Quickstart
Create an application, get a key, and make your first charge.
This walks through the shortest path from "no account" to "money moved" — using a test key, so nothing here touches real funds.
Create your account and an application
Sign up for a merchant account, then create an application from your dashboard. An application is the unit everything else attaches to — its own API keys, its own webhook URL, its own default successUrl/cancelUrl for hosted checkout.
You'll set a currency (ISO 4217, e.g. XAF) and a webhookUrl when you create it — you can change both later.
Create a test API key
From the application's API Keys page, create a key with environment: TEST. The plaintext key is shown once — copy it now:
sk_test_2f1a9c4e8b7d3f0a6e5c1b9d8a4f7e2c...One active key per application
An application can only have one active key at a time, regardless of
environment. Creating a second one while a key is already active fails with
409 API_KEY_ALREADY_ACTIVE. If you need live and test running side by
side, use two separate applications — rotating a key invalidates the
previous one immediately.
Make a test charge
POST /api/v1/pay-in/charge debits a mobile money account directly — no redirect, no hosted page. It's the fastest way to see a transaction move through the system.
curl -X POST https://api.orivantapay.com/api/v1/pay-in/charge \
-H "X-API-KEY: sk_test_2f1a9c4e8b7d3f0a6e5c1b9d8a4f7e2c..." \
-H "Content-Type: application/json" \
-d '{
"amount": 5000,
"currency": "XAF",
"paymentMethod": "MTN_MOMO_CM",
"payerAccount": "670000000",
"merchantReference": "test-001"
}'You'll get back a reference and a status of PENDING. See Pay-in for the full request and response shape, and Idempotency before you wire up retries.
Point a webhook at your server
Set webhookUrl on the application (or PATCH /api/v1/merchants/apps/{appId} from the dashboard side), then generate a webhook secret so deliveries are signed. Without a secret, webhooks still arrive — just unsigned, which means you can't verify they actually came from Orivanta Pay. See Webhooks for the payload shape and signature verification code.
Go live
Create a second application (or rotate the key on this one) with environment: LIVE, swap sk_test_ for sk_live_, and point your webhook at a production URL. Nothing else about the integration changes — same fields, same response shapes, same signature scheme.