Quickstart
Call the Shimi API from your backend only. Never put your API key or tokens in a browser or mobile app.
All requests go to:
Get an access token
Exchange your API key for an access token. Pass your company reference in the path and your API key in the x-api-key header.
Store both tokens securely. Each call to this endpoint replaces your previous refresh token.
Call the API with the token
Send the access token as a Bearer token on every other request. For example, to create a customer:
The customer receives an OTP on their BVN-linked phone. Pass it to Generate Customer Account to create their dedicated bank account.
Refresh the token when it expires
Access tokens last 15 minutes. When a request returns 403 Invalid or expired access token, get a new one with your refresh token. No API key is needed.
Set up webhooks
Add your webhook URL in the Shimi dashboard (Settings → Webhook) so you’re told about deposits and payout outcomes as they happen. See Webhooks.
Next steps
- Read Access & KYB for the errors every authenticated call can return.
- Read Responses & idempotency before you move money.
- Browse the API reference.
