Onboarding and verification
What PayDirect sets up for you, the path from sandbox to live, and the per-transaction limit that applies until your account is verified.
Your account on PayDirect is an Integrator. It holds your API keys, balances, settlement accounts, webhook settings and team. This page covers how you get one and what applies to it before and after verification.
What PayDirect sets up
Onboarding starts with PayDirect, not with an API call. There is no key yet to authenticate a self-service request with. PayDirect creates:
- Your Integrator, with its id. The id appears in many endpoint paths as
{id}. - An owner login for the dashboard. The sign-in details are emailed to the owner's address.
- Your first test key: a
DEVELOPMENTkey - a public key (pk_test_…), the raw API key, a secret key (sk_test_…) and, if you want webhooks, a webhook signing secret.
The raw API key, secret key and signing secret are shown once. Store them in a secret manager straight away. See API keys and credentials.
From test to live
- Build with your test key. Every money movement is mocked, so no real money moves and any amount works. See Environments and key types.
- Set up webhooks. Set your webhook URL, and your callback URL if you use hosted checkout. Verify signatures on real deliveries. See Webhooks overview.
- Tell PayDirect where your money should settle. Settlement accounts - the bank account or wallet that withdrawals pay out to - are registered by PayDirect for you. This is deliberate: a leaked key cannot redirect your funds.
- Try it for real with a
SANDBOXkey. Real money, at most GHS 1.00 per transaction. - Work through the go-live checklist, then issue a
PRODUCTIONkey.
Verification and the unverified limit
Until PayDirect has verified and approved your Integrator, your production keys are limited to GHS 1.00 per transaction, and to GHS only - the same limit a sandbox key always has. It covers collections, payouts, withdrawals, bill payments, transfers and checkout links. Test keys are never limited, since nothing real moves.
A production request over the limit is refused with 403 before anything happens:
{
"code": 403,
"status": "error",
"message": "Your integrator account is pending verification and approval. Every transaction is limited to GHS 1.00 until it is approved."
}
Nothing was created or moved, so there is nothing to reconcile. The limit on production keys is lifted when verification completes; sandbox keys stay at GHS 1.00. To start verification, or to ask where yours stands, contact support.
Your Integrator profile
GET /integrators/{id}/info returns your Integrator's configuration: its name, status, contact
details, webhook and callback URLs and similar settings. Signing secrets are never included.
verifiedAt shows when your Integrator was verified, or null if it has not been yet.
Operational emails, such as a notice that webhook deliveries to your endpoint are being abandoned, go to your Integrator's contact email. Make sure PayDirect has an address that someone reads.
Your team
One login can belong to more than one Integrator, so there is no need for a separate account per company.
| Endpoint | What it does |
|---|---|
GET /integrators/{id}/members |
List the people with access to your Integrator |
Your Integrator's owner adds and removes members, and decides whether each member can see all of the Integrator's transactions, from a signed-in dashboard session. API keys can list members but cannot change them. Keys are always issued to a named person, the owner or a member, so every change can be traced to someone. See Issuing further keys yourself.
Next
Quickstart - your first signed request, end to end.