API key pattern with $ and PHP clients

Send the API Key correctly in PHP

The Asaas API uses the access_token header to authenticate requests.

access_token: $aact_prod_xxxxxxxxxxxxxxxxxx
📘

Asaas does not use the Authorization: Bearer pattern.

Send the key directly in the access_token header.

Prefixes by environment

EnvironmentPrefix
Production$aact_prod_
Sandbox$aact_hmlg_

The key and the request URL must belong to the same environment.

Watch out for the $ character

The $ character is part of the key and must not be removed or changed.

In PHP, double-quoted strings allow variable interpolation. Because of this, a key written directly this way may have its value interpreted incorrectly.

Incorrect example

$apiKey = "$aact_prod_xxxxxxxxxxxxxxxxxx";

In this example, PHP tries to interpret the content starting with $ as a variable. As a result, the value sent in the header may differ from the original key and result in 401 Unauthorized.

Use single quotes

When declaring a key directly in a PHP string, use single quotes:

$apiKey = '$aact_hmlg_xxxxxxxxxxxxxxxxxx';

Single quotes cause the content to be treated as a literal string.

⚠️

Do not keep real keys directly in the source code.

The example above only demonstrates how the $ character is handled. In your application, use an environment variable or a secrets manager.

Request example

<?php

$apiKey = getenv('ASAAS_API_KEY');

if (!$apiKey) {
    throw new RuntimeException('The ASAAS_API_KEY variable has not been configured.');
}

$headers = [
    'Accept: application/json',
    'Content-Type: application/json',
    'User-Agent: your_application_name',
    'access_token: ' . $apiKey,
];

$ch = curl_init('https://api-sandbox.asaas.com/v3/customers');

curl_setopt_array($ch, [
    CURLOPT_HTTPHEADER => $headers,
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_CUSTOMREQUEST => 'GET',
]);

$response = curl_exec($ch);

if ($response === false) {
    throw new RuntimeException(curl_error($ch));
}

$statusCode = curl_getinfo($ch, CURLINFO_HTTP_CODE);

curl_close($ch);

echo "HTTP Status: {$statusCode}\n";
echo $response;

In this example, the key must be set in the ASAAS_API_KEY environment variable with the full value, including the $.

How to confirm it is being sent

Check that:

  • the header used is access_token;
  • the key keeps the $ character;
  • there are no spaces before or after the key;
  • the key and the URL belong to the same environment;
  • the value was not truncated or changed while reading the variable.

Authentication error

If the key is sent incorrectly, the API may return:

401 Unauthorized

To fix it:

  1. confirm the value loaded by the application;
  2. check that the $ character was preserved;
  3. check the environment URL;
  4. validate that the key is still active.

Next steps


Did this page help you?