Skip to main content

SDKs & Libraries

Official backend SDKs for TypeScript, Python, Go, PHP, Java, Kotlin, C#, Ruby, and Rust. These libraries handle authentication, serialization, and error handling so you can focus on your integration.

Mobile Checkout SDKs

Open Dodo’s hosted checkout from Android, iOS, React Native, and Flutter apps and get a typed result back in one call. These SDKs hold no API key.

Environment URLs

  • Test Mode: https://test.dodopayments.com
  • Live Mode: https://live.dodopayments.com
Learn more about Test Mode vs Live Mode.

Authentication

API requests require an API key, except a few public endpoints such as Activate License, Validate License, and Deactivate License. Generate one in your dashboard and include it in the Authorization header of every request.
1

Generate an API Key

Go to Developer → API Keys in your dashboard and select Add API Key. Create the key in the mode you want to call: a test mode key works only with https://test.dodopayments.com, and a live mode key works only with https://live.dodopayments.com. Give the key a descriptive name and choose your access level:
  • Enable write access checked (default): Full read and write permissions for all API operations.
  • Enable write access unchecked: Read-only access. You can fetch data (payments, subscriptions, customers, products) but cannot create or modify resources.
Uncheck Enable write access for integrations that only need to view data, such as analytics tools or dashboard integrations.
2

Store Your Key Securely

Copy the key immediately. You won’t see it again. Store it in an environment variable such as DODO_PAYMENTS_API_KEY.
3

Authenticate Requests

Include your API key in the Authorization header of every request:
Never expose your API key in client-side code, public repositories, or version control.

Response Format

Successful requests return 200 or 201 with a JSON body, or 204 with no body. Errors return a 4xx or 5xx status with a JSON body that contains a code and a message.

Rate Limits

The API enforces two limits at once: a per-second burst limit and a per-minute sustained limit. Limits apply to your business as a whole, across all of its API keys, and depend on your business’s rate limit tier.

Default Tier

Higher Tiers

Businesses with increased API needs can upgrade to higher rate limits:
To upgrade your rate limit tier, email support@dodopayments.com.

Unauthenticated Requests

Requests without a valid API key are rate limited by IP address:

Rate Limit Headers

Responses include headers that show your current usage:
  • X-RateLimit-Limit — Maximum requests allowed in the current window.
  • X-RateLimit-Remaining — Requests remaining before you hit the limit.
  • X-RateLimit-Reset — Seconds until the current window resets.
When you exceed the limit, the API returns 429 Too Many Requests. Implement exponential backoff in your retry logic.

Error Handling

To find what an error means and how to resolve it, see the error codes and transaction failures pages.

Error Codes

Complete list of error codes and their meanings.

Transaction Failures

Common transaction issues and how to handle them.

Webhooks

Receive real-time notifications when payments, subscriptions, and other events occur. Set up webhooks in your dashboard and handle the events your integration needs.

Webhook Guide

Set up webhooks, handle events, and verify signatures.

Integration Guides

Start with one of these guides to build your first integration:

One-time Payments

Create checkout sessions, payment links, and handle payments.

Subscriptions

Set up recurring billing, manage plans, and handle lifecycle events.

Usage-Based Billing

Meter usage and charge customers based on consumption.

Checkout Sessions

Create secure, hosted checkout experiences.
Last modified on September 25, 2026