/v1/...) require authentication using a secret API key. You generate and manage these keys in the Developers > API Keys section of the Tabs Merchant Portal.
API key format
Tabs keys use standardized environment prefixes:- Live environment:
sk_live_...(e.g.sk_live_4f9a7b8e12d3...) - Test environment:
sk_test_...(e.g.sk_test_9c2d1e0a4f5b...)
Passing your key
You can supply your API key in one of two HTTP headers:1. Bearer token (recommended)
Pass the key in the standardAuthorization header with the Bearer prefix:
2. Custom header
Alternatively, pass the key directly in theX-API-Key header:
Granular scopes
When generating a key in the merchant portal, you can grant wildcard access (*) or restrict the key to specific functional permissions:
If a request attempts an operation outside of the key’s assigned scopes, the API returns
403 Forbidden:
IP allowlisting
For high-security server-to-server integrations, you can restrict an API key to specific static IP addresses or CIDR blocks (e.g.198.51.100.42 or 198.51.100.0/24).
When configured, requests originating from unlisted IP addresses are immediately rejected with 403 Forbidden.
Key rolling and rotation
If an API key is compromised, or as part of routine security maintenance:- Navigate to Developers > API Keys in the merchant portal.
- Click Roll Key next to the target key.
- Tabs immediately generates a new replacement key and keeps the old key active for a 24-hour grace period.
- Update your backend services with the new key.
- After 24 hours (or upon clicking Revoke), the previous key ceases to function permanently.
