Authentication
One header, and the key that decides whether money is real.
Every request carries an account API key as a bearer token:
curl https://api.tizon.mobile/v1/wallet \
-H "Authorization: Bearer tz_live_..."A missing or unrecognised key is 401.
The key selects the mode
| Prefix | Mode | What it touches |
|---|---|---|
tz_test_ | Sandbox | Sandbox providers and testnet rails. No real money. |
tz_live_ | Live | Real providers, real money. |
There is one base URL, https://api.tizon.mobile. The mode comes from the key, never
from the host or a parameter, so promoting an integration to live is a change of
credential and nothing else.
Test and live are fully isolated: separate wallets, ledgers, provider credentials and webhook secrets. A test wallet's balance has no bearing on a live one, and an endpoint registered in test mode receives test events only.
Funding destinations differ between modes too. Never send real money to a test destination — see funding.
Getting keys
Test keys are issued on sign-up, with no KYC. Live keys unlock after KYC approval. Both are created, listed and rotated in the dashboard.
A key is shown once, at creation. Rotating a key revokes the old one, so deploy the new one before you revoke.
Test helpers refuse live keys
The sandbox tools under /v1/test_helpers/* — simulated deposits, forced fulfillment,
paid invoices — return 403 test_mode_only for a live key. The isolation is enforced by
the API, not by your discipline.
Request ids
Every response carries a Request-Id header, and every error body repeats it as
request_id. Log it, and quote it when reporting a problem.