Two auth models:
- API key — for creating checkout sessions and all off-ramp endpoints
- None — for session status, payment link info, and payment link session creation
API key
All keys use the ms_live_ prefix.
Never put your API key in frontend JS, mobile apps, or public repos. Backend only.
Example
Generate a key
- Open merchant.minisend.xyz/dashboard.
- Go to API Keys → New Key.
- Copy the full value immediately; it’s shown once. Minisend stores only a hash.
401 = invalid/missing key. 403 = key valid but merchant account inactive.
Key scopes
Keys carry scopes that gate which endpoint families they can call:
| Scope | Grants | How to get it |
|---|
checkout | Checkout session creation | On every key by default |
offramp | All /api/offramp/* endpoints | Contact Minisend to enable off-ramp on your account |
Calling an off-ramp endpoint without the offramp scope returns 403.
Rate limits
60 requests / minute / IP. Response includes X-RateLimit-Remaining. Exceeding it returns 429. Contact support for higher limits.
Public endpoints
No Authorization header needed:
| Endpoint | Use |
|---|
GET /api/merchant/checkout/{session_id} | Session status |
GET /api/merchant/pay/info?slug={slug} | Merchant display info + live rate |
POST /api/merchant/pay | Create session from payment link |
Safe to call from a browser or mobile app.