Braintree Read-Only Access
Use this guide when you want Reveal to read Braintree data without connecting full Account Admin API keys. You create a limited role, assign it to an API user, then collect Merchant ID, Public Key, and Private Key for that user.
This page lists what Reveal requires. Create the role, user, and keys in the Braintree Control Panel using Braintree’s documentation for the latest UI. After you have the credentials, follow Braintree to add the source in Reveal Transactions and register the webhook.
Note
Braintree’s Control Panel labels and navigation can change. Use Braintree’s documentation for up-to-date Control Panel steps. Keep the Reveal requirements on this page as your checklist when setup is complete.
Before you start
- Sign in to the Braintree Control Panel as an Account Admin (required to create roles and users).
- Use an email address you can access for the API user activation link.
- Decide which Braintree merchant accounts Reveal should cover. You assign them when you create the API user.
- Use the same environment you will connect in Reveal (sandbox or production).
Create a limited access role in Braintree
What Reveal needs from this step: a custom role that includes the rights below (including Manage Webhooks, unless an Account Admin will create the Reveal webhook later).
In Braintree, create a new role (for example, named Reveal read-only) and grant at least:
- Transactions: Download Transactions with Masked Payment Data
- Reporting: Create, Run and Download Reports
- Fraud Tools: Select All
- Recurring Billing: Select All
- Dispute Management: View, Manage and contest disputes
- Webhooks: Manage Webhooks
- Statements: View Statements
- Read only Access: View Merchant Accounts, Payment Methods, Transactions, Verifications, Download Files
- Search: Search Transactions, Search Verifications
Create and edit roles from Team in the Braintree Control Panel. Braintree documents role and webhook permission changes in Webhooks overview (user permissions section).
If your security team removes Manage Webhooks from this role, an Account Admin must create the Reveal webhook after you connect the source.
Create a user for API access
What Reveal needs from this step: an API-enabled Braintree user assigned to the limited role, with access to the merchant accounts you want in Reveal, and an activated login.
In Braintree, create a user that:
- Can sign in with an email you control (complete activation before generating keys).
- Has API access enabled.
- Uses the limited role you created for Reveal.
- Includes every merchant account Reveal should analyze.
Braintree recommends a dedicated API user for integrations rather than an individual employee’s keys. See Braintree: go live (API user guidance).
Generate API keys for the read-only user
What Reveal needs from this step: Public Key, Private Key, and Merchant ID for the API user in the correct environment.
- Sign in to Braintree as the activated API user (not as a different employee’s user).
- Open that user’s API authorizations and copy:
- Public Key and Private Key
- Merchant ID for the gateway environment
For where Braintree surfaces these values, see Braintree: go live (get credentials). Keys are user- and environment-specific.
Store the credentials securely. You will paste them into Reveal when you add Braintree as a source.
Connect the keys in Reveal
On the Braintree page:
- Add Braintree under Transactions > Sources using Merchant ID, Public Key, Private Key, and an Alias.
- Copy the Reveal webhook URL for that source and create the webhook in Braintree using Create a webhook.
Take the next step
- Braintree: Add the source in Reveal and configure the webhook.
- Get started with Transactions: See the shared connection workflow across processors.
- Settlements Braintree read-only access: Same least-privilege pattern if you also connect Braintree for Settlements.
Was this article helpful?