Information
- OpenAPI version:
3.1.0
Accept payments in Nigeria with card, bank transfer, USSD and Pay with Nablr.
The public API of Nablr for Business (Pay with Nablr). Your server calls it with your secret key to start payments, check them, manage payment links and webhook endpoints, and read customers and settlements.
Conventions
Content-Type: application/json with every body.
Unknown fields in a request body are refused (VALIDATION_FAILED, detail
code unknown), so a misspelt field never goes unnoticed.{"data": …, "meta": {"request_id": "…"}}. Lists add
meta.next (a cursor, or null on the last page) and meta.has_more.{"error": {"message", "code", "title", "details"?, "meta"?}, "meta": {"request_id"}}. Branch on error.code, show error.message.500000 is ₦5,000.00.
The only currency is NGN.2026-10-01T09:30:00Z.pay_, cus_, lnk_, evt_, whe_, whd_,
stl_, mer_, key_. An id with the wrong prefix is a 404.404 NOT_FOUND; a method a path does not take is
405 METHOD_NOT_ALLOWED with an Allow header. Both use the error
envelope.VALIDATION_FAILED with detail code
type, naming the field and what to send (for example Send a whole number.).Test and live. The key decides the mode. A sk_test_ key only ever
sees test data and a sk_live_ key only live data; the two never mix.
Test mode runs on a simulator, so no money moves.
Rate limits. With your secret key, 1,000 requests a minute per
business per mode, however many of your servers share one IP address.
Account-name enquiry (POST /banks/resolve) has a tighter limit of its
own: 30 a minute per key (or per dashboard user).
Browser traffic (the checkout, payment links, your publishable key) is
limited to 300 a minute per IP address. Responses carry
X-RateLimit-Limit and X-RateLimit-Remaining; a refusal is 429 RATE_LIMITED with Retry-After.
Your secret key, from Developers in the dashboard:
Authorization: Bearer sk_test_…. Keep it on your server. A
publishable key (pk_…) is refused with 403 SECRET_KEY_REQUIRED
everywhere except POST /checkout/initialize.
Security scheme type: http
Bearer format: sk_test_… or sk_live_…
Your publishable key, from Developers in the dashboard. Safe to put
in a web page or app: it can only start a checkout
(POST /checkout/initialize). Every other request needs the secret key.
Security scheme type: http
Bearer format: pk_test_… or pk_live_…