Authentication
The Vexutopia API uses API keys to authenticate requests. Include your key in the X-API-Key header on every request.
Base URL
https://vexutopia.com/api/v1API Key Types
Vexutopia provides two types of API keys for different environments:
Use test keys during development. They open a sandbox checkout where you simulate success or failure — no real payment is taken, and webhooks fire with livemode: false. See Testing webhooks.
vex_test_...Use live keys in production. Real transactions are processed.
vex_live_...Getting Your API Keys
- 1Sign in to your Vexutopia dashboard
- 2Navigate to API Keys in the sidebar
- 3Click "Create API Key" and choose the key type (Test or Live)
- 4Copy your key immediately — it won't be shown again
Using Your API Key
Pass your API key in the X-API-Key header with every request:
curl https://vexutopia.com/api/v1/payments \
-H "X-API-Key: vex_test_your_api_key" \
-H "Content-Type: application/json"const response = await fetch('https://vexutopia.com/api/v1/payments', {
headers: {
'X-API-Key': 'vex_test_your_api_key',
'Content-Type': 'application/json'
}
});
const data = await response.json();Required Headers
| Parameter | Type | Description |
|---|---|---|
X-API-Keyrequired | string | Your API key. Format: vex_test_xxx (test) or vex_live_xxx (live) |
Content-Typerequired | string | Must be application/json for requests with a body |
User-Agent | string | Strongly recommended for server-to-server integrations. Send a descriptive value identifying your app (e.g. "YourCompany-Integration/1.0"). See the note below. |
Server-to-server: set a descriptive User-Agent
Our edge bot-protection can challenge or block requests whose User-Agent looks automated — many HTTP libraries send a generic default (or none), which may be flagged. If you see Cloudflare challenges or an Error 1010 on your API calls, it is caused by the User-Agent, not your IP address. Set an explicit, app-specific User-Agent header and the issue clears:
User-Agent: YourCompany-Integration/1.0
Authentication Errors
If authentication fails, you'll receive one of these errors:
{
"error": "Missing X-API-Key header",
"code": "MISSING_API_KEY"
}{
"error": "Invalid API key",
"code": "INVALID_API_KEY"
}{
"error": "API key has been revoked",
"code": "REVOKED_API_KEY"
}Security Best Practices
Keep keys secret
Never expose API keys in client-side code, public repositories, or share them in plain text.
Use environment variables
Store API keys in environment variables, not in your codebase.
# .env
VEXUTOPIA_API_KEY=vex_live_your_api_keyRotate keys regularly
Create new keys periodically and revoke old ones to maintain security.