Full platform access · every action here is logged and cannot be erasedChanges are audit logged

API keys

Credentials for the mobile app, aggregators and partners.

Active
3
Revoked
1
Live keys
2
Unused 7+ days
0
NameKeyScopesCreatedLast usedStatus
Mobile app (production)ev_live_8f2c…
sessions:writestations:readpayments:write
Mar 20262 min agoactive
PayHere aggregator callbackev_live_31ab…
webhooks:write
Mar 202611 min agoactive
Partner sandbox - ChargeNETev_test_77de…
stations:read
Jun 2026Yesterdayactive
Legacy pilot keyev_live_0a19…
stations:read
Feb 20263 weeks agorevoked-

Rotation policy

Rotating is not revoking. A rotation issues a new key and keeps the old one valid for a grace period so the client can be updated without downtime. Revoking kills it instantly - use that when a key has leaked.

The mobile app key is embedded in a shipped binary. Treat it as public: anyone with the app can extract it. It is scoped to what a customer can already do, and every privileged action still requires the customer's own authenticated session on top.

Rotation grace
24 hours
Max key age
365 days

Housekeeping

“Partner sandbox - ChargeNET” last used yesterday

Test keys with real traffic are worth a second look - either the partner is testing against production data, or this key is misnamed. Both are worth knowing.

“Legacy pilot key” revoked, still listed

Revoked keys stay visible on purpose. Deleting the row would erase the evidence of what it could do and when it was last used - exactly what you need after an incident.