### Security Notice
🔒 **All endpoints requiring `x-api-key` and `x-client-id` headers MUST be called from your backend server only.** These credentials should never be exposed in client-side applications (web browsers, mobile apps, etc.) as they provide full access to your merchant account.
