PayOrbit
Sign in
Auth

Authentication

Obtain a Bearer token with your client credentials before calling Recharge or Bill Payment APIs.

Where to find your keys?

Open the developer panel to copy Client ID, API Secret, and manage environment access.

Call this before any Recharge or Bill Payment API. Exchange your keys for a Bearer token, then send that token on every request.

Credentials

Copy these from Developer panel → API Keys:

  • Client ID — public identifier used to request an access token
  • API Secret — private key; never expose it in client-side code
  • Base URL — UAT or Production host for API calls

Prerequisites

  1. Sign up on the portal
  2. Complete KYC from the email link
  3. Wait until an admin approves your application
  4. Copy your UAT credentials from API Keys

Get a Bearer token

POST /api/v1/auth/client-credentials
Content-Type: application/json

{
  "client_id": "uat_client_portal_user",
  "api_secret": "uat_secret_••••••••",
  "environment": "uat",
  "device_name": "uat-live-test"
}

device_name is optional. Field name is api_secret (not client_secret).

Example success response:

{
  "token": "1|xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
  "token_type": "Bearer",
  "environment": "uat",
  "base_url": "https://uat-api.vizodigital.com",
  "user": {
    "id": 4,
    "name": "Portal User",
    "email": "user@portal.test"
  }
}

Send the token on every business API call:

Authorization: Bearer {token}

Verify the token

GET /api/v1/auth/me
Authorization: Bearer {token}
Accept: application/json

Example response:

{
  "id": 4,
  "name": "Portal User",
  "email": "user@portal.test",
  "roles": ["developer"],
  "permissions": ["api-keys.manage"]
}

Environment rules

  • UAT credentials only work against the UAT base URL
  • Production credentials appear only after an admin unlocks live access
  • Do not mix UAT secrets with the Production host (or the reverse)