Getting started
Authentication
Merida uses two kinds of secrets: API keys (your backend → Merida) and webhook signing secrets (Merida → your backend).
API keys
Create one in Settings → API keys. The key is shown exactly once. We only store its SHA-256 hash server-side, so a lost key must be rotated, not recovered.
- Prefix
mrd_test_…for test mode,mrd_live_…for live mode. The mode is baked into the prefix at creation time and is the only source of truth, so a leaked test key cannot reach live data.- Scope
One organisation, one mode. Switch the dashboard's mode toggle to mint or list keys for the other mode.
- Lifetime
Until you revoke it, or until the optional
expiresAtyou set at creation time.
Send it on every API call:
Authorization: Bearer mrd_test_abc123XYZ...
For example, listing products:
curl https://api.meridapay.com/products \
-H "Authorization: Bearer $MERIDA_API_KEY"
Error responses
Missing, malformed, revoked, or expired keys all return 401 unauthorized. A
valid key attempting to reach a different org's resource returns
404 not_found, never the resource, so probe-by-ID is safe.
Rotation
Create the replacement key first, deploy it, then revoke the old one. The
dashboard shows lastUsedAt on each key so you can confirm nothing is still
using the old one before revoking.
Webhook signing secrets
Each webhook endpoint you register in Settings → Webhooks
has its own signing secret (prefix whsec_). We HMAC-SHA256 every delivery
and emit Standard Webhooks headers
alongside the original Merida pair (kept for one release cycle):
webhook-id: <event uuid>
webhook-timestamp: 1714000000
webhook-signature: v1,<base64>
X-Merida-Signature: t=1714000000,v1=<hex> (deprecated, removed in 0.2)
X-Merida-Timestamp: 1714000000 (deprecated, removed in 0.2)
Verifying is one function call. See Webhooks for Node and Python implementations.
Next up
Embedded overlay →