Get your API credentials

You need a Triple-A account before you can call any API. Credentials come from the Triple-A dashboard, and your request goes through a manual review first. This page shows how to request sandbox access and what happens after you submit.

Request sandbox access

To request a sandbox account, follow these steps.

  1. Sign up for a sandbox account. If you already work with a Triple-A account manager, you can ask them for one instead.
  2. Submit the form. You get an automatic reply that confirms your request was received.

What happens after you submit

The following diagram shows the path from your request to your credentials.

flowchart LR A[You submit the form] --> B[Automatic confirmation email] B --> C[Triple-A manual review] C --> D[Triple-A contacts you] D --> E[You receive credentials]

The Triple-A team reviews your request before you get access. The confirmation email says the team will review the request shortly and contact you after the review.

Plan for a wait#

No turnaround time is stated for this review. A live signup on October 5, 2026 confirmed the review step and gave no timeframe. Submit your request before you need credentials.

After approval, you receive an email with instructions to set up your dashboard login. The link in that email is valid for 24 hours. If it expires, go to the dashboard login page and choose Forgot Password.

What you receive

After you log in to the dashboard, open API Credentials. The table below lists what you find there and what each item is for.

ItemWhat it isUsed for
Client ID and Client SecretOAuth credentialsRequesting an access token. See Authentication.
Sandbox API IDIdentifies a merchant account that accepts testnet currenciesSandbox payments. See Sandbox and test mode.
Live API IDIdentifies a merchant account that accepts real digital currenciesProduction. See Go live.

Your dashboard login and your API credentials are separate. The login lets you into the dashboard, and the Client ID and Client Secret authenticate API requests.

The Make a payment request endpoint also needs a merchant_key, which you receive when you sign up. If you can’t find it in the dashboard, ask your Triple-A contact.

Keep credentials safe

Treat your Client ID and Client Secret like passwords.

  • Never put them in public places such as GitHub or client-side code.
  • Remember that Triple-A support never asks for your credentials.
  • To rotate credentials, click + Create Credentials, update your integration, and then delete the old pair with the × next to it. Deleting credentials immediately invalidates every access token issued with them, so update your integration first.

While you wait

You can do all of the following without credentials.

Next steps

These pages are the best places to go next.