Getting started

API keys

API keys authenticate your servers. Each key belongs to one organization and carries only the scopes you grant it.

Test and live keys#

The prefix tells you which network a key acts on. Keys from one environment never work in the other.

PrefixNetworkUse
mk_test_Solana devnet / localDevelopment and CI. Payouts use test MUNY.
mk_live_Solana mainnetProduction payouts with real MUNY.

Creating a key#

  1. Open Developers → API keys

    Owners, Admins and Developers can create keys.

  2. Name it and choose scopes

    Give each integration its own key so you can revoke one without affecting the others.

  3. Copy the secret

    The full key is shown exactly once. Store it in your secrets manager.

Shown once, stored hashed

Muny stores only a SHA-256 hash of each key, plus a short non-secret prefix (like mk_live_8fA2) so you can recognise it in the dashboard. Nobody at Muny can recover a lost key — create a new one instead.

Scopes#

ScopeAllows
create_payoutCreate payouts and payout batches.
view_payoutsRead payouts, batches and transactions.
manage_recipientsCreate, update and archive recipients.
manage_webhooksManage webhook endpoints and deliveries.
view_analyticsRead payout analytics and usage.
manage_walletsList wallets and read balances.

Team, organization and API-key management are never available to API keys — those always require a signed-in member. Approving a payout that needs approval also requires a member.

Using a key#

bash
curl https://api.muny.io/v1/wallets \
  -H "Authorization: Bearer mk_test_..."

Rotation#

  • Create the new key and deploy it alongside the old one.
  • Watch last used on the old key in the dashboard until traffic stops.
  • Revoke the old key. Revocation takes effect immediately.

Every key creation and revocation is recorded in the organization's activity log with the member who did it.