Use API keys only from your server. Do not expose them in frontend JavaScript, mobile apps, logs, screenshots, or public repositories.If you regenerate an API key, update every server environment that calls Kyren Pay. The previous key stops working after regeneration.
If IP allowlist is enabled for your merchant account, make sure every server that calls Kyren Pay is included. Missing server IPs can cause authentication or authorization failures.