curl https://api.liddie.io/api/v1/api-keys/publishable \
-H "Authorization: Bearer <dashboard JWT>"
// Dashboard-session endpoint: send the JWT as a Bearer token.
const response = await fetch('https://api.liddie.io/api/v1/api-keys/publishable', {
headers: { 'Authorization': 'Bearer <dashboard JWT>' },
});
const { publishableKey } = await response.json();
{"publishableKey":"pk_live_..."}
API keys
Get publishable key
Read your Liddie publishable key (pk_live_*) — the public-by-design credential that powers embeddable Payment and Donation widgets.
GET
/
api
/
v1
/
api-keys
/
publishable
curl https://api.liddie.io/api/v1/api-keys/publishable \
-H "Authorization: Bearer <dashboard JWT>"
// Dashboard-session endpoint: send the JWT as a Bearer token.
const response = await fetch('https://api.liddie.io/api/v1/api-keys/publishable', {
headers: { 'Authorization': 'Bearer <dashboard JWT>' },
});
const { publishableKey } = await response.json();
{"publishableKey":"pk_live_..."}
Read your
pk_live_* publishable key — the one that powers embeddable Payment/Donation widgets.
This endpoint takes no parameters — the merchant is inferred from your dashboard session.
This key is safe to embed in client-side code. It can only create widget payments — gated by each widget’s origin allowlist and rate limits — and reads nothing.
Authorization
This endpoint is dashboard-only: a dashboard JWT with rolemerchant_admin, merchant_member (with team permission widgets:view) or super_admin. API-key callers are rejected with 401 {"error":"Invalid or expired token"} — the JWT guard runs first and an API key is not a session token, so the call never reaches the role check. The key is not revoked; it simply cannot authenticate a dashboard-only route.
A
super_admin passes the role guard, but platform accounts carry no merchant context, so the handler
short-circuits with 400 {"ok":false,"error":{"code":"NO_MERCHANT_CONTEXT","message":"No merchant context"}}.
In practice this endpoint is for merchant accounts.curl https://api.liddie.io/api/v1/api-keys/publishable \
-H "Authorization: Bearer <dashboard JWT>"
// Dashboard-session endpoint: send the JWT as a Bearer token.
const response = await fetch('https://api.liddie.io/api/v1/api-keys/publishable', {
headers: { 'Authorization': 'Bearer <dashboard JWT>' },
});
const { publishableKey } = await response.json();
{"publishableKey":"pk_live_..."}
Response fields
string
The full
pk_live_* value, repeatable — it is not secret.See also
- Rotate publishable key: invalidate the current
pk_live_*value and mint a new one. - Create an API key: the secret (
lid_live_*) counterpart for server-side calls. - Authentication: how publishable, secret, and dashboard credentials differ.