Create API credentials.
Use ERP → Developers API → Credentials. Save the one-time Client Secret and Encryption Key securely, outside source control.
Start with the authentication requirements in your product reference. Your BankU workspace login and session cookies are not public API credentials.
Credentials identify your organisation. The approved environment, source-IP whitelist and product activation determine which requests it can make.
Use ERP → Developers API → Credentials. Save the one-time Client Secret and Encryption Key securely, outside source control.
Add the exact egress IPv4 or IPv6 address for the server making the request. An empty whitelist denies all requests.
The connection check validates credentials and source IP. It records a transaction, but does not call a provider or activate a product.
Submit your website and use case. BankU Control approval and product entitlement are separate requirements.
The ERP gateway guide specifies X-Client-Id, X-Client-Secret and Idempotency-Key. The idempotency key identifies a logical request; it is not a credential. Never substitute your Client Secret or Encryption Key.
Keep credentials on your backend, use HTTPS and redact secrets and personal data from logs. Arrange rotation with the service owner; the gateway guide explains expiry and how rotation affects existing credentials.
For webhooks, verify the signature against the raw request body, validate the timestamp and deduplicate events before acknowledging delivery. Use the published guide for the exact signing format and delivery rules.
Review rotation, retries and signed webhooks →