Developers

A versioned JSON REST API with predictable errors, idempotency, and signed webhooks.

Authentication

Each key pair has a public key (cpk_test_… / cpk_live_…) and a secret (csk_…). Send them with HTTP Basic auth from your server only – never from a browser or mobile app. Keys can be scoped, IP-restricted, rotated and revoked from your dashboard.

Environments

Sandbox keys work immediately and never move real money; sandbox transactions are clearly labelled. Live keys are issued only after your account is approved.

Webhooks

Events such as collection.successful are signed with HMAC-SHA256 using a per-endpoint secret, include an event ID and timestamp for replay protection, and are retried with exponential back-off.

Get sandbox keys
// PHP / Laravel – request a collection
$response = Http::withBasicAuth(env('CEDARPAY_PUBLIC_KEY'), env('CEDARPAY_SECRET'))
    ->withHeaders(['Idempotency-Key' => $order->uuid])
    ->post('https://pay.cedar-net.com/api/v1/collections', [
        'merchant_reference' => $order->number,
        'amount'   => 45000,
        'currency' => 'UGX',
        'provider' => 'airtel_uganda',
        'customer' => ['phone' => '256752123456'],
    ]);

// Verify a webhook
$expected = hash_hmac('sha256', $timestamp.'.'.$rawBody, $endpointSecret);
abort_unless(hash_equals($expected, $signature), 401);
Launch status: the CedarPay sandbox is open to developers now. Live MTN MoMo and Airtel Money processing starts once operator onboarding and the applicable regulatory approvals are complete.