LedgerBlock API requests require authentication and, where enabled for your merchant account, requests must originate from an approved IP address.
Authentication
Authentication is required to access protected LedgerBlock API endpoints.
Your authentication credentials identify your merchant account and authorize your application to interact with LedgerBlock services.
Authentication Headers
LedgerBlock requests use authentication information in the request headers.
Depending on the endpoint, the required headers may include:
| Header | Required | Description |
|---|---|---|
Authorization | Yes* | Authentication credential used to authorize the request |
x-merchant-ref | Yes* | Identifies the merchant making the request |
Content-Type | Where applicable | Specifies the format of the request body |
- Required headers may vary by endpoint. Always check the authentication requirements shown on the specific API endpoint.
Example Request
GET https://block.fuspay.finance/api/v1/utility/operators
Authorization: Bearer YOUR_API_KEY
x-merchant-ref: YOUR_MERCHANT_REF
Content-Type: application/jsonReplace the placeholder values with the credentials associated with your LedgerBlock merchant account.
Never include real API credentials in documentation, source code, frontend applications, screenshots, or publicly accessible repositories.
Merchant Reference
The x-merchant-ref header identifies the merchant associated with the API request.
Example:
x-merchant-ref: YOUR_MERCHANT_REFThe merchant reference should be included exactly as provided when the endpoint documentation specifies it as required.
Authorization
The Authorization header is used to authenticate requests to protected LedgerBlock endpoints.
Example:
Authorization: Bearer YOUR_API_KEYKeep your API credentials on your server and never expose them in client-side applications.
Recommended Credential Handling
Store your credentials securely using environment variables or a secrets-management solution.
For example:
LEDGERBLOCK_API_KEY=your_api_key
LEDGERBLOCK_MERCHANT_REF=your_merchant_referenceYour application should read these values at runtime rather than hard-coding them into the application source code.
IP Whitelisting
IP whitelisting provides an additional layer of security by restricting API access to requests originating from approved IP addresses.
When IP whitelisting is enabled for your merchant account, LedgerBlock only accepts API requests originating from the IP addresses registered for your account.
How IP Whitelisting Works
The process is:
- Your server sends a request to LedgerBlock.
- LedgerBlock identifies the originating IP address.
- The IP address is checked against the IP addresses registered for your merchant account.
- If the IP address is authorized, the request proceeds to authentication and processing.
- If the IP address is not authorized, the request is rejected.
Which IP Address Should Be Whitelisted?
Whitelist the public outbound IP address used by your backend server when communicating with LedgerBlock.
Do not whitelist:
- Your personal computer's local IP address
localhost- Private network addresses such as
192.168.x.x - Private network addresses such as
10.x.x.x - An IP address that is not used by your production server to make outbound API requests
For cloud deployments, confirm the outbound or egress IP address configured for the service.
Multiple Servers
If your application sends LedgerBlock API requests from multiple servers with different public IP addresses, each IP address that needs API access should be registered for whitelisting.
For example:
203.0.113.10
203.0.113.11
203.0.113.12Only add IP addresses that are actually required by your integration.
Changing Your Server IP
If your production server's public IP address changes, API requests may be rejected if the new IP has not been added to your approved whitelist.
Before migrating servers or changing your infrastructure:
- Identify the new outbound public IP.
- Request that the new IP be added to your merchant whitelist.
- Confirm that the new IP is active.
- Update your application infrastructure.
- Verify API connectivity.
Security Best Practices
For a secure LedgerBlock integration:
- Keep API credentials private.
- Store credentials in environment variables or a secrets manager.
- Make API requests from your backend rather than directly from the browser.
- Restrict API access to known production server IP addresses where IP whitelisting is enabled.
- Do not commit credentials to Git repositories.
- Do not expose credentials in logs or error messages.
- Rotate credentials if they are accidentally exposed.
- Remove old or unused IP addresses from your whitelist.
Important: Production credentials provide access to live LedgerBlock services. Treat them as sensitive credentials and restrict access to authorized systems and personnel only.

