Skip to main content

API key header

Every server-side API request is authenticated with your API key sent in the x-api-key header:
Which key to use: Using the wrong key is the most common cause of 401 Unauthorized — a live key on a test payment (or vice versa) will not behave as expected.
Public resources need no key. Authentication is only required for secret API resources (creating payments, managing webhooks, reading your dashboard). Public, read-only resources — such as fetching the status of a payment by its ID on the hosted checkout — do not require an API key:
No key required

Verifying webhooks

Tribridge signs every webhook it sends using your endpoint’s webhook secret (the one returned once when you created the endpoint). The signature arrives in the X-Tribridge-Signature header as sha256=<hmac>, alongside a timestamp:
1

Read the raw request body

You need the exact bytes Tribridge sent — parse the JSON only after verifying. In Express, use express.raw({ type: 'application/json' }) for the webhook route.
2

Recompute the HMAC

Compute HMAC-SHA256 over the raw body using your endpoint’s webhook secret as the key, hex-encoded.
3

Compare in constant time

Strip the sha256= prefix from the header and compare with crypto.timingSafeEqual (never === — it’s vulnerable to timing attacks). Reject mismatches with a non-2xx status so Tribridge retries.
Verify signature (Node.js)

Troubleshooting 401s

  • Missing header — the request has no x-api-key at all.
  • Wrong key for the mode — test key against a live flow or vice versa.
  • Revoked keypair — regenerating keys invalidates the old pair immediately (test and live together).
  • Webhook 401 on your side — your signature check rejected the payload. Re-check that you’re hashing the raw body with the correct endpoint secret (test and live endpoints have different secrets).