Skip to content
JPRAXCCLOUD & OFFLINE
+91 9792908835 sales@jpraxc.com
JPRAXC Docs

Keep your gateway keys safe

Who in the school should hold payment gateway keys, how to handle them, and what to do at once if one is exposed.

For: School owners, principals, school administrator

The keys, secrets and salts you paste into Payment Configuration let software act on the school's merchant account: start payments, check them and send refunds. Treat them like the key to the school's cash box. This guide sets out simple rules and what to do if a key leaks.

Who should have access#

PersonNeeds
The owner or principal who signed up with the gatewayOwner access to the gateway dashboard. Decides who else gets in.
The school administrator in the ERPThe gateway keys, only while connecting or changing a gateway. Only the school administrator can open and save Payment Configuration.
The accountantThe gateway's reports and settlements, and the ERP's Online fee collection. Not the keys. Give a view-only or reports user in the gateway dashboard if the gateway offers one.
Office staff at the counterNeither the keys nor the gateway dashboard.

Rules for handling keys#

  • Copy each key straight from the gateway's dashboard into the ERP screen. Do not type it into a document first.
  • Never send keys by e-mail, chat, WhatsApp or SMS, to anyone, and never put them in a screenshot or a photo of a screen.
  • Keep test keys and live keys apart. Paste each only into the matching Test environment or Live environment.
  • Store downloaded key files (for example, a private key file from PayGlocal) where only the people above can reach them, and delete stray copies from Downloads folders and shared drives.
  • Guard the school administrator's ERP login. It asks for a code from an authenticator app after the password; keep that phone safe, and never share the login. See Getting started.
  • Change the keys when someone who had them leaves the school or no longer needs them.

What the ERP does with the keys#

  • A saved secret is never shown again on the screen, not even to the administrator. A saved box shows Saved — leave blank to keep.
  • Leaving a box blank keeps the saved value, so an accidental save does not wipe a key.
  • Every change to Payment Configuration is recorded in the Audit Log with who made it and when. The key values themselves are not written there.
  • Parents and staff never see the keys. The parent's payment page only carries what the gateway needs to open its checkout.

If a key may have been exposed#

Act at once. It takes a few minutes.

  1. Sign in to the gateway's dashboard and regenerate or revoke the exposed key. Do the same for any webhook secret or password that was exposed with it.
  2. Open General Settings › Payment Configuration, select Open settings on that gateway and choose the right environment (Live environment for live keys).
  3. Paste the new values and select Save settings.
  4. Saving changed keys gives the gateway new addresses. Copy the new Webhook URL (and Return URL, if shown) and update them in the gateway's dashboard.
  5. Select Test connection if the gateway has it, or run a sandbox payment. See Test a payment end to end.
  6. In the gateway's dashboard, look for payments, refunds or setting changes the school did not make. Report anything unexpected to the gateway.
  7. In the ERP's Audit Log, check for Payment Configuration changes the school did not make.
  8. If you think an ERP login was misused, change that user's password and tell JPRAXC support.

Good to know#

  • Regenerating a key in the gateway stops the old key working straight away. Payments already recorded stay recorded.
  • If a refund of a payment made before the key change does not go through, contact JPRAXC support with the payment reference.
  • If you are not sure whether a key was exposed, change it anyway. It costs little.

YOUR NEXT CHAPTER

Let’s make work
work better.

sales@jpraxc.com

A REAL CONVERSATION STARTS HERE

Hello.
Let’s talk.

SALES & DEMOS+91 9792908835 ↗sales@jpraxc.comChat on WhatsApp ↗
ALREADY WITH JPRAXC?+91 9792908836 ↗support@jpraxc.comWhatsApp support ↗
JPRAXC INFYNEX PRIVATE LIMITED
CIN: U62011UP2026PTC252552
Corporate / Business office
Ward No 12, Dudahi
Kushinagar, Uttar Pradesh
PIN - 274302, India
Dudahi, Kushinagar

A DEMO BUILT AROUND YOUR WORK

See your workflow.
Not a slide deck.

Tell us what you run. We will arrange a tailored 30-minute walkthrough and reply within one working day.

01 Share your setup 02 Choose a time 03 See the right modules
What would you like to see?
You can choose more than one, or leave these blank for a recommendation.

We use your details to handle this request. Promotional contact needs your separate choice above.

A TICKET NUMBER, HERE AND BY E-MAIL

Make a complaint.

Tell the support team what went wrong. You receive a six-digit complaint number the moment you submit; a person acknowledges it within 24 hours and gives a written decision within 30 days. For ordinary appeals, if the decision does not satisfy you, the Grievance Officer accepts that number for 30 days while the complaint is marked Decided. Privacy, statutory and urgent concerns may be reported directly without those steps.

Do not include passwords, one-time codes, card details or complete student or patient records. Prefer e-mail? Write to support@jpraxc.com; you receive the ticket number by return.

JPRAXC / THE COMPLETE PICTURE

Find your next move.

PRODUCTSSchool ERP ↗Hospital ERP ↗Billing & GST ERP ↗Custom Business ERP ↗Websites & hosting ↗All products ↗
CONNECTED SERVICESConnectX ↗Business Email ↗WhatsApp API ↗SMS ↗Payment Gateways ↗Cloud or offline ↗Mail login ↗
LET’S GET STARTEDPricing ↗Buy or renew ↗Read the blog ↗Become a partner ↗User guides (Docs) ↗Demo portals ↗Book a guided demo ↗Mobile apps ↗Downloads ↗
COMPANYAbout JPRAXC ↗Customer stories ↗FAQs ↗Privacy policy ↗Mobile app privacy ↗Terms of service ↗Partner programme terms ↗Refund & cancellation ↗Legal ↗Grievances ↗