Create checkout

Creates a new checkout payment. Returns a provider-rendered payment UI and a payment_id to track the payment's lifecycle.

Supports two request modes:

  • Mode A: Standard checkout using merchant credentials (X-Merchant-Id, X-Merchant-Api-Key headers required)
  • Mode B: Widget-token checkout where amount/currency/order_id/merchant are resolved from the token record (merchant headers optional)

Mode A fields:

FieldTypeRequiredDescription
currencystringYes3-letter ISO currency code (e.g., gbp)
amountnumberYesAmount in minor units (e.g., 4999 for £49.99)
customer_emailstringYesForwarded to the payment provider

Mode B fields:

FieldTypeRequiredDescription
widget_tokenstringYesSingle-use token from POST /api/v1/checkout/init. Used for checkout authentication.
customer_emailstringNoThe shopper, forwarded to the provider. Omit for guest checkout with a new card. Required when saved_payment_method_id is sent.
amountnumberNoOptional, but if sent it must match the token amount exactly
currencystringNoOptional, but if sent it must match the token currency exactly
save_cardbooleanNoDefault false. Stores the new card against customer_email for future use. Has no effect for a guest, and is ignored on the saved-card and pay-by-bank rails.
saved_payment_method_idstringNoCharges a stored card directly. The method must belong to the customer_email + merchant + provider combination.
payment_method_typestringNo"card" (default) or "pay_by_bank". Pay-by-bank is accepted only for an eligible merchant. Ineligible requests return 400.
return_urlstringConditionalRequired when payment_method_type is "pay_by_bank". The merchant-owned URL the shopper returns to after approving; the provider appends its own query parameters. Absolute http/https, and outside local development https only.

Note: saved_payment_method_id, payment_method_type: "pay_by_bank", alternative_payment_method_id and the advanced-flow payment_method are mutually exclusive; combining them returns 400. Rail validation runs before the widget token is consumed, so a rejected request leaves the token usable.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
≥ 0
object | null
length ≥ 1
length ≥ 1
object | null
boolean
Defaults to false
length ≥ 1
length ≥ 1
Responses

Language
Credentials
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json