Connect PayPal With API Keys
POST/api/paypal/integrations/:id/api-keys
Connect a PayPal integration (or replace its keys) with the merchant's own PayPal REST app credentials. Create the app on developer.paypal.com under Apps & Credentials (type Merchant) and copy its Client ID and Secret.
This endpoint currently requires session authentication; Personal Access Token scope support is in progress.
Authentication: Requires Bearer token with permission to manage integrations.
Body:
environment(required) —production(Live keys) orsandbox.client_id(required, string, 20–255 characters) — the app's Client ID.client_secret(required, string, 20–255 characters) — the app's Secret. Stored encrypted and never returned.
The keys are checked with PayPal before anything is saved; keys PayPal rejects return 422. SKU.io then subscribes a webhook on the app so payments, refunds and disputes are recorded instantly. If PayPal refuses the webhook (for example, the app already has 10 webhooks) the account still connects and webhook_warning explains what to fix; payments are still recorded by SKU.io's periodic checks. Turning on the app's Transaction search feature lets SKU.io import and reconcile the account's PayPal activity (can_import_transactions).
This connection does not need SKU.io's Connect with PayPal sign-in. An account connected this way can later switch to Connect with PayPal and keep its pay links and payment history.
Request
Responses
- 200
- 401
- 403
- 404
- 422
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Unprocessable Entity
Response Headers
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.