Authentication

The Vexutopia API uses API keys to authenticate requests. Include your key in the X-API-Key header on every request.

Base URL

cURL
https://vexutopia.com/api/v1

API Key Types

Vexutopia provides two types of API keys for different environments:

TESTTest Keys

Use test keys during development. They open a sandbox checkout where you simulate success or failure — no real payment is taken, and webhooks fire with livemode: false. See Testing webhooks.

vex_test_...
LIVELive Keys

Use live keys in production. Real transactions are processed.

vex_live_...

Getting Your API Keys

  1. 1Sign in to your Vexutopia dashboard
  2. 2Navigate to API Keys in the sidebar
  3. 3Click "Create API Key" and choose the key type (Test or Live)
  4. 4Copy your key immediately — it won't be shown again

Using Your API Key

Pass your API key in the X-API-Key header with every request:

cURL
curl https://vexutopia.com/api/v1/payments \
  -H "X-API-Key: vex_test_your_api_key" \
  -H "Content-Type: application/json"
JavaScript
const response = await fetch('https://vexutopia.com/api/v1/payments', {
  headers: {
    'X-API-Key': 'vex_test_your_api_key',
    'Content-Type': 'application/json'
  }
});

const data = await response.json();

Required Headers

ParameterTypeDescription
X-API-KeyrequiredstringYour API key. Format: vex_test_xxx (test) or vex_live_xxx (live)
Content-TyperequiredstringMust be application/json for requests with a body
User-AgentstringStrongly recommended for server-to-server integrations. Send a descriptive value identifying your app (e.g. "YourCompany-Integration/1.0"). See the note below.

Server-to-server: set a descriptive User-Agent

Our edge bot-protection can challenge or block requests whose User-Agent looks automated — many HTTP libraries send a generic default (or none), which may be flagged. If you see Cloudflare challenges or an Error 1010 on your API calls, it is caused by the User-Agent, not your IP address. Set an explicit, app-specific User-Agent header and the issue clears:

User-Agent: YourCompany-Integration/1.0

Authentication Errors

If authentication fails, you'll receive one of these errors:

401Missing API Key
JSON
{
  "error": "Missing X-API-Key header",
  "code": "MISSING_API_KEY"
}
401Invalid API Key
JSON
{
  "error": "Invalid API key",
  "code": "INVALID_API_KEY"
}
401Revoked API Key
JSON
{
  "error": "API key has been revoked",
  "code": "REVOKED_API_KEY"
}

Security Best Practices

Keep keys secret

Never expose API keys in client-side code, public repositories, or share them in plain text.

Use environment variables

Store API keys in environment variables, not in your codebase.

cURL
# .env
VEXUTOPIA_API_KEY=vex_live_your_api_key

Rotate keys regularly

Create new keys periodically and revoke old ones to maintain security.

Next Steps

Now that you're authenticated, start integrating with the API: