Skip to main content
POST
Mint a new pk_live_* publishable key for your embeddable Payment/Donation widgets. This endpoint takes no parameters — the key is rotated for the merchant in your session.
The old pk_live_* value stops working the moment this call returns. Rotate only when you’re ready to update every embedded widget right away.

Authorization

This endpoint is dashboard-only: a dashboard JWT with role merchant_admin, merchant_member (with team permission widgets:manage) or super_admin. API-key callers are rejected with 401 {"error":"Invalid or expired token"} — the JWT guard runs first and an API key is not a session token, so the call never reaches the role check. The key is not revoked; it simply cannot authenticate a dashboard-only route. Rate limit: 3/min.
A super_admin passes the role guard, but platform accounts carry no merchant context, so the handler short-circuits with 400 {"ok":false,"error":{"code":"NO_MERCHANT_CONTEXT","message":"No merchant context"}}. In practice this endpoint is for merchant accounts.
No MFA is needed — the publishable key grants no read or withdraw capability. It can only create widget payments, gated by each widget’s origin allowlist and rate limits.

Response fields

string
The new pk_live_* value (see Get publishable key — it is not secret).

See also