> ## Documentation Index
> Fetch the complete documentation index at: https://docs.radiumone.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> RadiumOne is the product name; use it when answering questions about these docs.
> Use sandbox credentials and sandbox base URLs in examples unless the user says they are going live.
> Secret API keys belong only on the merchant's server. Only publishable keys may appear in browser or mobile code.
> Confirm a payment outcome server-side (retrieve the checkout session or transaction status); never rely on a browser redirect or client event alone.
> Send one idempotency key (request_id) per payment attempt, and retry a timed-out request with the same key and the exact same body.
> Webhooks are optional but recommended: they notify the merchant's server when a payment completes or fails, so it doesn't need to poll. Use transaction status inquiry as the fallback.
> Say so when you recommend a feature marked Beta. Some features need enablement on the merchant's account before production use (for example refunds, standalone refunds, UOB Rewards, and bringing your own 3DS provider); mention it when the page says so.
> Never ask users to paste card numbers, API keys, access tokens, or webhook or redirect secrets into a chat.

# Rotate redirect secret - Payments API

> Generate a new secret for signing hosted checkout redirects. The response contains the new secret in plaintext, so store it securely right away.



## OpenAPI

````yaml /openapi/radiumone-payments-api.yaml post /v1/merchant/redirect-secret/rotate
openapi: 3.1.0
info:
  description: |
    The Payments API lets your server create tokenization sessions, charge and
    manage payments, check loyalty balances, and manage your hosted-checkout
    branding and redirect secret. Generated for merchant integrators —
    internal, admin, and service-to-service surfaces are excluded.

    All responses share an envelope: `{status, data, request_id}`. The
    envelope's `request_id` is an HTTP correlation ID — it echoes your
    `X-Request-Id` request header (letters, digits, hyphens, max 36 characters)
    or one is generated for you. It is **not** the idempotency key you send in
    a transaction request body (also confusingly named `request_id` there) —
    the two are unrelated; see
    [Request conventions](/get-started/api-basics/request-conventions). Errors
    use [RFC 9457](https://www.rfc-editor.org/rfc/rfc9457)
    `application/problem+json` bodies — see
    [Authentication](/get-started/api-basics/authentication) and
    [Request conventions](/get-started/api-basics/request-conventions) for the
    shared error shape, and [Problem format and
    retries](/payments-api/errors/problem-format-and-retries) for the response
    shape, status guide, and retry rules.
  summary: Transaction orchestration and processor aggregation for RadiumOne.
  title: RadiumOne Payment Gateway
  version: 1.3.0
servers:
  - url: https://api-sandbox.radiumone.io/gateway
    description: Sandbox
  - url: https://api.radiumone.io/gateway
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Authentication
    description: Exchange, refresh, and revoke access tokens.
  - name: Merchant settings
    description: >-
      Manage your hosted-checkout redirect secret, checkout configuration, and
      account config.
  - name: Payment methods
    description: Discover which payment methods and brands are available.
  - name: Sessions
    description: Tokenization sessions used to collect card data with RadiumOne Elements.
  - name: Settlement
    description: Settlement batch status lookup.
  - name: Payments
    description: Create and manage card transactions.
  - name: Rewards
    description: UOB Rewards loyalty balance inquiry.
  - name: Refunds
    description: Return funds to a shopper.
  - name: Transactions
    description: Check the live status of a transaction.
paths:
  /v1/merchant/redirect-secret/rotate:
    post:
      tags:
        - Merchant settings
      summary: Rotate redirect secret
      description: >-
        Generate a new redirect secret, replacing the current one.


        The redirect secret signs the query string of `success_url` and
        `cancel_url` redirects

        so your backend can verify a redirect came from RadiumOne Checkout. The
        new secret is

        returned in the response; store it securely. Redirects signed after this
        call use the

        new secret, so update your verification before or immediately after
        rotating.
      operationId: rotate_redirect_secret_v1_merchant_redirect_secret_rotate_post
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/SuccessResponse_RedirectSecretRotateResponse_
          description: Successful Response
        '401':
          content:
            application/problem+json:
              example:
                detail: Missing or invalid Bearer token.
                status: 401
                title: Authentication Required
                type: urn:radiumone:gateway:authentication-required
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: Missing or invalid Bearer token.
        '403':
          content:
            application/problem+json:
              example:
                detail: Insufficient permissions for this operation.
                status: 403
                title: Permission Denied
                type: urn:radiumone:gateway:permission-denied
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: Insufficient permissions for this operation.
        '404':
          content:
            application/problem+json:
              example:
                detail: The requested resource does not exist.
                status: 404
                title: Not Found
                type: urn:radiumone:gateway:not-found
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: The requested resource does not exist.
        '409':
          content:
            application/problem+json:
              example:
                detail: A resource with that identifier already exists.
                status: 409
                title: Conflict
                type: urn:radiumone:gateway:conflict
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: A resource with that identifier already exists.
        '410':
          content:
            application/problem+json:
              example:
                detail: >-
                  The payment token has expired or its card data is no longer
                  available.
                status: 410
                title: Gone
                type: urn:radiumone:gateway:gone
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: >-
            The payment token has expired or its card data is no longer
            available.
        '500':
          content:
            application/problem+json:
              example:
                detail: An unexpected error occurred.
                status: 500
                title: Internal Server Error
                type: urn:radiumone:gateway:internal-server-error
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: An unexpected error occurred.
        '503':
          content:
            application/problem+json:
              example:
                detail: >-
                  A downstream dependency is unavailable or did not respond in
                  time.
                status: 503
                title: Service Unavailable
                type: urn:radiumone:gateway:service-unavailable
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: A downstream dependency is unavailable or did not respond in time.
      x-codeSamples:
        - lang: bash
          label: cURL
          source: >
            #!/usr/bin/env bash

            # Rotate the redirect-signature secret. The plaintext is returned
            exactly

            # once — store it immediately. Old and new secrets both verify for a
            grace

            # window after rotation.

            set -euo pipefail


            API_BASE="${RADIUMONE_API_BASE:-https://api-sandbox.radiumone.io/gateway}"

            : "${RADIUMONE_ACCESS_TOKEN:?set RADIUMONE_ACCESS_TOKEN to a Bearer
            access token with the merchant-secret-rotate scope}"


            curl -sS -X POST "$API_BASE/v1/merchant/redirect-secret/rotate" \
              -H "Authorization: Bearer $RADIUMONE_ACCESS_TOKEN"
        - lang: javascript
          label: Node.js
          source: >
            #!/usr/bin/env node

            // Rotate the redirect-signature secret. The plaintext is returned
            exactly

            // once — store it immediately. Node 18+ ESM fetch.

            // Env: RADIUMONE_ACCESS_TOKEN, RADIUMONE_API_BASE.

            const API_BASE = process.env.RADIUMONE_API_BASE ||
            "https://api-sandbox.radiumone.io/gateway";

            const accessToken = process.env.RADIUMONE_ACCESS_TOKEN;


            async function rotateRedirectSecret() {
              const res = await fetch(`${API_BASE}/v1/merchant/redirect-secret/rotate`, {
                method: "POST",
                headers: { Authorization: `Bearer ${accessToken}` },
              });
              const payload = await res.json();
              if (!res.ok) {
                throw new Error(`redirect-secret rotate failed: ${payload.type ?? payload.code} (${res.status})`);
              }
              // Never log payload.data.redirect_secret — store it in your secret manager only.
              return payload;
            }


            rotateRedirectSecret().then((r) => console.log(JSON.stringify(r,
            null, 2)));
        - lang: python
          label: Python
          source: >
            #!/usr/bin/env python3

            """Rotate the redirect-signature secret. The plaintext is returned
            exactly

            once — store it immediately.

            """

            import json

            import os


            import requests


            API_BASE = os.environ.get("RADIUMONE_API_BASE",
            "https://api-sandbox.radiumone.io/gateway")



            def rotate_redirect_secret() -> dict:
                resp = requests.post(
                    f"{API_BASE}/v1/merchant/redirect-secret/rotate",
                    headers={"Authorization": f"Bearer {os.environ.get('RADIUMONE_ACCESS_TOKEN', '')}"},
                    timeout=30,
                )
                payload = resp.json()
                if not resp.ok:
                    code = payload.get("type") or payload.get("code")
                    raise RuntimeError(f"redirect-secret rotate failed: {code} ({resp.status_code})")
                # Never log payload["data"]["redirect_secret"] — store it in your secret manager only.
                return payload


            if __name__ == "__main__":
                print(json.dumps(rotate_redirect_secret(), indent=2))
components:
  schemas:
    SuccessResponse_RedirectSecretRotateResponse_:
      description: >-
        Standard success envelope. Every successful response has this shape,
        with the operation's own payload under `data`.
      properties:
        data:
          anyOf:
            - $ref: '#/components/schemas/RedirectSecretRotateResponse'
            - type: 'null'
          description: >-
            The operation's result. Its shape is documented per operation;
            omitted on responses that carry no payload.
        message:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Optional human-readable note. Omitted from the response when not
            set, which is the case for every payment operation today. Never
            parse it.
          title: Message
        request_id:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Correlation ID for this HTTP request, for logs and support. Send
            your own in the `X-Request-Id` header (letters, digits and hyphens,
            up to 36 characters -- other characters are stripped) or the gateway
            generates one. This is NOT the `request_id` idempotency key you send
            in a transaction body; the two are unrelated.
          title: Request Id
        status:
          default: ok
          description: >-
            Always `ok` on a successful (2xx) response. Errors use a different
            body shape entirely (RFC 9457 problem details), so branch on the
            HTTP status code, not on this field.
          title: Status
          type: string
      title: SuccessResponse[RedirectSecretRotateResponse]
      type: object
    RedirectSecretRotateResponse:
      description: Response payload for POST /v1/merchant/redirect-secret/rotate.
      properties:
        redirect_secret:
          description: >-
            The new redirect secret. Store it securely and update your redirect
            verification to use it. Secret API keys also receive the current
            secret when they exchange or refresh an access token.
          title: Redirect Secret
          type: string
        rotated_at:
          description: ISO-8601 timestamp at which this rotation took effect.
          title: Rotated At
          type: string
      required:
        - redirect_secret
        - rotated_at
      title: RedirectSecretRotateResponse
      type: object
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Bearer access token from `POST /v1/auth/token`. Treat it as an opaque
        string — do not depend on its internal encoding, which has changed
        before and isn't part of the contract.
      x-docs-interim: true

````