API key header
Every server-side API request is authenticated with your API key sent in thex-api-key header:
Using the wrong key is the most common cause of
401 Unauthorized — a live key on a test payment (or vice versa) will not behave as expected.
Public resources need no key. Authentication is only required for secret API resources (creating payments, managing webhooks, reading your dashboard). Public, read-only resources — such as fetching the status of a payment by its ID on the hosted checkout — do not require an API key:
No key required
Verifying webhooks
Tribridge signs every webhook it sends using your endpoint’s webhook secret (the one returned once when you created the endpoint). The signature arrives in theX-Tribridge-Signature header as sha256=<hmac>, alongside a timestamp:
1
Read the raw request body
You need the exact bytes Tribridge sent — parse the JSON only after verifying. In Express, use
express.raw({ type: 'application/json' }) for the webhook route.2
Recompute the HMAC
Compute HMAC-SHA256 over the raw body using your endpoint’s webhook secret as the key, hex-encoded.
3
Compare in constant time
Strip the
sha256= prefix from the header and compare with crypto.timingSafeEqual (never === — it’s vulnerable to timing attacks). Reject mismatches with a non-2xx status so Tribridge retries.Verify signature (Node.js)
Troubleshooting 401s
- Missing header — the request has no
x-api-keyat all. - Wrong key for the mode — test key against a live flow or vice versa.
- Revoked keypair — regenerating keys invalidates the old pair immediately (test and live together).
- Webhook 401 on your side — your signature check rejected the payload. Re-check that you’re hashing the raw body with the correct endpoint secret (test and live endpoints have different secrets).

