harbordocs Get API keys

Going live

Switch to a live key when your sandbox flow handles every outcome. No review, no sales call.

Checklist

  • Your server holds the keys and user tokens. Nothing secret ships in a browser or app.
  • You handle every next action: confirm, user_input, redirect_to_merchant, on_device, reconnect.
  • You show display_message (or next_action.description) to users when it's there.
  • Your webhook endpoint verifies signatures and returns 2xx quickly.
  • You ran the sandbox recipes, including a decline and an out-of-stock item.
  • You open Harbor Approve from hosted_url, not the sandbox shortcut.

Switch to live

  1. In the dashboard, switch to live and create a live key on API keys. It starts with hk_live_ and is shown once.
  2. Add your live webhook endpoint. Its secret is different from sandbox.
  3. Send your users through Approve again with the live key. Sandbox user tokens don't work live.

What's different in live:

  • Sandbox stores and /v1/sandbox/* aren't available.
  • Offers and orders are real, at real stores.
  • Usage counts toward your bill.

Pricing

No monthly fee and no minimums.

Price
First 100 completed orders each month Free
Offer lookups: 10,000 a month, plus 50 with every completed order Free
Completed order $0.50
Active retailer connection $0.25 a month
Each lookup beyond that $0.005
Orders past 10,000 a month $0.35 each
Orders past 100,000 a month $0.20 each

Failed orders are never billed. The shopper pays the store directly; Harbor never holds their money. Your usage so far this month is on the dashboard's overview in live mode.

Billing

Add a payment method in the dashboard under Settings → Billing. It opens Stripe Checkout; nothing is charged up front. After that:

  • Usage is billed monthly, in arrears, by Stripe. Manage your card and invoices with Manage billing.
  • Without a payment method, live usage pauses once you've used the month's free allowance: new live checkouts and lookups return BILLING_REQUIRED. It resumes on the 1st, or as soon as you add a card.
  • Sandbox is always free and never paused.

Keys

  • Roll a key on API keys any time. The old key stops working immediately.
  • Each environment has one active key.
  • If a key leaks, roll it first, then update your server.

Questions: hello@useharbor.io.