One keypair, two modes
When you generate keys from your dashboard, Tribridge issues a single keypair containing both a test and a live key. Each key is shown exactly once at creation time — store it somewhere safe before closing the dialog.Test Key — tri_test_...
Routes payments through test mode. No real funds move. Use this while building and validating your webhooks.
Live Key — tri_live_...
Activates real on-chain payments. Never expose it publicly, and only switch to it once your integration is verified in test mode.
Example keypair response
x-api-key header:
Webhook secrets
Separately from your API keys, every webhook endpoint you register receives its own signing secret. It is returned only once when the endpoint is created, and it is what lets you prove incoming webhooks genuinely came from Tribridge (see Authentication). Treat it like a password.Create a webhook (returns secret once)
Rotating and revoking keys
1
Generate a fresh keypair
In the dashboard under API Keys, generate a new keypair. Both a new test and live key are issued together.
2
Update your server config
Swap the old keys for the new ones in your environment variables or secrets manager, then deploy.
3
Revoke the old keypair
Revoke the previous keypair from the dashboard. Requests using it immediately start returning
401.Security best practices
- Always load keys from environment variables — never hardcode or commit them.
- Never put API keys in frontend/mobile code; only your server should call Tribridge with them.
- Your webhook signing secret is shown once. Store it securely; you cannot retrieve it again.
- Use separate environment variables for test and live keys so you can’t mix them up.

