Olympus PayDevelopers

Authentication

Every request is authenticated with an API key sent as a bearer token.

Authorization: Bearer olp_live_xxxxxxxxxxxxxxxxxxxxxxxx

There is no other credential to manage: no client secret, no OAuth flow, no session.

Sandbox and live keys#

Sandbox keyLive key
Prefixolp_test_olp_live_
Real moneyNeverYes
Business verification neededNoYes
Payments and payment linksConfirmed on a sandbox pageProcessed by the payment provider
PayoutsRejected (400)Allowed
DataSeparate: sandbox objects never appear with a live key, and the reverse

The key itself decides the environment. The base URL is the same. Use a sandbox key everywhere except production.

Creating a key#

Developers, then API keys, then Create key in the dashboard. Only the business owner and admins can create keys. The full key is shown once. Olympus Pay stores only a hash, so a lost key cannot be recovered, only replaced.

Scopes#

Give each key only what its integration needs. A request outside a key's scopes returns 403 with code permission_denied.

ScopeAllows
payment_links:writePOST /payment-links
qr_codes:writePOST /qr-codes
payments:readGET /payments, GET /payments/{id}
payments:cancelPOST /payments/{id}/cancel
refunds:create_fullPOST /payments/{id}/refund without an amount
refunds:create_partialPOST /payments/{id}/refund with an amount
payouts:createPOST /payouts
payouts:readGET /payouts
payouts:cancelPOST /payouts/{id}/cancel
settlements:readGET /settlements
reports:exportCSV export of settlements (in addition to settlements:read)
recipients:write, recipients:read, recipients:verify, recipients:disableSplit recipients
splits:assignAttaching a split recipient to a link or QR code
webhooks:manage, webhooks:read_logs, webhooks:retryWebhook endpoints and deliveries
account:read, kyc:read, kyc:writeBusiness profile and verification

A key created with no scopes has full access. Prefer explicit scopes.

Hardening a key#

On the key's page you can also set:

  • IP allowlist. Requests from any other address get 401.
  • Expiry date. After it the key stops working.
  • Redirect domains. A returnUrl on a payment link or QR code must be on one of these domains.

Rotation and revocation#

  • Rotate replaces the key's secret in place: the key keeps its identity, scopes and allowlist, and the old secret stops working immediately. The new secret is shown once. Have the new value ready to deploy before you rotate. Rotate on a schedule and whenever someone with access leaves.
  • Revoke disables a key immediately and cannot be undone.
  • The key's page shows recent requests with their status codes and the IP address each came from. Check it after any suspected leak.

If a key is exposed (committed to a repository, pasted in a chat, logged), revoke it first and investigate afterwards.

Authentication errors#

StatusCodeMeaning
401authentication_failedMissing, malformed, unknown, revoked or expired key, or a request from an address outside the key's allowlist
403permission_deniedThe key is valid but lacks the scope, or the business is not yet verified for a live operation
429rate_limitedToo many requests: see Rate limits

Every error body carries a request_id: see Errors.