API key pattern with $ and PHP clients
Send the API Key correctly in PHP
The Asaas API uses the access_token header to authenticate requests.
access_token: $aact_prod_xxxxxxxxxxxxxxxxxxAsaas does not use the
Authorization: Bearerpattern.Send the key directly in the
access_tokenheader.
Prefixes by environment
| Environment | Prefix |
|---|---|
| Production | $aact_prod_ |
| Sandbox | $aact_hmlg_ |
The key and the request URL must belong to the same environment.
Watch out for the $ character
$ characterThe $ character is part of the key and must not be removed or changed.
In PHP, double-quoted strings allow variable interpolation. Because of this, a key written directly this way may have its value interpreted incorrectly.
Incorrect example
$apiKey = "$aact_prod_xxxxxxxxxxxxxxxxxx";In this example, PHP tries to interpret the content starting with $ as a variable. As a result, the value sent in the header may differ from the original key and result in 401 Unauthorized.
Use single quotes
When declaring a key directly in a PHP string, use single quotes:
$apiKey = '$aact_hmlg_xxxxxxxxxxxxxxxxxx';Single quotes cause the content to be treated as a literal string.
Do not keep real keys directly in the source code.
The example above only demonstrates how the
$character is handled. In your application, use an environment variable or a secrets manager.
Request example
<?php
$apiKey = getenv('ASAAS_API_KEY');
if (!$apiKey) {
throw new RuntimeException('The ASAAS_API_KEY variable has not been configured.');
}
$headers = [
'Accept: application/json',
'Content-Type: application/json',
'User-Agent: your_application_name',
'access_token: ' . $apiKey,
];
$ch = curl_init('https://api-sandbox.asaas.com/v3/customers');
curl_setopt_array($ch, [
CURLOPT_HTTPHEADER => $headers,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CUSTOMREQUEST => 'GET',
]);
$response = curl_exec($ch);
if ($response === false) {
throw new RuntimeException(curl_error($ch));
}
$statusCode = curl_getinfo($ch, CURLINFO_HTTP_CODE);
curl_close($ch);
echo "HTTP Status: {$statusCode}\n";
echo $response;In this example, the key must be set in the ASAAS_API_KEY environment variable with the full value, including the $.
How to confirm it is being sent
Check that:
- the header used is
access_token; - the key keeps the
$character; - there are no spaces before or after the key;
- the key and the URL belong to the same environment;
- the value was not truncated or changed while reading the variable.
Authentication error
If the key is sent incorrectly, the API may return:
401 UnauthorizedTo fix it:
- confirm the value loaded by the application;
- check that the
$character was preserved; - check the environment URL;
- validate that the key is still active.
Next steps
Updated 2 days ago
