Get Your Credentials

Sign up, find your credentials, and make every request authenticate.

1. Create your account

Sign up at displai.transfi.com/auth — company details, email OTP, password, then MFA with an authenticator app. You can start testing immediately; no sales call.

2. Find your credentials

Settings → Integration in the dashboard shows three things:

WhatWhere
UsernameShown on the Integration tab
Password (merchant key)Click the regenerate icon → Yes, generate → copy it. It is shown once.
MIDYour merchant ID, on the same tab

Settings → Integration: username, MID and the password regenerate icon

Click regenerate, confirm, then copy the password — it's shown once

Sandbox and production have separate credentials. Store them as environment variables — never in code, frontend JavaScript, mobile bundles or public repositories.

# .env
TRANSFI_USERNAME=your_sandbox_username
TRANSFI_PASSWORD=your_sandbox_password
TRANSFI_MID=your_mid

3. Send them on every request

TransFi uses HTTP Basic authentication plus a mid header.

HeaderValue
AuthorizationBasic + Base64 of username:password
midYour MID. Required on every request.
Content-Typeapplication/json when sending a body
EnvironmentBase URLReal money?KYB required?
Sandboxhttps://sandbox-api.transfi.comNo — use Testing in SandboxNo
Productionhttps://api.transfi.comYesYes
curl 'https://sandbox-api.transfi.com/v3/mids' \
  -u "$TRANSFI_USERNAME:$TRANSFI_PASSWORD" \
  -H "mid: $TRANSFI_MID"
const credentials = Buffer.from(`${process.env.TRANSFI_USERNAME}:${process.env.TRANSFI_PASSWORD}`).toString('base64');
const headers = {
  'Authorization': `Basic ${credentials}`,
  'mid': process.env.TRANSFI_MID,
  'Content-Type': 'application/json'
};
import base64, os
credentials = base64.b64encode(f"{os.getenv('TRANSFI_USERNAME')}:{os.getenv('TRANSFI_PASSWORD')}".encode()).decode()
headers = {
    'Authorization': f'Basic {credentials}',
    'mid': os.getenv('TRANSFI_MID'),
    'Content-Type': 'application/json'
}

If the call returns your MIDs, you're authenticated. 401 means the encoding is wrong or the credentials aren't active yet; UNAUTHORIZED_CUSTOMER means the mid header is missing or wrong.

⚠️

A missing mid header is the most common first-call failure. It isn't inferred from your credentials.

📘

More than one MID? Balances, orders and settings are scoped to the mid you send. See List MIDs.


Did this page help you?