Skip to main content

One keypair, two modes

When you generate keys from your dashboard, Tribridge issues a single keypair containing both a test and a live key. Each key is shown exactly once at creation time — store it somewhere safe before closing the dialog.

Test Key — tri_test_...

Routes payments through test mode. No real funds move. Use this while building and validating your webhooks.

Live Key — tri_live_...

Activates real on-chain payments. Never expose it publicly, and only switch to it once your integration is verified in test mode.
A generated keypair looks like this (returned once, never retrievable again):
Example keypair response
Every server-side request carries the key in the x-api-key header:

Webhook secrets

Separately from your API keys, every webhook endpoint you register receives its own signing secret. It is returned only once when the endpoint is created, and it is what lets you prove incoming webhooks genuinely came from Tribridge (see Authentication). Treat it like a password.
Create a webhook (returns secret once)
Register separate endpoints for test and live mode — each gets its own secret.

Rotating and revoking keys

1

Generate a fresh keypair

In the dashboard under API Keys, generate a new keypair. Both a new test and live key are issued together.
2

Update your server config

Swap the old keys for the new ones in your environment variables or secrets manager, then deploy.
3

Revoke the old keypair

Revoke the previous keypair from the dashboard. Requests using it immediately start returning 401.
The test and live keys are a pair: revoking one revokes both. Plan key rotation accordingly, and if a key is ever compromised, revoke it immediately and generate a fresh keypair.

Security best practices

  • Always load keys from environment variables — never hardcode or commit them.
  • Never put API keys in frontend/mobile code; only your server should call Tribridge with them.
  • Your webhook signing secret is shown once. Store it securely; you cannot retrieve it again.
  • Use separate environment variables for test and live keys so you can’t mix them up.