PayMongo · Authentication Profile

Paymongo Authentication

Authentication

PayMongo secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.

PaymentsFintechPhilippinesSoutheast AsiaGCashE-WalletCard Payments
Methods: http Schemes: 1 OAuth flows: API key in:

Security Schemes

basic_auth http
scheme: basic

Source

Authentication Profile

Raw ↑
generated: '2026-07-17'
method: derived
source: openapi/paymongo-openapi.yml
summary:
  types:
  - http
schemes:
- name: basic_auth
  type: http
  scheme: basic
  sources:
  - openapi/paymongo-openapi.yml
  - https://docs.paymongo.com/reference/authentication-1
notes: >-
  PayMongo uses HTTP Basic authentication. The API key is supplied as the
  Basic-auth username (base64-encoded per the Basic scheme); the password
  field is left blank for single-key calls. Secret keys (sk_test_* / sk_live_*)
  are used for server-side calls; the public key (pk_test_* / pk_live_*) may be
  used client-side for Payment Method creation. Some newer Workflow / Ledgers
  surfaces additionally require an Organization-Id header. Webhook payloads are
  verified separately via the Paymongo-Signature header (HMAC with the webhook
  signing secret), which is a payload-integrity mechanism rather than a request
  auth scheme. Live probe: GET https://api.paymongo.com/v1/payment_intents
  returned HTTP 401 without credentials, confirming Basic auth is enforced.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/paymongo-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.