⚠ 重要事項 SGPポイントの有効期限は発行日から180日(6か月未満)です。期限超過後は失効。送金・譲渡・現金化を目的としたサービスではありません。

API integration

You can issue a client ID and client secret from the dashboard. The secret is shown only once, at the moment you create it.

Updated · Read 4min · Applies to v2026.08

Issuing credentials

Use "OAuth client" in the menu.

  1. Open the screen

    After signing in, choose "OAuth client" from the menu.

  2. Generate

    A client ID and client secret are displayed.

  3. Store the secret somewhere safe

    Read the warning below first.

The client secret is shown only once

It cannot be displayed again after you close the screen. Save it into a password manager or secret store immediately.

If you lose it you must regenerate — but regenerating invalidates the previous credentials. Live integrations will stop, so plan the switchover first.

What regenerating does

Regenerating invalidates the previous client and every access token already issued.

ImpactDetail
Existing integrationsAuthentication fails and all API calls stop
Issued tokensAll revoked
RecoveryConfigure the new credentials in your systems
When to regenerate

With a live system, avoid regenerating during business hours. Payment and order integrations stop until the new values are in place.

If you suspect the secret has leaked, regenerate immediately and accept the outage.

Handling credentials

DoDo not
Keep them in environment variables or a secret storeHard-code them in source
Use them only from server-side codeEmbed them in a browser or mobile app
Limit who has accessShare them over chat or email
Regenerate when staff leaveKeep using the same values indefinitely

Never put a secret in a support ticket

Do not paste client secrets or access tokens into tickets or chat. Our staff will never ask for them.

When contacting us, send the client ID only.

Common errors

SymptomLikely causeWhat to do
Authentication fails (401)Regenerated but old values still in use, or a copy errorReconfigure with the current credentials
Forbidden (403)That feature is not in your contractCheck with support
Rejected (429)Too many calls in a short windowAdd back-off and retry
Intermittent failuresTransient network or processing errorsRetry, and make payment calls idempotent
Designing payment-related calls

A failed connection does not always mean the other side failed to process it. Design so that repeating the same operation cannot double-charge — deduplicate on the transaction ID.

Do you actually need the API?

If a payment link covers your use case, you do not need API integration. Payment links need no development and can notify your systems by webhook.

The API is the right choice when you want to:

  • Keep balances in sync with your own membership system
  • Process large volumes automatically
  • Build your own checkout experience

For technical questions, open a support ticket with the API you called, a summary of the request, and the error returned. Again — never include the secret.

Did this page help?

Your answer tells us which pages need rewriting.

法人加盟店様へ

TMAホワイトラベル・団体向け
サービスのご相談はこちら

法人加盟店様、コミュニティ、団体、会員制サービス向けに、TMAアプリ・カスタムトークン・請求管理を組み合わせたホワイトラベル型サービスをご提案します。各国の法令や提携パートナー要件を確認したうえで、安心して導入できる設計をご相談いただけます。