backend production 2026-10', environment: 'live'})
};
fetch('https://guichet.apidjonanko.tech/v1/merchants/me/credentials', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://guichet.apidjonanko.tech/v1/merchants/me/credentials"
payload = {
"label": "backend production 2026-10",
"environment": "live"
}
headers = {
"x-api-key": "<api-key>",
"x-api-secret": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://guichet.apidjonanko.tech/v1/merchants/me/credentials",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'label' => 'backend production 2026-10',
'environment' => 'live'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>",
"x-api-secret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"credential": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"apiKey": "<string>",
"apiSecret": "<string>",
"environment": "<string>",
"label": "<string>",
"createdAt": "2023-11-07T05:31:56Z"
},
"notice": "<string>"
}{
"success": false,
"error": {
"code": "INVALID_CREDENTIALS",
"message": "Identifiants API invalides."
},
"requestId": "9f1c2b7e-4a5d-4c8f-b0a1-e2d3c4b5a697",
"timestamp": "2026-10-01T10:12:04.000Z"
}Compte
Émettre une nouvelle paire de clés
Pour une rotation sans coupure : émettez la nouvelle paire, déployez-la, puis révoquez l’ancienne. Plusieurs paires peuvent être actives simultanément.
Le secret n’est affiché qu’une seule fois.
POST
/
merchants
/
me
/
credentials
Émettre une nouvelle paire de clés
curl --request POST \
--url https://guichet.apidjonanko.tech/v1/merchants/me/credentials \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--header 'x-api-secret: <api-key>' \
--data '
{
"label": "backend production 2026-10",
"environment": "live"
}
'const options = {
method: 'POST',
headers: {
'x-api-key': '<api-key>',
'x-api-secret': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({label: 'backend production 2026-10', environment: 'live'})
};
fetch('https://guichet.apidjonanko.tech/v1/merchants/me/credentials', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://guichet.apidjonanko.tech/v1/merchants/me/credentials"
payload = {
"label": "backend production 2026-10",
"environment": "live"
}
headers = {
"x-api-key": "<api-key>",
"x-api-secret": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://guichet.apidjonanko.tech/v1/merchants/me/credentials",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'label' => 'backend production 2026-10',
'environment' => 'live'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>",
"x-api-secret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"credential": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"apiKey": "<string>",
"apiSecret": "<string>",
"environment": "<string>",
"label": "<string>",
"createdAt": "2023-11-07T05:31:56Z"
},
"notice": "<string>"
}{
"success": false,
"error": {
"code": "INVALID_CREDENTIALS",
"message": "Identifiants API invalides."
},
"requestId": "9f1c2b7e-4a5d-4c8f-b0a1-e2d3c4b5a697",
"timestamp": "2026-10-01T10:12:04.000Z"
}Authorizations
Votre clé publique, préfixée gk_live_ (ou gk_test_).
Votre secret, préfixé gs_live_ (ou gs_test_). Affiché une seule fois, à l'émission de la clé. Il ne doit jamais quitter vos serveurs.
Body
application/json
Libellé pour distinguer cette paire des autres.
Maximum string length:
80Example:
"backend production 2026-10"
Une clé test authentifie et permet la consultation, mais est refusée sur les endpoints qui déplacent de l'argent réel.
Available options:
live, test 