mk_…) and a secret (ms_…). It exchanges them for an access
token, and sends that token with every request.
Create an API key
- In the portal, open Settings → API keys. Only Owners and Admins see it.
- Give the key a name that says which system uses it, such as
QuickBooks sync. - Under What it can do, tick only what that system needs (permissions).
- Select Create key, then copy the key id and the secret. The secret is shown once. Mojo Payments keeps only a fingerprint of it, so a lost secret can’t be recovered: create a new key and revoke the old one.
Get an access token
Send the key toPOST /oauth/token (the OAuth 2.0 client credentials grant):
Authorization header, as OAuth client
libraries send them.
- The token lasts 10 minutes (
expires_in, in seconds). Keep using it until it expires, then get a new one; don’t get a new token for every request. scopelists what the key can do.organization_idis your organization’s id.
Use the token
Permissions
A key can do only what was ticked when it was made. A request for anything else gets403.
You can give a key only what you can do yourself across the whole organization. Merchant permissions appear for
merchants and reseller permissions for reseller partners.
Revoke a key
In Settings → API keys, select Revoke. New tokens are refused at once, and tokens already issued stop working within a minute (401 with the title API key revoked). Revoked keys stay in the list, marked with the date.