Where to find your TBBN API keys
TBBN has two kinds of API key. Use the one for the product you're integrating:
| Key | Starts with | For | Where to create it |
|---|---|---|---|
| Merchant API key | sk_sandbox_ (sandbox), sk_live_ (live) | The Trade Engine: listings, sellers, offers, trades, webhooks | merchants.tbbnetwork.com → API Keys |
| Space API key | sk_space_sandbox_, sk_space_live_ | The Space API: searching and booking Spaces from your app | account.tbbnetwork.com → Space API keys |
A key is shown only once, when it's created. TBBN stores only a fingerprint of it, so it can't show it to you again. Copy it straight into your server's secret store.
Get a sandbox key in seconds (no account)
Just exploring? On the developer site, open Sandbox and select Get a sandbox key. You get a working sandbox key for a brand-new, isolated sandbox merchant — free, rate-limited, no production data. Select Copy key and save it; it's shown once.
Merchant API keys
You need a Merchant account, and you must be its Owner or Admin to create or revoke keys.
- Sign in at merchants.tbbnetwork.com (enter your email, select Send code, enter the code, select Verify & log in).
- Select API Keys in the sidebar.
- Select:
- Create sandbox key — works any time, against sandbox data only;
- Create production key — available once TBBN has approved your Merchant account. Confirm the prompt: anything a live key creates is real.
- The key appears under New key secret — shown once. Copy it now.
The table lists every key by its first characters (Key), Environment, Scopes, Status and Last used — never the full secret.
Use it
Send it on every API call as a bearer token, from your server only:
Authorization: Bearer sk_sandbox_…
See Authentication and Getting started.
Space API keys
You need a Business. Developers, Admins and the owner can create sandbox keys; production keys need an Admin or the owner.
- Go to account.tbbnetwork.com. On Overview, find your Business and select Space API keys.
- Select New sandbox key or New production key.
- Copy the key shown under Copy this key now — it won't be shown again.
- Optionally set the key's defaults — Default country, Default region/state, Default radius (miles), Booking consent (headless bookings only) and Pinned Branch IDs — and select Save config.
See the Space API guide for what each setting does.
Rotate or revoke a key
- Revoke stops a key working immediately. Use it when a key may have leaked or is no longer used.
- Rotate (Space API keys) issues a replacement and retires the old one. Copy the new key — it's shown once.
For a Merchant key, create a new key, switch your servers to it, then Revoke the old one.
Keep keys safe
- Never put a key in a website's front-end code, a mobile app, or a public repository. Keys belong on your server.
- Use sandbox keys for development and testing; use live keys only in production.
- Give each environment or service its own key, so you can revoke one without breaking the others.
- Revoke keys used by people who leave your team.
Common questions
I lost my key. It can't be shown again. Create a new one and revoke the lost one.
"Production keys are available once TBBN approves your Merchant account." Your application is still under review. Keep building with a sandbox key.
My live key gets a 402 USAGE_BALANCE_EXHAUSTED or PAYMENT_REQUIRED error. Your plan
allowance is used up and your usage balance is below zero, or an invoice is unpaid. Top up, upgrade
or pay the invoice — see
Plans and billing. Sandbox keys keep working.
Which key does a webhook use? Neither. Each webhook endpoint has its own signing secret — see Webhooks.
Still stuck? Ask in the community or contact us from tbbnetwork.com/contact.