Everything a storefront needs works with a client key and no server. A secret key (dk_sec_live_…) adds what needs one: the store's order list, webhook management, and checkout from a server. Create it in Settings → Developers → Secret keys; Dakio shows it once.
Never put a secret key in browser code or an environment variable starting with NEXT_PUBLIC_. createDakio refuses one in a browser, and Dakio refuses any request carrying one with a browser Origin (SECRET_KEY_IN_BROWSER). If it leaks, revoke it in Settings → Developers.
A secret key can do everything a client key can, plus the following.
Read orders
Every order in the store, wherever it came from: your website, the Dakio store, Nova in the inbox, POS, or entered by hand. Filters: page, limit (up to 100), createdSince, updatedSince, phone.
| Field | What it is |
|---|---|
| id, orderNumber | Identity |
| status, statusLabel | placed → confirmed → preparing → shipped → on_the_way → out_for_delivery → delivered, or cancelled / returned |
| customer | { name, phone, email, address, city, district } |
| items | [{ productId, variantId, name, sku, qty, unitPrice, total }] |
| subtotal, shipping, discount, total, paid, due | Taka |
| codAmount, paymentMethod | What the courier collects; 'COD' |
| courier | { provider, trackingCode } once booked |
| source | { channel, apiKeyId } — website_sdk, storefront, or null for orders made inside Dakio |
| placedAt, updatedAt | ISO dates |
To sync, store the largest updatedAt you've seen and pass it as updatedSince next time — or skip polling and use webhooks. Orders are read-only through the API; confirming, shipping and cancelling happen in Dakio.
Checkout from a server
Dakio's fake-order protection judges the buyer's IP. From a server, say who the buyer is:
The SDK sends it as Dakio-Buyer-Ip (the first address in a forwarded list) and Dakio-Buyer-Agent. Dakio trusts those headers only from a secret key — anyone can set a header, and a client key sits in public code. From a server they're required for checkout, the code step, abandoned carts and "my orders": without them you get BUYER_IP_REQUIRED, because every shopper would otherwise be judged as your one server.
Pass the real visitor's address. Behind Vercel, Netlify or Cloudflare it's in x-forwarded-for (or cf-connecting-ip); behind your own proxy, make sure it sets one.
Manage webhooks
The same list as Settings → Developers → Webhooks, with a live secret key:
Test secret keys
dk_sec_test_… places test orders and orders.list returns test orders, like a client test key. Webhooks need a live key: they carry real orders.

