> For the complete documentation index, see [llms.txt](https://docs.loomgate.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.loomgate.io/getting-started/api-keys.md).

# Khóa API và xác thực

Secret key, publishable key, client secret và cách gửi chúng.

Loomgate dùng ba loại thông tin xác thực:

| Loại            | Dạng                  | Dùng ở đâu                       | Cho phép                                                            |
| --------------- | --------------------- | -------------------------------- | ------------------------------------------------------------------- |
| Secret key      | `sk_live_` + 32 ký tự | Chỉ máy chủ của bạn              | Mọi route server: tạo, sửa, xác nhận payment, hoàn tiền, đọc số dư… |
| Publishable key | `pk_live_` + 32 ký tự | Trình duyệt (an toàn khi lộ)     | Chỉ các route `/partner/v1/client/*` mà `loomgate.js` gọi           |
| Client secret   | `lg_cs_…`             | Trình duyệt, cho **một** payment | Hiện form thẻ và xác nhận đúng payment đó                           |

Gửi key trong header `Authorization`:

```http
Authorization: Bearer sk_live_…
```

## Tạo và thu hồi key

Trong dashboard merchant, mục [**API key**](https://app.loomgate.io/api-keys):

* **Tạo cặp key mới**: mỗi lần tạo được một secret key và một publishable key. Secret key chỉ hiện đúng một lần; nếu mất, tạo cặp mới.
* **Thu hồi**: key bị thu hồi bị từ chối ngay với lỗi `api_key_revoked`. Để đổi key không gián đoạn, tạo cặp mới, triển khai lên máy chủ, rồi mới thu hồi cặp cũ.
* Danh sách key chỉ hiện 4 ký tự cuối của secret key.

{% hint style="danger" %}
Secret key cho phép tạo payment và hoàn tiền trên tài khoản của bạn. Không để nó trong mã chạy ở trình duyệt, ứng dụng di động, kho mã nguồn hay log. Nếu nghi bị lộ, thu hồi ngay.
{% endhint %}

## Client secret

Mỗi payment có một `client_secret` riêng, chỉ trả về trong response tạo payment (và khi gửi lại cùng `Idempotency-Key`). Máy chủ chuyển nó cho trình duyệt của đúng người mua; `loomgate.js` dùng nó cùng publishable key. Publishable key phải thuộc cùng tài khoản với payment, nếu không API trả `payment_intent_not_found`.

## Lỗi xác thực

| Mã lỗi                  | HTTP | Nghĩa                                               |
| ----------------------- | ---- | --------------------------------------------------- |
| `invalid_api_key`       | 401  | Thiếu header `Authorization` hoặc key không tồn tại |
| `api_key_revoked`       | 401  | Key đã bị thu hồi                                   |
| `invalid_client_secret` | 401  | `client_secret` sai hoặc không khớp payment         |

Nhiều lần xác thực sai từ cùng một địa chỉ IP sẽ bị giới hạn tần suất (xem mục Giới hạn tần suất ở [Tham chiếu API](/api-reference.md)).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.loomgate.io/getting-started/api-keys.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
