Basics
Authentication
Authenticate every request with an API key in the x-api-key header. Create, rotate and revoke keys on the API Keys page.
Keep your keys secret
A key moves money from your wallet. Keep it on your server — never in a browser, mobile app or Git repository. If a key leaks, rotate or revoke it immediately.
Base URL
https://czettapayapi-prod.czettapay.com/api/v1
Every path in this reference is relative to this URL, e.g. https://czettapayapi-prod.czettapay.com/api/v1/airtime.
Environments
Your key decides the environment. There is no separate URL for testing.
Sandbox
Keys starting with sk_test_
Purchases are simulated against your TEST wallet; nothing reaches a network. The number 08000000000 always simulates a provider failure.
Live
Keys starting with sk_live_
Real vends, charged to your LIVE wallet. Live keys can only be created after KYC verification.
Key controls
- Up to 5 active keys per environment — give each server or app its own key.
- Rotate issues a new key; the old one keeps working for the grace period you choose (immediately, 1 hour, 24 hours or 7 days).
- Revoke stops a key immediately (
401). Expired keys also return401. - IP allow-list: restrict a key to your server IPs. Calls from any other IP return
403.
Authenticated request
curl -X GET https://czettapayapi-prod.czettapay.com/api/v1/wallet/balance \
-H "x-api-key: sk_test_..."