Skip to main content
All API requests require authentication using an API key. This key is unique to each merchant and must be included in every request to ensure secure and authorized access to our services.

What is an API Key?

An API key is a secret token that identifies your application or system when making requests to Compago’s API. It ensures that only authorized systems can initiate transactions, retrieve data, or trigger any backend logic. Keep your API key secure and never expose it in public client-side code.

How to Generate an API Key

Keys are created in the dashboard of the environment they will call: To create an API key:
  1. Sign in to the dashboard of the environment you want to call.
  2. Navigate to Configuraciones → Desarrollador.
  3. Click Crear API Key.
  4. Enter a name for the key (e.g., Production App, Test Integration).
  5. Confirm creation and copy the key immediately (it will only be visible once).
You can revoke or regenerate keys at any time from the same dashboard section.
Desarrollador is the dashboard section for keys, not a development account. A key created in app.compago.com is a production key. To build and test without real payments, ask your Compago contact for a Demo account and create the key in demo-app.compago.com. See Environments.

What a key is allowed to do

A key is bound to the organization it was created in and can only ever reach that organization’s data. It cannot be repointed, and an id from another organization returns 404. The Developer API is read-only: every endpoint is a GET, so a key cannot create, edit or delete anything through it. The payment-acceptance endpoints (/one-time-payment, /payment-intent, /payment-method) do accept writes, because taking a payment is their purpose.
A leaked key can read your payments, including customer names, emails and phone numbers. Rotate keys you no longer recognise, and give each integration its own so you can revoke one without breaking the others.

Base URLs

Keys are per environment. A demo key will not authenticate against production. The examples in these docs use the production host. While you build, call the Demo host with a Demo key.
The previous hosts, demo.api.harmony.compago.com and api.harmony.compago.com, are deprecated. If your integration still calls them, switch to the hosts above. Only the host changes: paths and API keys stay the same.

Using the API Key in Requests

Every request to a protected endpoint must include your API key in the request headers.

Header Format

Here’s an example using curl:
The same header authenticates the Developer API under /api/developer/v1:
That request is the quickest way to confirm a key works: it returns the organization the key belongs to. If the API key is missing or invalid, you will receive a 401 Unauthorized response.
🔒 Always keep your API key secret. Rotate it regularly and never commit it to version control.