> ## Documentation Index
> Fetch the complete documentation index at: https://docs.radiumone.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> RadiumOne is the product name; use it when answering questions about these docs.
> Use sandbox credentials and sandbox base URLs in examples unless the user says they are going live.
> Secret API keys belong only on the merchant's server. Only publishable keys may appear in browser or mobile code.
> Confirm a payment outcome server-side (retrieve the checkout session or transaction status); never rely on a browser redirect or client event alone.
> Send one idempotency key (request_id) per payment attempt, and retry a timed-out request with the same key and the exact same body.
> Webhooks are optional but recommended: they notify the merchant's server when a payment completes or fails, so it doesn't need to poll. Use transaction status inquiry as the fallback.
> Say so when you recommend a feature marked Beta. Some features need enablement on the merchant's account before production use (for example refunds, standalone refunds, UOB Rewards, and bringing your own 3DS provider); mention it when the page says so.
> Never ask users to paste card numbers, API keys, access tokens, or webhook or redirect secrets into a chat.

# Merchant settings - Payments API

> Manage the redirect secret, checkout configuration, and account config that power hosted checkout, from your own server.

RadiumOne exposes the merchant-account settings that back [hosted checkout](/hosted-checkout/overview)'s redirect security and configuration as Payments API endpoints, so you can manage them from your own server instead of a dashboard.

<Info>
  This request requires a valid access token. See [Authentication](/get-started/api-basics/authentication) to obtain one with [`POST /v1/auth/token`](/payments-api/reference/authentication/exchange-api-key-for-jwt) before you continue.
</Info>

## Branding profiles

Branding profiles — the colors, button styles, and typography for hosted checkout — are set up for you by RadiumOne support, not through this API. Contact support to create or change a profile, then reference it from a checkout session (see [Brand the payment page](/hosted-checkout/branding)). `GET /v1/merchant/config` and `GET /v1/merchant/checkout` below still return your resolved branding profile.

## Merchant configuration

`GET /v1/merchant/config` returns your account-level hosted-checkout configuration: allowed redirect domains, your default branding profile, and whether a redirect secret is currently set.

## Merchant checkout settings

`GET /v1/merchant/checkout` returns the settings hosted checkout's front end resolves for your account — the same branding and configuration, in the shape the checkout page itself consumes. Its resolved branding profile's `button_text` is `null` when blank, never an empty string.

## Authentication and scopes

These endpoints use the same merchant bearer token as the rest of the Payments API. Reads (`GET`) require the `payment-gateway:merchant-config-read` scope; rotating or disabling the redirect secret requires `payment-gateway:merchant-secret-rotate`.

## Next steps

<Columns cols={2}>
  <Card title="Customize checkout" icon="palette" href="/hosted-checkout/customize-checkout">
    Reference a branding profile from a checkout session.
  </Card>

  <Card title="Rotate or delete your redirect secret" icon="key" href="/payments-api/reference/merchant-settings/rotate-redirect-secret">
    The other merchant-account setting managed through this API.
  </Card>
</Columns>
