Skip to main content
POST
cURL

Authorizations

Authorization
string
header
required

Bearer access token from POST /v1/auth/token. Treat it as an opaque string — do not depend on its internal encoding, which has changed before and isn't part of the contract.

Body

application/json

Optional body for creating a checkout session.

Every field is optional. You don't send your merchant ID -- it is taken from your access token.

amount
integer | null

Amount in smallest currency unit (optional; enables amount-conditioned discovery).

Required range: x >= 0
cancel_url
string | null

Payment-cancel redirect URL. Validated against the merchant's allowed_domains (422 on mismatch).

Maximum string length: 2048
currency
string | null

ISO 4217 currency code. When set, response includes supported payment_methods.

Required string length: 3
Pattern: ^[A-Za-z]{3}$
ip_address
string | null

Your customer's IP address, used as a fraud signal (optional).

Maximum string length: 45
outlet_id
string | null

Outlet UUID for discovery. Defaults to the merchant's DEFAULT outlet.

success_url
string | null

Post-payment redirect URL. Validated against the merchant's allowed_domains (422 on mismatch).

Maximum string length: 2048
ttl_minutes
integer | null

How long the session stays valid, in minutes (5–60). Defaults to 30.

Required range: 5 <= x <= 60
user_agent
string | null

Your customer's browser User-Agent, used as a fraud signal (optional).

Maximum string length: 512

Response

Successful Response

Standard success envelope. Every successful response has this shape, with the operation's own payload under data.

data
SessionCreatedResponse · object | null

The operation's result. Its shape is documented per operation; omitted on responses that carry no payload.

message
string | null

Optional human-readable note. Omitted from the response when not set, which is the case for every payment operation today. Never parse it.

request_id
string | null

Correlation ID for this HTTP request, for logs and support. Send your own in the X-Request-Id header (letters, digits and hyphens, up to 36 characters -- other characters are stripped) or the gateway generates one. This is NOT the request_id idempotency key you send in a transaction body; the two are unrelated.

status
string
default:ok

Always ok on a successful (2xx) response. Errors use a different body shape entirely (RFC 9457 problem details), so branch on the HTTP status code, not on this field.

Last modified on September 15, 2026