X-PayFi-Api-Key and the private secret to sign every Partner API request.
If a private secret is lost or exposed, ask PayFi support to rotate the key. After rotation, deploy the new secret from your secret manager and stop using the old one.
Dashboard access
PayFi dashboard access is separate from signed Partner API authentication:ADMINis an internal PayFi administrator and can create partner integrations, partner admins, admins, and operators.PARTNERis the administrator for one partner integration. It can manage API keys, document requirement settings, compliance/risk configuration, operations, customers, documents, manual review, and operators for its ownpartnerIntegrationId.OPERATORbelongs to one partner integration but only receives the endpoint keys explicitly granted inallowedEndpointKeys.
partnerIntegrationId when using partner-scoped dashboard endpoints. PayFi resolves that scope from the logged-in user profile.