Skip to main content
Your system signs in with an API key: a key id (mk_…) and a secret (ms_…). It exchanges them for an access token, and sends that token with every request.

Create an API key

  1. In the portal, open Settings → API keys. Only Owners and Admins see it.
  2. Give the key a name that says which system uses it, such as QuickBooks sync.
  3. Under What it can do, tick only what that system needs (permissions).
  4. Select Create key, then copy the key id and the secret. The secret is shown once. Mojo Payments keeps only a fingerprint of it, so a lost secret can’t be recovered: create a new key and revoke the old one.
An API key belongs to your organization, not to the person who made it: it keeps working when they leave.
Treat the secret like a password. Keep it in your system’s secret store, never in code, a URL, an email or a log.

Get an access token

Send the key to POST /oauth/token (the OAuth 2.0 client credentials grant):
The body can also be JSON, or the key id and secret can go in an HTTP Basic Authorization header, as OAuth client libraries send them.
  • The token lasts 10 minutes (expires_in, in seconds). Keep using it until it expires, then get a new one; don’t get a new token for every request.
  • scope lists what the key can do. organization_id is your organization’s id.

Use the token

Permissions

A key can do only what was ticked when it was made. A request for anything else gets 403. You can give a key only what you can do yourself across the whole organization. Merchant permissions appear for merchants and reseller permissions for reseller partners.

Revoke a key

In Settings → API keys, select Revoke. New tokens are refused at once, and tokens already issued stop working within a minute (401 with the title API key revoked). Revoked keys stay in the list, marked with the date.

Token errors