CREDENTIALS, ACCESS & ENVIRONMENTS

Set up access.
Keep credentials on your server.

Start with the authentication requirements in your product reference. Your BankU workspace login and session cookies are not public API credentials.

BEFORE YOU CONNECT

Access has more than one part.

Credentials identify your organisation. The approved environment, source-IP whitelist and product activation determine which requests it can make.

01 / CREATE

Create API credentials.

Use ERP → Developers API → Credentials. Save the one-time Client Secret and Encryption Key securely, outside source control.

02 / RESTRICT

Whitelist your server.

Add the exact egress IPv4 or IPv6 address for the server making the request. An empty whitelist denies all requests.

03 / CHECK

Check the connection.

The connection check validates credentials and source IP. It records a transaction, but does not call a provider or activate a product.

04 / ACTIVATE

Request product approval.

Submit your website and use case. BankU Control approval and product entitlement are separate requirements.

Follow the documented headers.

The ERP gateway guide specifies X-Client-Id, X-Client-Secret and Idempotency-Key. The idempotency key identifies a logical request; it is not a credential. Never substitute your Client Secret or Encryption Key.

Read the header rules and connection-check example →

Plan for the whole credential lifecycle.

Keep credentials on your backend, use HTTPS and redact secrets and personal data from logs. Arrange rotation with the service owner; the gateway guide explains expiry and how rotation affects existing credentials.

For webhooks, verify the signature against the raw request body, validate the timestamp and deduplicate events before acknowledging delivery. Use the published guide for the exact signing format and delivery rules.

Review rotation, retries and signed webhooks →

Search documentation

↑ ↓ Results Tab Controls Enter Open