Keep your gateway keys safe
Who in the school should hold payment gateway keys, how to handle them, and what to do at once if one is exposed.
The keys, secrets and salts you paste into Payment Configuration let software act on the school's merchant account: start payments, check them and send refunds. Treat them like the key to the school's cash box. This guide sets out simple rules and what to do if a key leaks.
Who should have access#
| Person | Needs |
|---|---|
| The owner or principal who signed up with the gateway | Owner access to the gateway dashboard. Decides who else gets in. |
| The school administrator in the ERP | The gateway keys, only while connecting or changing a gateway. Only the school administrator can open and save Payment Configuration. |
| The accountant | The gateway's reports and settlements, and the ERP's Online fee collection. Not the keys. Give a view-only or reports user in the gateway dashboard if the gateway offers one. |
| Office staff at the counter | Neither the keys nor the gateway dashboard. |
Rules for handling keys#
- Copy each key straight from the gateway's dashboard into the ERP screen. Do not type it into a document first.
- Never send keys by e-mail, chat, WhatsApp or SMS, to anyone, and never put them in a screenshot or a photo of a screen.
- Keep test keys and live keys apart. Paste each only into the matching Test environment or Live environment.
- Store downloaded key files (for example, a private key file from PayGlocal) where only the people above can reach them, and delete stray copies from Downloads folders and shared drives.
- Guard the school administrator's ERP login. It asks for a code from an authenticator app after the password; keep that phone safe, and never share the login. See Getting started.
- Change the keys when someone who had them leaves the school or no longer needs them.
What the ERP does with the keys#
- A saved secret is never shown again on the screen, not even to the administrator. A saved box shows Saved — leave blank to keep.
- Leaving a box blank keeps the saved value, so an accidental save does not wipe a key.
- Every change to Payment Configuration is recorded in the Audit Log with who made it and when. The key values themselves are not written there.
- Parents and staff never see the keys. The parent's payment page only carries what the gateway needs to open its checkout.
If a key may have been exposed#
Act at once. It takes a few minutes.
- Sign in to the gateway's dashboard and regenerate or revoke the exposed key. Do the same for any webhook secret or password that was exposed with it.
- Open General Settings › Payment Configuration, select Open settings on that gateway and choose the right environment (Live environment for live keys).
- Paste the new values and select Save settings.
- Saving changed keys gives the gateway new addresses. Copy the new Webhook URL (and Return URL, if shown) and update them in the gateway's dashboard.
- Select Test connection if the gateway has it, or run a sandbox payment. See Test a payment end to end.
- In the gateway's dashboard, look for payments, refunds or setting changes the school did not make. Report anything unexpected to the gateway.
- In the ERP's Audit Log, check for Payment Configuration changes the school did not make.
- If you think an ERP login was misused, change that user's password and tell JPRAXC support.
Good to know#
- Regenerating a key in the gateway stops the old key working straight away. Payments already recorded stay recorded.
- If a refund of a payment made before the key change does not go through, contact JPRAXC support with the payment reference.
- If you are not sure whether a key was exposed, change it anyway. It costs little.
