Getting started
API keys
API keys authenticate your servers. Each key belongs to one organization and carries only the scopes you grant it.
Test and live keys#
The prefix tells you which network a key acts on. Keys from one environment never work in the other.
| Prefix | Network | Use |
|---|---|---|
mk_test_ | Solana devnet / local | Development and CI. Payouts use test MUNY. |
mk_live_ | Solana mainnet | Production payouts with real MUNY. |
Creating a key#
Open Developers → API keys
Owners, Admins and Developers can create keys.
Name it and choose scopes
Give each integration its own key so you can revoke one without affecting the others.
Copy the secret
The full key is shown exactly once. Store it in your secrets manager.
Shown once, stored hashed
Muny stores only a SHA-256 hash of each key, plus a short non-secret prefix (likemk_live_8fA2) so you can recognise it in the dashboard. Nobody at Muny can recover a lost key — create a new one instead.Scopes#
| Scope | Allows |
|---|---|
create_payout | Create payouts and payout batches. |
view_payouts | Read payouts, batches and transactions. |
manage_recipients | Create, update and archive recipients. |
manage_webhooks | Manage webhook endpoints and deliveries. |
view_analytics | Read payout analytics and usage. |
manage_wallets | List wallets and read balances. |
Team, organization and API-key management are never available to API keys — those always require a signed-in member. Approving a payout that needs approval also requires a member.
Using a key#
curl https://api.muny.io/v1/wallets \
-H "Authorization: Bearer mk_test_..."Rotation#
- Create the new key and deploy it alongside the old one.
- Watch
last usedon the old key in the dashboard until traffic stops. - Revoke the old key. Revocation takes effect immediately.
Every key creation and revocation is recorded in the organization's activity log with the member who did it.