Stripe API Authentication
How to authenticate Stripe API requests: one Bearer API key plus a connectionId. MindCloud stores your Stripe credentials — no auth headers to build.
Every Stripe API request through MindCloud needs two things: a MindCloud API Key and a connectionId for your Stripe account. This page covers both, plus exactly how to send them, so you do not need to visit any other page to get authenticated.
Steps to authenticate
- Create a MindCloud account at app.mindcloud.co if you do not already have one.
- Generate a MindCloud API Key in API Keys. This is the Bearer token you send on every request. Keep it on your server.
- Create a Stripe connection in Connections. Stripe uses a username and password. You enter them when you create the connection — MindCloud stores them securely so your requests never carry raw credentials.
- Copy the connection’s
connectionId— you will send it on every request alongside your MindCloud API Key.
How requests are authenticated
Authentication has two layers. Your MindCloud API Key authenticates the request to MindCloud, sent as a Bearer token in the Authorization header. The connectionId selects the connected Stripe account that should run the action. MindCloud stores and refreshes the Stripe credentials behind that connection, so you never send provider tokens with your requests.
Pass connectionId in the query string for GET and DELETE actions, and in the JSON body for POST, PUT, and PATCH actions.
For example, calling List Customers with an Stripe connection looks like this:
curl --request GET \
--url "https://connect.mindcloud.co/v1/universal/stripe/latest/actions/list-customers" \
--header "Authorization: Bearer $MINDCLOUD_API_KEY" \
--get \
--data-urlencode "connectionId=$CONNECTION_ID"The Authorization: Bearer <your MindCloud API Key> header authenticates you to MindCloud; the connectionId tells MindCloud which Stripe account to run the action against. Missing or invalid Authorization returns 401, and a missing or mismatched connectionId returns 400.
Set up your Stripe live secret key
You need access to the Stripe Developers Dashboard for the account MindCloud should use. Stripe secret keys are server-side credentials and must be kept private.
- Open the Stripe API keys page
In Stripe, open the Developers Dashboard and go to the API keys page. If you cannot view API keys, ask the Stripe account owner to grant you the required team permissions.
- Switch to live mode
Turn off Test mode in the top-right corner so the page shows your live mode keys.
- Reveal or create a live secret key
Use the live mode secret key for this connection. If you need a new one, click Create secret key, complete Stripe's verification step, name the key, and copy the value when Stripe shows it.
- Paste the key into MindCloud
Enter the Stripe secret key as the basic-auth username or API key value in MindCloud. Leave the password blank.
Keep your key safe
Keep your MindCloud API Key on your server; do not ship it in browser code, mobile apps, public repositories, or logs. Anyone with the key can call the Universal API as your MindCloud account, across every connection you have created.