Developers
A versioned JSON REST API with predictable errors, idempotency, and signed webhooks.
Authentication
Each key pair has a public key (cpk_test_… / cpk_live_…) and a secret (csk_…). Send them with HTTP Basic auth from your server only – never from a browser or mobile app. Keys can be scoped, IP-restricted, rotated and revoked from your dashboard.
Environments
Sandbox keys work immediately and never move real money; sandbox transactions are clearly labelled. Live keys are issued only after your account is approved.
Webhooks
Events such as collection.successful are signed with HMAC-SHA256 using a per-endpoint secret, include an event ID and timestamp for replay protection, and are retried with exponential back-off.
// PHP / Laravel – request a collection $response = Http::withBasicAuth(env('CEDARPAY_PUBLIC_KEY'), env('CEDARPAY_SECRET')) ->withHeaders(['Idempotency-Key' => $order->uuid]) ->post('https://pay.cedar-net.com/api/v1/collections', [ 'merchant_reference' => $order->number, 'amount' => 45000, 'currency' => 'UGX', 'provider' => 'airtel_uganda', 'customer' => ['phone' => '256752123456'], ]); // Verify a webhook $expected = hash_hmac('sha256', $timestamp.'.'.$rawBody, $endpointSecret); abort_unless(hash_equals($expected, $signature), 401);
Launch status: the CedarPay sandbox is open to developers now. Live MTN MoMo and Airtel Money processing starts once operator onboarding and the applicable regulatory approvals are complete.