pag_...). There is no token exchange: send the key directly as the Bearer token.
Prerequisite: an API key (
pag_...) provided by the PagAmerican team. It is shown only once at creation. Store it securely.Using your key
Send the key in theAuthorization header on every request:
/auth call. The key carries your identity and scope, so you only ever receive the data that belongs to your account.
Security best practices
Treat the key like a password
Never expose your
pag_ key in frontend code, public repositories, or logs. It grants full read access to your account’s data.Always HTTPS
All calls must use HTTPS. Plain HTTP requests fail.
One key, reused
Send the same key on every request. There is no per-request token to generate.
Rotate if leaked
If you suspect a leak, ask the PagAmerican team to revoke the key and issue a new one. Revoked keys stop working immediately.