Every request carries a POS Gateway key in two fields: CardPointeUsername is the key id (pgk_…) and
CardPointePassword its secret (pgs_…).
- A key is made for one terminal at one location. It works only with that terminal and that location’s MIDs, so a
key copied to another register is refused.
- A key with no terminal is for back-office calls: voids, refunds, captures and look-ups.
- The secret is shown once, when the key is created. Mojo Payments keeps only a fingerprint of it, so a lost
secret can’t be recovered: create a new key and revoke the old one.
- Revoking a key stops it at once (HTTP
401).
Keys are created and revoked in the portal under Settings → POS Gateway → Register keys, where each new key can
also be downloaded as a ready-made CLI setup for that register.
Treat the secret like a password: never put it in a URL, a log, or a screenshot.