Outcomes & errors
RezolvePay, not the provider, is the authority on a payment. A provider success is not proof the payment was recorded — the SDK polls GET /api/v1/payments/{payment_id}/status to a terminal value before it reports anything.
| Result | Meaning | What your app should do |
|---|---|---|
onSuccess | RezolvePay recorded confirmed. | Fulfil the order. Safe to treat as final. |
onFailure, needsReconciliation: false | Declined or errored. message is safe to show a shopper; code is the provider's. | Show the message. To retry, mint a new token and mount again. |
onFailure, needsReconciliation: true | Outcome unknown — the poll ran out of budget. The payment may still confirm. | Do not tell the shopper it failed, and do not re-charge. Reconcile paymentId server-side, or wait for your webhook. |
Endpoints the SDK calls
Six, and nothing else — all against the configured baseUrl. Each is documented in full in the reference above; follow the link for parameters, responses and errors.
| Endpoint | When the SDK calls it |
|---|---|
POST /api/v1/checkout/init | Only on the SDK-minting path. The one call that carries merchant credentials; a host that mints on its own backend never reaches it. |
POST /api/v1/checkout/lookup | On mount. Reads the order, the card field's configuration and the saved cards. Does not spend the token — an abandoned form leaves it usable. |
POST /api/v1/mobile/checkout | On Pay. This is what spends the token, and what returns provider_params and the payment_client_token. |
GET /api/v1/payments/{payment_id}/status | Polled to a terminal status. Authenticated by the payment_client_token, not merchant credentials. |
DELETE /api/v1/saved-payment-methods/{id} | Edit Payment Methods — remove a card. |
POST /api/v1/payment-methods/{id}/set-default | Edit Payment Methods — set the default card. |
Testing
In a sandbox merchant, the standard test card numbers behave as they do on the web — 4242 4242 4242 4242 succeeds, 4000 0027 6000 3184 forces a 3DS challenge, and 4000 0000 0000 0002 declines. No test payment reaches a real card.
To run against a development stack on your machine, point baseUrl at your own machine on port 3000 — an iOS simulator reaches it via the loopback interface, an Android emulator as 10.0.2.2. Both platforms block cleartext HTTP by default, so a development run needs a debug-only exception (NSAllowsLocalNetworking on iOS, a scoped network_security_config on Android). Neither belongs in a release build.
Updated about 4 hours ago

