> ## Documentation Index
> Fetch the complete documentation index at: https://docs.radiumone.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> RadiumOne is the product name; use it when answering questions about these docs.
> Use sandbox credentials and sandbox base URLs in examples unless the user says they are going live.
> Secret API keys belong only on the merchant's server. Only publishable keys may appear in browser or mobile code.
> Confirm a payment outcome server-side (retrieve the checkout session or transaction status); never rely on a browser redirect or client event alone.
> Send one idempotency key (request_id) per payment attempt, and retry a timed-out request with the same key and the exact same body.
> Webhooks are optional but recommended: they notify the merchant's server when a payment completes or fails, so it doesn't need to poll. Use transaction status inquiry as the fallback.
> Say so when you recommend a feature marked Beta. Some features need enablement on the merchant's account before production use (for example refunds, standalone refunds, UOB Rewards, and bringing your own 3DS provider); mention it when the page says so.
> Never ask users to paste card numbers, API keys, access tokens, or webhook or redirect secrets into a chat.

# Get merchant configuration - Payments API

> Retrieve your merchant account's configuration, including hosted checkout settings. Secrets are never returned in plaintext.



## OpenAPI

````yaml /openapi/radiumone-payments-api.yaml get /v1/merchant/config
openapi: 3.1.0
info:
  description: |
    The Payments API lets your server create tokenization sessions, charge and
    manage payments, check loyalty balances, and manage your hosted-checkout
    branding and redirect secret. Generated for merchant integrators —
    internal, admin, and service-to-service surfaces are excluded.

    All responses share an envelope: `{status, data, request_id}`. The
    envelope's `request_id` is an HTTP correlation ID — it echoes your
    `X-Request-Id` request header (letters, digits, hyphens, max 36 characters)
    or one is generated for you. It is **not** the idempotency key you send in
    a transaction request body (also confusingly named `request_id` there) —
    the two are unrelated; see
    [Request conventions](/get-started/api-basics/request-conventions). Errors
    use [RFC 9457](https://www.rfc-editor.org/rfc/rfc9457)
    `application/problem+json` bodies — see
    [Authentication](/get-started/api-basics/authentication) and
    [Request conventions](/get-started/api-basics/request-conventions) for the
    shared error shape, and [Problem format and
    retries](/payments-api/errors/problem-format-and-retries) for the response
    shape, status guide, and retry rules.
  summary: Transaction orchestration and processor aggregation for RadiumOne.
  title: RadiumOne Payment Gateway
  version: 1.3.0
servers:
  - url: https://api-sandbox.radiumone.io/gateway
    description: Sandbox
  - url: https://api.radiumone.io/gateway
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Authentication
    description: Exchange, refresh, and revoke access tokens.
  - name: Merchant settings
    description: >-
      Manage your hosted-checkout redirect secret, checkout configuration, and
      account config.
  - name: Payment methods
    description: Discover which payment methods and brands are available.
  - name: Sessions
    description: Tokenization sessions used to collect card data with RadiumOne Elements.
  - name: Settlement
    description: Settlement batch status lookup.
  - name: Payments
    description: Create and manage card transactions.
  - name: Rewards
    description: UOB Rewards loyalty balance inquiry.
  - name: Refunds
    description: Return funds to a shopper.
  - name: Transactions
    description: Check the live status of a transaction.
paths:
  /v1/merchant/config:
    get:
      tags:
        - Merchant settings
      summary: Get merchant configuration
      description: >-
        Return your merchant configuration.


        Includes your allowed domains, default branding profile id, whether a
        redirect secret

        is configured and when it was last rotated. Secrets themselves are never
        returned.


        Pass `branding_profile_id` to embed a branding profile in the same
        response. The

        embedded profile is the one you requested if it exists and belongs to
        you, otherwise

        your default profile, otherwise `null`. An unknown or foreign
        `branding_profile_id`

        never returns 404.
      operationId: get_merchant_config_v1_merchant_config_get
      parameters:
        - description: >-
            Branding profile to embed in the response. If the id is unknown or
            not one of your profiles, your default branding profile is embedded
            instead.
          in: query
          name: branding_profile_id
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            description: >-
              Branding profile to embed in the response. If the id is unknown or
              not one of your profiles, your default branding profile is
              embedded instead.
            title: Branding Profile Id
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResponse_MerchantConfigResponse_'
          description: Successful Response
        '401':
          content:
            application/problem+json:
              example:
                detail: Missing or invalid Bearer token.
                status: 401
                title: Authentication Required
                type: urn:radiumone:gateway:authentication-required
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: Missing or invalid Bearer token.
        '403':
          content:
            application/problem+json:
              example:
                detail: Insufficient permissions for this operation.
                status: 403
                title: Permission Denied
                type: urn:radiumone:gateway:permission-denied
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: Insufficient permissions for this operation.
        '404':
          content:
            application/problem+json:
              example:
                detail: The requested resource does not exist.
                status: 404
                title: Not Found
                type: urn:radiumone:gateway:not-found
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: The requested resource does not exist.
        '500':
          content:
            application/problem+json:
              example:
                detail: An unexpected error occurred.
                status: 500
                title: Internal Server Error
                type: urn:radiumone:gateway:internal-server-error
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: An unexpected error occurred.
      x-codeSamples:
        - lang: bash
          label: cURL
          source: >
            #!/usr/bin/env bash

            # Retrieve your merchant-level hosted-checkout configuration:
            allowed

            # redirect domains, default branding profile, and redirect-secret
            status.

            set -euo pipefail


            API_BASE="${RADIUMONE_API_BASE:-https://api-sandbox.radiumone.io/gateway}"

            : "${RADIUMONE_ACCESS_TOKEN:?set RADIUMONE_ACCESS_TOKEN to a Bearer
            access token (secret key)}"


            curl -sS "$API_BASE/v1/merchant/config" \
              -H "Authorization: Bearer $RADIUMONE_ACCESS_TOKEN"
        - lang: javascript
          label: Node.js
          source: >
            #!/usr/bin/env node

            // Retrieve your merchant-level hosted-checkout configuration.

            // Node 18+ ESM fetch. Env: RADIUMONE_ACCESS_TOKEN,
            RADIUMONE_API_BASE.

            const API_BASE = process.env.RADIUMONE_API_BASE ||
            "https://api-sandbox.radiumone.io/gateway";

            const accessToken = process.env.RADIUMONE_ACCESS_TOKEN;


            async function getMerchantConfig() {
              const res = await fetch(`${API_BASE}/v1/merchant/config`, {
                headers: { Authorization: `Bearer ${accessToken}` },
              });
              const payload = await res.json();
              if (!res.ok) {
                throw new Error(`merchant/config failed: ${payload.type ?? payload.code} (${res.status})`);
              }
              return payload;
            }


            getMerchantConfig().then((r) => console.log(JSON.stringify(r, null,
            2)));
        - lang: python
          label: Python
          source: >
            #!/usr/bin/env python3

            """Retrieve your merchant-level hosted-checkout configuration."""

            import json

            import os


            import requests


            API_BASE = os.environ.get("RADIUMONE_API_BASE",
            "https://api-sandbox.radiumone.io/gateway")



            def get_merchant_config() -> dict:
                resp = requests.get(
                    f"{API_BASE}/v1/merchant/config",
                    headers={"Authorization": f"Bearer {os.environ.get('RADIUMONE_ACCESS_TOKEN', '')}"},
                    timeout=30,
                )
                payload = resp.json()
                if not resp.ok:
                    code = payload.get("type") or payload.get("code")
                    raise RuntimeError(f"merchant/config failed: {code} ({resp.status_code})")
                return payload


            if __name__ == "__main__":
                print(json.dumps(get_merchant_config(), indent=2))
components:
  schemas:
    SuccessResponse_MerchantConfigResponse_:
      description: >-
        Standard success envelope. Every successful response has this shape,
        with the operation's own payload under `data`.
      properties:
        data:
          anyOf:
            - $ref: '#/components/schemas/MerchantConfigResponse'
            - type: 'null'
          description: >-
            The operation's result. Its shape is documented per operation;
            omitted on responses that carry no payload.
        message:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Optional human-readable note. Omitted from the response when not
            set, which is the case for every payment operation today. Never
            parse it.
          title: Message
        request_id:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Correlation ID for this HTTP request, for logs and support. Send
            your own in the `X-Request-Id` header (letters, digits and hyphens,
            up to 36 characters -- other characters are stripped) or the gateway
            generates one. This is NOT the `request_id` idempotency key you send
            in a transaction body; the two are unrelated.
          title: Request Id
        status:
          default: ok
          description: >-
            Always `ok` on a successful (2xx) response. Errors use a different
            body shape entirely (RFC 9457 problem details), so branch on the
            HTTP status code, not on this field.
          title: Status
          type: string
      title: SuccessResponse[MerchantConfigResponse]
      type: object
    MerchantConfigResponse:
      description: Response payload for GET /v1/merchant/config.
      properties:
        allowed_domains:
          description: >-
            Domains permitted to host your hosted-checkout and tokenization
            pages. A page served from any other origin is refused.
          items:
            type: string
          title: Allowed Domains
          type: array
        branding_profile:
          anyOf:
            - $ref: '#/components/schemas/BrandingProfileResponse'
            - type: 'null'
          description: >-
            Resolved branding profile (requested id → merchant default → null).
            Fail-open: a bad/foreign id never 404s -- it falls back to the
            default or null.
        default_branding_profile_id:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            The branding profile applied when a checkout does not name one. Null
            when you have not marked any profile as the default.
          title: Default Branding Profile Id
        has_redirect_secret:
          description: True if a redirect signing secret is currently configured.
          title: Has Redirect Secret
          type: boolean
        merchant_id:
          description: Your merchant identifier, as issued by the gateway.
          title: Merchant Id
          type: string
        merchant_name:
          description: >-
            Your registered merchant name, suitable for display on a checkout
            page.
          title: Merchant Name
          type: string
        redirect_secret_rotated_at:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            ISO-8601 timestamp of the last redirect secret rotation (null if
            never set).
          title: Redirect Secret Rotated At
      required:
        - merchant_id
        - merchant_name
        - allowed_domains
        - has_redirect_secret
      title: MerchantConfigResponse
      type: object
    BrandingProfileResponse:
      description: Response payload for a single branding profile.
      properties:
        accent_color:
          description: >-
            Accent colour used to highlight elements on the hosted checkout page
            (#RRGGBB).
          title: Accent Color
          type: string
        background_color:
          description: >-
            Page background colour of the hosted checkout page, as a hex value
            (#RRGGBB).
          title: Background Color
          type: string
        border_radius:
          description: >-
            Corner rounding for buttons and fields: 'square', 'rounded', or
            'pill'.
          title: Border Radius
          type: string
        button_color:
          description: Fill colour of the payment button (#RRGGBB).
          title: Button Color
          type: string
        button_text:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Label on the payment button. Null means the hosted checkout page
            applies its own default label.
          title: Button Text
        button_text_color:
          description: Colour of the label on the payment button (#RRGGBB).
          title: Button Text Color
          type: string
        color_scheme:
          description: >-
            Colour scheme for the hosted checkout page: 'light', 'dark', or
            'auto' to follow the shopper's device setting.
          title: Color Scheme
          type: string
        created_at:
          description: When you created this profile, as an ISO 8601 timestamp.
          title: Created At
          type: string
        display_name:
          description: >-
            The store or brand name shown to your shoppers on the hosted
            checkout page.
          title: Display Name
          type: string
        error_color:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Colour for error messages (#RRGGBB). Null means the built-in colour
            is used.
          title: Error Color
        focus_color:
          description: >-
            Colour marking the field a shopper is currently filling in
            (#RRGGBB).
          title: Focus Color
          type: string
        font_family:
          description: Font used on the hosted checkout page.
          title: Font Family
          type: string
        id:
          description: >-
            Identifier of this branding profile. Quote it when you want a
            checkout to use this profile.
          title: Id
          type: string
        is_default:
          description: >-
            True when this is your default profile, used whenever a checkout
            does not name a profile. At most one of your profiles is the
            default.
          title: Is Default
          type: boolean
        logo_url:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Link to your logo image shown on the hosted checkout page. Null if
            you have not set one.
          title: Logo Url
        merchant_id:
          description: Identifier of the merchant account that owns this profile.
          title: Merchant Id
          type: string
        name:
          description: Your internal label for this profile. Not shown to your shoppers.
          title: Name
          type: string
        primary_color:
          description: >-
            Your main brand colour on the hosted checkout page, as a hex value
            (#RRGGBB).
          title: Primary Color
          type: string
        success_color:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Colour for success messages (#RRGGBB). Null means the built-in
            colour is used.
          title: Success Color
        updated_at:
          description: When this profile was last changed, as an ISO 8601 timestamp.
          title: Updated At
          type: string
        warning_color:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Colour for warning messages (#RRGGBB). Null means the built-in
            colour is used.
          title: Warning Color
      required:
        - id
        - merchant_id
        - name
        - display_name
        - primary_color
        - background_color
        - accent_color
        - button_color
        - button_text_color
        - focus_color
        - font_family
        - color_scheme
        - border_radius
        - is_default
        - created_at
        - updated_at
      title: BrandingProfileResponse
      type: object
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Bearer access token from `POST /v1/auth/token`. Treat it as an opaque
        string — do not depend on its internal encoding, which has changed
        before and isn't part of the contract.
      x-docs-interim: true

````