Outcomes & errors

RezolvePay, not the provider, is the authority on a payment. A provider success is not proof the payment was recorded — the SDK polls GET /api/v1/payments/{payment_id}/status to a terminal value before it reports anything.

ResultMeaningWhat your app should do
onSuccessRezolvePay recorded confirmed.Fulfil the order. Safe to treat as final.
onFailure, needsReconciliation: falseDeclined or errored. message is safe to show a shopper; code is the provider's.Show the message. To retry, mint a new token and mount again.
onFailure, needsReconciliation: trueOutcome unknown — the poll ran out of budget. The payment may still confirm.Do not tell the shopper it failed, and do not re-charge. Reconcile paymentId server-side, or wait for your webhook.

Endpoints the SDK calls

Six, and nothing else — all against the configured baseUrl. Each is documented in full in the reference above; follow the link for parameters, responses and errors.

EndpointWhen the SDK calls it
POST /api/v1/checkout/initOnly on the SDK-minting path. The one call that carries merchant credentials; a host that mints on its own backend never reaches it.
POST /api/v1/checkout/lookupOn mount. Reads the order, the card field's configuration and the saved cards. Does not spend the token — an abandoned form leaves it usable.
POST /api/v1/mobile/checkoutOn Pay. This is what spends the token, and what returns provider_params and the payment_client_token.
GET /api/v1/payments/{payment_id}/statusPolled to a terminal status. Authenticated by the payment_client_token, not merchant credentials.
DELETE /api/v1/saved-payment-methods/{id}Edit Payment Methods — remove a card.
POST /api/v1/payment-methods/{id}/set-defaultEdit Payment Methods — set the default card.

Testing

In a sandbox merchant, the standard test card numbers behave as they do on the web — 4242 4242 4242 4242 succeeds, 4000 0027 6000 3184 forces a 3DS challenge, and 4000 0000 0000 0002 declines. No test payment reaches a real card.

To run against a development stack on your machine, point baseUrl at your own machine on port 3000 — an iOS simulator reaches it via the loopback interface, an Android emulator as 10.0.2.2. Both platforms block cleartext HTTP by default, so a development run needs a debug-only exception (NSAllowsLocalNetworking on iOS, a scoped network_security_config on Android). Neither belongs in a release build.


Did this page help you?