Getting started

Authentication

Merida uses two kinds of secrets: API keys (your backend → Merida) and webhook signing secrets (Merida → your backend).

API keys

Create one in Settings → API keys. The key is shown exactly once. We only store its SHA-256 hash server-side, so a lost key must be rotated, not recovered.

Prefix

mrd_test_… for test mode, mrd_live_… for live mode. The mode is baked into the prefix at creation time and is the only source of truth, so a leaked test key cannot reach live data.

Scope

One organisation, one mode. Switch the dashboard's mode toggle to mint or list keys for the other mode.

Lifetime

Until you revoke it, or until the optional expiresAt you set at creation time.

Send it on every API call:

Authorization: Bearer mrd_test_abc123XYZ...

For example, listing products:

bash
curl https://api.meridapay.com/products \
  -H "Authorization: Bearer $MERIDA_API_KEY"

Error responses

Missing, malformed, revoked, or expired keys all return 401 unauthorized. A valid key attempting to reach a different org's resource returns 404 not_found, never the resource, so probe-by-ID is safe.

Rotation

Create the replacement key first, deploy it, then revoke the old one. The dashboard shows lastUsedAt on each key so you can confirm nothing is still using the old one before revoking.

Webhook signing secrets

Each webhook endpoint you register in Settings → Webhooks has its own signing secret (prefix whsec_). We HMAC-SHA256 every delivery and emit Standard Webhooks headers alongside the original Merida pair (kept for one release cycle):

webhook-id:        <event uuid>
webhook-timestamp: 1714000000
webhook-signature: v1,<base64>
X-Merida-Signature: t=1714000000,v1=<hex>     (deprecated, removed in 0.2)
X-Merida-Timestamp: 1714000000                (deprecated, removed in 0.2)

Verifying is one function call. See Webhooks for Node and Python implementations.