Superchat BD
Developer Docs
v1.0
Security & Access

Authentication & API Keys

All requests to the Superchat BD Developer Platform API are authenticated using Bearer tokens containing your secret API key.

Key Types & Environments

Live (Production)
Live Secret Keys

Prefix: sk_live_...

Used in production to accept real customer money via bKash, Nagad, and international bank cards.

Test (Sandbox)
Test Secret Keys

Prefix: sk_test_...

Used during development and staging. Test charges simulate payment completions without moving real money.

Sending the Authorization Header

Include your secret key in the `Authorization` header of every HTTP request:

# cURL Example

curl https://api.superchatbd.com/api/v1/account \
  -H "Authorization: Bearer sk_live_your_secret_key"

# x-api-key works too, if you prefer a header that is not Authorization

curl https://api.superchatbd.com/api/v1/account \
  -H "x-api-key: sk_live_your_secret_key"

A missing, malformed or revoked key returns `401 Unauthorized`. Keys are stored only as a SHA-256 hash — the secret is shown once at creation and cannot be retrieved afterwards, so rotate by creating a new key and revoking the old one.

Trying the API without an account

The public sandbox key sk_test_demo works against the sandbox workspace and is what the Swagger UI uses, so you can exercise the endpoints before creating your own keys. It behaves like a normal `sk_test_` key: payments are simulated and no real money moves.

Rate limits

Each key may make 120 requests per minute. Every response reports the budget in `X-RateLimit-Limit` and `X-RateLimit-Remaining`; exceeding it returns `429` with a `Retry-After` header. See the SDK page for the full header reference.

Keep your secret keys secure

Never expose secret keys (`sk_live_...` or `sk_test_...`) in client-side code such as React components, browser scripts, or mobile app binaries. All requests using secret keys must originate from your secure backend servers.