Authentication & API Keys
All requests to the Superchat BD Developer Platform API are authenticated using Bearer tokens containing your secret API key.
Key Types & Environments
Prefix: sk_live_...
Used in production to accept real customer money via bKash, Nagad, and international bank cards.
Prefix: sk_test_...
Used during development and staging. Test charges simulate payment completions without moving real money.
Sending the Authorization Header
Include your secret key in the `Authorization` header of every HTTP request:
# cURL Example
curl https://api.superchatbd.com/api/v1/account \ -H "Authorization: Bearer sk_live_your_secret_key"
# x-api-key works too, if you prefer a header that is not Authorization
curl https://api.superchatbd.com/api/v1/account \ -H "x-api-key: sk_live_your_secret_key"
A missing, malformed or revoked key returns `401 Unauthorized`. Keys are stored only as a SHA-256 hash — the secret is shown once at creation and cannot be retrieved afterwards, so rotate by creating a new key and revoking the old one.
Trying the API without an account
The public sandbox key sk_test_demo works against the sandbox workspace and is what the Swagger UI uses, so you can exercise the endpoints before creating your own keys. It behaves like a normal `sk_test_` key: payments are simulated and no real money moves.
Rate limits
Each key may make 120 requests per minute. Every response reports the budget in `X-RateLimit-Limit` and `X-RateLimit-Remaining`; exceeding it returns `429` with a `Retry-After` header. See the SDK page for the full header reference.
Never expose secret keys (`sk_live_...` or `sk_test_...`) in client-side code such as React components, browser scripts, or mobile app binaries. All requests using secret keys must originate from your secure backend servers.
