cURL
#!/usr/bin/env bash
# Disable redirect signing for this merchant. Idempotent: 204 even if already
# null. Downgrade risk: once disabled, redirect URLs carry no signature —
# always confirm the payment server-side (webhook or authenticated GET), not
# from the redirect alone.
set -euo pipefail
API_BASE="${RADIUMONE_API_BASE:-https://api-sandbox.radiumone.io/gateway}"
: "${RADIUMONE_ACCESS_TOKEN:?set RADIUMONE_ACCESS_TOKEN to a Bearer access token with the merchant-secret-rotate scope}"
curl -sS -o /dev/null -w '%{http_code}\n' -X DELETE "$API_BASE/v1/merchant/redirect-secret" \
-H "Authorization: Bearer $RADIUMONE_ACCESS_TOKEN"#!/usr/bin/env python3
"""Disable redirect signing for this merchant. Idempotent: 204 even if
already null. Downgrade risk — once disabled, redirect URLs carry no
signature; always confirm the payment server-side (webhook or authenticated
GET), not from the redirect alone.
"""
import os
import requests
API_BASE = os.environ.get("RADIUMONE_API_BASE", "https://api-sandbox.radiumone.io/gateway")
def delete_redirect_secret() -> int:
resp = requests.delete(
f"{API_BASE}/v1/merchant/redirect-secret",
headers={"Authorization": f"Bearer {os.environ.get('RADIUMONE_ACCESS_TOKEN', '')}"},
timeout=30,
)
if resp.status_code != 204:
payload = resp.json() if resp.content else {}
code = payload.get("type") or payload.get("code")
raise RuntimeError(f"redirect-secret delete failed: {code} ({resp.status_code})")
return resp.status_code
if __name__ == "__main__":
print(f"disabled (HTTP {delete_redirect_secret()})")
{
"detail": "Missing or invalid Bearer token.",
"status": 401,
"title": "Authentication Required",
"type": "urn:radiumone:gateway:authentication-required"
}{
"detail": "Insufficient permissions for this operation.",
"status": 403,
"title": "Permission Denied",
"type": "urn:radiumone:gateway:permission-denied"
}{
"detail": "The requested resource does not exist.",
"status": 404,
"title": "Not Found",
"type": "urn:radiumone:gateway:not-found"
}{
"detail": "A resource with that identifier already exists.",
"status": 409,
"title": "Conflict",
"type": "urn:radiumone:gateway:conflict"
}{
"detail": "The payment token has expired or its card data is no longer available.",
"status": 410,
"title": "Gone",
"type": "urn:radiumone:gateway:gone"
}{
"detail": "An unexpected error occurred.",
"status": 500,
"title": "Internal Server Error",
"type": "urn:radiumone:gateway:internal-server-error"
}{
"detail": "A downstream dependency is unavailable or did not respond in time.",
"status": 503,
"title": "Service Unavailable",
"type": "urn:radiumone:gateway:service-unavailable"
}Disable redirect signing - Payments API
Clear your redirect secret to stop signing hosted checkout redirects. Safe to retry — returns 204 even if signing is already off.
DELETE
/
v1
/
merchant
/
redirect-secret
cURL
#!/usr/bin/env bash
# Disable redirect signing for this merchant. Idempotent: 204 even if already
# null. Downgrade risk: once disabled, redirect URLs carry no signature —
# always confirm the payment server-side (webhook or authenticated GET), not
# from the redirect alone.
set -euo pipefail
API_BASE="${RADIUMONE_API_BASE:-https://api-sandbox.radiumone.io/gateway}"
: "${RADIUMONE_ACCESS_TOKEN:?set RADIUMONE_ACCESS_TOKEN to a Bearer access token with the merchant-secret-rotate scope}"
curl -sS -o /dev/null -w '%{http_code}\n' -X DELETE "$API_BASE/v1/merchant/redirect-secret" \
-H "Authorization: Bearer $RADIUMONE_ACCESS_TOKEN"#!/usr/bin/env python3
"""Disable redirect signing for this merchant. Idempotent: 204 even if
already null. Downgrade risk — once disabled, redirect URLs carry no
signature; always confirm the payment server-side (webhook or authenticated
GET), not from the redirect alone.
"""
import os
import requests
API_BASE = os.environ.get("RADIUMONE_API_BASE", "https://api-sandbox.radiumone.io/gateway")
def delete_redirect_secret() -> int:
resp = requests.delete(
f"{API_BASE}/v1/merchant/redirect-secret",
headers={"Authorization": f"Bearer {os.environ.get('RADIUMONE_ACCESS_TOKEN', '')}"},
timeout=30,
)
if resp.status_code != 204:
payload = resp.json() if resp.content else {}
code = payload.get("type") or payload.get("code")
raise RuntimeError(f"redirect-secret delete failed: {code} ({resp.status_code})")
return resp.status_code
if __name__ == "__main__":
print(f"disabled (HTTP {delete_redirect_secret()})")
{
"detail": "Missing or invalid Bearer token.",
"status": 401,
"title": "Authentication Required",
"type": "urn:radiumone:gateway:authentication-required"
}{
"detail": "Insufficient permissions for this operation.",
"status": 403,
"title": "Permission Denied",
"type": "urn:radiumone:gateway:permission-denied"
}{
"detail": "The requested resource does not exist.",
"status": 404,
"title": "Not Found",
"type": "urn:radiumone:gateway:not-found"
}{
"detail": "A resource with that identifier already exists.",
"status": 409,
"title": "Conflict",
"type": "urn:radiumone:gateway:conflict"
}{
"detail": "The payment token has expired or its card data is no longer available.",
"status": 410,
"title": "Gone",
"type": "urn:radiumone:gateway:gone"
}{
"detail": "An unexpected error occurred.",
"status": 500,
"title": "Internal Server Error",
"type": "urn:radiumone:gateway:internal-server-error"
}{
"detail": "A downstream dependency is unavailable or did not respond in time.",
"status": 503,
"title": "Service Unavailable",
"type": "urn:radiumone:gateway:service-unavailable"
}Authorizations
Bearer access token from POST /v1/auth/token. Treat it as an opaque string — do not depend on its internal encoding, which has changed before and isn't part of the contract.
Response
Successful Response
Last modified on September 15, 2026