Authentication
Authenticated provider calls use a Bearer API key.
Authorization: Bearer <YOUR_API_KEY>
Content-Type: application/json
Never put a real key in documentation, source control, or browser JavaScript.
Rules
- Sandbox keys work only on
https://sandbox-api.studentpay.co.nz - Production keys work only on
https://api.studentpay.co.nz - Keys are provider-specific. The key determines provider identity
provider.provider_codein the body must match the key. You cannot select another provider in the request- Do not reuse a production key in sandbox, or the reverse
- Call StudentPay from your backend. Do not embed keys in enrolment pages
Public endpoints
These do not require a key:
GET /v1GET /v1/environment
Use them to confirm the host and readiness before you send student data.
Onboarding a provider
StudentPay issues a sandbox provider_code and a server-side key. Also required in Salesforce: an Account and an active Provider_Integration_Config__c whose Environment__c matches the API runtime (Sandbox or Production), with API_Enabled__c true and Account__c populated.
Optional PIC branding and success/cancel URLs are used on hosted legal/setup pages. Allowlist the provider origin in ALLOWED_ORIGINS.
Keys are provider-specific. The key must match provider.provider_code in the request body. PROVIDER_API_KEY_<CODE> and PROVIDER_API_KEYS are generic; there is no Bela-only authentication path on /v1.
Sandbox examples in this site use SANDBOX_DEMO. Issued codes such as BELA_NZ are assigned to a specific provider. Seeing a code in an example does not mean that provider’s credentials are public.
Failure modes
v1 wraps authentication failures in the standard error envelope.
| Code | HTTP | When |
|---|---|---|
MISSING_API_KEY |
401 | Authorization header absent or empty |
INVALID_API_KEY |
403 | Bearer token is not a recognised key |
PROVIDER_KEY_MISMATCH |
403 | Key does not match provider.provider_code |
See Errors.
Obtaining keys
Ask StudentPay for a sandbox key first. Production keys are issued separately after sandbox integration. Contact partners@studentpay.com.au.