Endpoint catalog
Canonical routes for the DEUNA order, payment, user, card, and subscription endpoints referenced throughout the documentation.
On this page
Use this catalog when a guide links to an API operation. Paths and HTTP methods are kept stable here so older integration guides resolve to a useful, current destination.
Complete API Gateway inventory#
This inventory is generated from the effective API Gateway configuration, rather than from the smaller legacy OpenAPI snapshot. Use the filters to identify who should call an operation, which service owns it, what authorization it supports, and which headers the gateway accepts or forwards.
The catalog includes merchant and customer APIs, partner routes, provider callbacks, and public browser routes. Internal Admin and management operations are excluded. Provider callbacks are shown for integration context and must not be called by merchant integrations.
Generated from the public-facing portion of the effective API Gateway configuration.
Merchant backend · server to serverUse from a trusted merchant backend for orders, payments and operational workflows.278
/cards/bin/{bin}Retrieve Bin.
- Domain
- Cards and vault
- Owning service
- Card metadata
- Intended for
- Merchant backend · server to server
/merchants/external-orders/{order_token}/gift-cardsCreate Gift Cards.
- Domain
- Cards and vault
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/external-orders/{order_token}/couponsCreate Coupons.
- Domain
- Checkout
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/external-orders/{order_token}/coupons/{coupon_code}Delete Coupons.
- Domain
- Checkout
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/external-orders/{order_token}/custom-fieldsUpdate Custom Fields.
- Domain
- Checkout
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/external-orders/{order_token}/shipping-methodsCreate Shipping Methods.
- Domain
- Checkout
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/external-orders/{order_token}/shipping-methods/{code}Update Shipping Methods.
- Domain
- Checkout
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/external-orders/{order_token}/shipping-rateCreate Shipping Rate.
- Domain
- Checkout
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/credentialsList or retrieve Credentials.
- Domain
- Connections
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputesList or retrieve Disputes.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputesCreate Disputes.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}Retrieve Disputes.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/draftUpdate Draft.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/evidenceList or retrieve Evidence.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/evidenceCreate Evidence.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/evidence/{evidence_id}Retrieve Evidence.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/evidence/{evidence_id}/archiveRun Archive for Evidence.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/evidence/{evidence_id}/versionsCreate Versions.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/evidence/{evidence_id}/versions/{version_id}/completeRun Complete for Versions.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/evidence/{evidence_id}/versions/{version_id}/downloadRun Download for Versions.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/information-requestsList or retrieve Information Requests.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/information-requestsCreate Information Requests.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/information-requests/{request_id}Retrieve Information Requests.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/information-requests/{request_id}/dismissRun Dismiss for Information Requests.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/information-requests/{request_id}/resolveRun Resolve for Information Requests.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/information-requests/{request_id}/responsesCreate Responses.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/metadataUpdate Metadata.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/requirementsList or retrieve Requirements.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/reviewsCreate Reviews.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/reviews/{review_id}Retrieve Reviews.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/reviews/{review_id}/approveRun Approve for Reviews.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/reviews/{review_id}/snapshotList or retrieve Snapshot.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/submissionsList or retrieve Submissions.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/submissions/{submission_id}Retrieve Submissions.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/submitRun Submit for Disputes.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/{id}/updatesList or retrieve Updates.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/capabilitiesList or retrieve Capabilities.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/connectionsList or retrieve Connections.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/disputes/connections/{processor_account_id}Retrieve Connections.
- Domain
- Disputes
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/avs/codesList or retrieve Codes.
- Domain
- Fraud and risk
- Owning service
- Fraud and risk
- Intended for
- Merchant backend · server to server
/filters/anti-fraud-providersList or retrieve Anti Fraud Providers.
- Domain
- Fraud and risk
- Owning service
- Fraud and risk
- Intended for
- Merchant backend · server to server
/merchant/anti-fraud-processorList or retrieve Anti Fraud Processor.
- Domain
- Fraud and risk
- Owning service
- Fraud and risk
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/fraud-settingsDelete Fraud Settings.
- Domain
- Fraud and risk
- Owning service
- Fraud and risk
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/fraud-settingsList or retrieve Fraud Settings.
- Domain
- Fraud and risk
- Owning service
- Fraud and risk
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/fraud-settingsUpdate Fraud Settings.
- Domain
- Fraud and risk
- Owning service
- Fraud and risk
- Intended for
- Merchant backend · server to server
/filters/acquirers/merchants/{merchant_id}Retrieve Merchants.
- Domain
- Merchant administration
- Owning service
- Reports and reconciliation
- Intended for
- Merchant backend · server to server
/filters/data_source/merchants/{merchant_id}Retrieve Merchants.
- Domain
- Merchant administration
- Owning service
- Reports and reconciliation
- Intended for
- Merchant backend · server to server
/fulfillments/{provider}/{merchant_id}Create Fulfillments.
- Domain
- Merchant administration
- Owning service
- Post-transaction
- Intended for
- Merchant backend · server to server
/merchant/{id}/avs/historyList or retrieve History.
- Domain
- Merchant administration
- Owning service
- Fraud and risk
- Intended for
- Merchant backend · server to server
/merchant/{id}/profileList or retrieve Profile.
- Domain
- Merchant administration
- Owning service
- Fraud and risk
- Intended for
- Merchant backend · server to server
/merchant/{id}/profileUpdate Profile.
- Domain
- Merchant administration
- Owning service
- Fraud and risk
- Intended for
- Merchant backend · server to server
/merchant/profileCreate Profile.
- Domain
- Merchant administration
- Owning service
- Fraud and risk
- Intended for
- Merchant backend · server to server
/merchant/transaction/{id}Retrieve Transaction.
- Domain
- Merchant administration
- Owning service
- Fraud and risk
- Intended for
- Merchant backend · server to server
/merchantsList or retrieve Merchants.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchantsCreate Merchants.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants-allList or retrieve Merchants All.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants-tokens/meList or retrieve Me.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}Retrieve Merchants.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}Update Merchants.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/applicationsList or retrieve Applications.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/applicationsUpdate Applications.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/applicationsCreate Applications.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/applications/{application_id}Retrieve Applications.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/applications/{application_id}/storesCreate Stores.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/configurationsList or retrieve Configurations.
- Domain
- Merchant administration
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/configurationsCreate Configurations.
- Domain
- Merchant administration
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/configurations/{configuration_id}Delete Configurations.
- Domain
- Merchant administration
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/configurations/{configuration_id}Retrieve Configurations.
- Domain
- Merchant administration
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/decryptCreate Decrypt.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/external-endpointsCreate External Endpoints.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/external-endpoints/{external_endpoint_id}Delete External Endpoints.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/external-endpoints/{external_endpoint_id}Update External Endpoints.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/filesList or retrieve Files.
- Domain
- Merchant administration
- Owning service
- Reports and reconciliation
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/onboarding_step/{step}Create Onboarding Step.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/public-keysCreate Public Keys.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/recipientsList or retrieve Recipients.
- Domain
- Merchant administration
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/recipientsCreate Recipients.
- Domain
- Merchant administration
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/recipients/{recipient_id}Delete Recipients.
- Domain
- Merchant administration
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/recipients/{recipient_id}Update Recipients.
- Domain
- Merchant administration
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/storesList or retrieve Stores.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/storesCreate Stores.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/tokensCreate Tokens.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/applications/validateList or retrieve Validate.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/applications/validateUpdate Validate.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/applications/validateCreate Validate.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/audit-logsList or retrieve Audit Logs.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/audit-logs/exportsList or retrieve Exports.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/audit-logs/exportsCreate Exports.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/audit-logs/exports/{export_id}/downloadRun Download for Exports.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/audit-logs/filtersList or retrieve Filters.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/billing/invoicesList or retrieve Invoices.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/billing/invoices/{invoice_id}Retrieve Invoices.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/countries/{country}/{state}/citiesList or retrieve Cities.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/countries/{country}/banksList or retrieve Banks.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/countries/{country}/citiesList or retrieve Cities.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/countries/{country}/statesList or retrieve States.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/countries/listList or retrieve List.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/data/airline-informationList or retrieve Airline Information.
- Domain
- Merchant administration
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/data/airline-informationCreate Airline Information.
- Domain
- Merchant administration
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/data/airline-information/{source_version}/rollbackRun Rollback for Airline Information.
- Domain
- Merchant administration
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/domain/{record}/validateCreate Validate.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/domain/validateCreate Validate.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/loginRun Login for Merchants.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/merchant-eventsList or retrieve Merchant Events.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/merchant-events/{merchant_id}Retrieve Merchant Events.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/merchant-events/{merchant_id}Create Merchant Events.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/msiDelete Msi.
- Domain
- Merchant administration
- Owning service
- Installments
- Intended for
- Merchant backend · server to server
/merchants/msiList or retrieve Msi.
- Domain
- Merchant administration
- Owning service
- Installments
- Intended for
- Merchant backend · server to server
/merchants/msiCreate Msi.
- Domain
- Merchant administration
- Owning service
- Installments
- Intended for
- Merchant backend · server to server
/merchants/msi/{merchant_id}Retrieve Msi.
- Domain
- Merchant administration
- Owning service
- Installments
- Intended for
- Merchant backend · server to server
/merchants/request-codeRun Request Code for Merchants.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/resources/external-endpointsList or retrieve External Endpoints.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/self-onboardingCreate Self Onboarding.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/validate-codeCreate Validate Code.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/tenantsList or retrieve Tenants.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/tenantsCreate Tenants.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/tenants/{tenant_id}Retrieve Tenants.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/tenants/{tenant_id}Update Tenants.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants-tokens/meList or retrieve Me.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants/{merchant_id}/security/mfaList or retrieve Mfa.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants/{merchant_id}/security/mfaUpdate Mfa.
- Domain
- Merchant administration
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/ordersList or retrieve Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/orders/{order_token}Retrieve Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/orders/{order_token}/captureRun Capture for Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/orders/{order_token}/payment_optionsList or retrieve Payment Options.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/orders/{order_token}/refundCreate Refund.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/orders/{order_token}/status/{status}Create Status.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/orders/{order_token}/voidRun Void for Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/orders/{order_token}/vouchersList or retrieve Vouchers.
- Domain
- Orders
- Owning service
- Vouchers
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/orders/{order_token}/vouchersCreate Vouchers.
- Domain
- Orders
- Owning service
- Vouchers
- Intended for
- Merchant backend · server to server
/merchants/external-orders/{order_token}/billing-addressCreate Billing Address.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/external-orders/{order_token}/scheduleCreate Schedule.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/ordersList or retrieve Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/ordersCreate Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}Retrieve Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}Update Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/cancelRun Cancel for Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/captureRun Capture for Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/capture-asyncCreate Capture Async.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/consentList or retrieve Consent.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/consentCreate Consent.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/expireRun Expire for Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/payments-methodsList or retrieve Payments Methods.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/promotionsCreate Promotions.
- Domain
- Orders
- Owning service
- Merchant middleware
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/refundCreate Refund.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/refund-asyncCreate Refund Async.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/successRun Success for Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/transactions/nequi/verifyRun Verify for Nequi.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/transactions/verifyRun Verify for Transactions.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/voidRun Void for Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/{order_token}/void-asyncRun Void Async for Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/filters-optionsList or retrieve Filters Options.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/orders/id/{order_id}Retrieve Id.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/transactions/orders/{order_token}/installmentsList or retrieve Installments.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/orders/statusList or retrieve Status.
- Domain
- Orders
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/v2/merchants/{merchant_id}/orders/{order_token}/captureRun Capture for Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/v2/merchants/orders/{order_token}/captureRun Capture for Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/v2/merchants/orders/{order_token}/refundCreate Refund.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/v2/merchants/orders/purchaseCreate Purchase.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/payments/links/templatesList or retrieve Templates.
- Domain
- Payment links
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/payments/links/templatesCreate Templates.
- Domain
- Payment links
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/payments/links/templates/{template_id}Retrieve Templates.
- Domain
- Payment links
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/payments/links/templates/{template_id}Update Templates.
- Domain
- Payment links
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/payment-linksCreate Payment Links.
- Domain
- Payment links
- Owning service
- Payment links
- Intended for
- Merchant backend · server to server
/merchants/payment-links/{payment_link_id}Retrieve Payment Links.
- Domain
- Payment links
- Owning service
- Payment links
- Intended for
- Merchant backend · server to server
/merchants/payment-links/{payment_link_id}Update Payment Links.
- Domain
- Payment links
- Owning service
- Payment links
- Intended for
- Merchant backend · server to server
/merchants/payment-links/{payment_link_id}/ordersList or retrieve Orders.
- Domain
- Payment links
- Owning service
- Payment links
- Intended for
- Merchant backend · server to server
/merchants/payment-links/allList or retrieve All.
- Domain
- Payment links
- Owning service
- Payment links
- Intended for
- Merchant backend · server to server
/merchants/payments/links/templates/{template_id}/ordersList or retrieve Orders.
- Domain
- Payment links
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/payment-links/{payment_link_id}Retrieve Payment Links.
- Domain
- Payment links
- Owning service
- Payment links
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/batch-transactionsList or retrieve Batch Transactions.
- Domain
- Payments
- Owning service
- Batch transactions
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/batch-transactionsCreate Batch Transactions.
- Domain
- Payments
- Owning service
- Batch transactions
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/batch-transactions/{batch_id}Retrieve Batch Transactions.
- Domain
- Payments
- Owning service
- Batch transactions
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/installmentsDelete Installments.
- Domain
- Payments
- Owning service
- Installments
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/installmentsList or retrieve Installments.
- Domain
- Payments
- Owning service
- Installments
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/installmentsCreate Installments.
- Domain
- Payments
- Owning service
- Installments
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/transactionsList or retrieve Transactions.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/merchants/stores/payments-methodsList or retrieve Payments Methods.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/payments-middleware/manifestList or retrieve Manifest.
- Domain
- Payments
- Owning service
- Merchant middleware
- Intended for
- Merchant backend · server to server
/payments-middleware/payment-methodsList or retrieve Payment Methods.
- Domain
- Payments
- Owning service
- Merchant middleware
- Intended for
- Merchant backend · server to server
/payments-middleware/paymentsCreate Payments.
- Domain
- Payments
- Owning service
- Merchant middleware
- Intended for
- Merchant backend · server to server
/payments-middleware/payments/{payment_id}/cancellationsCreate Cancellations.
- Domain
- Payments
- Owning service
- Merchant middleware
- Intended for
- Merchant backend · server to server
/payments-middleware/payments/{payment_id}/refundsCreate Refunds.
- Domain
- Payments
- Owning service
- Merchant middleware
- Intended for
- Merchant backend · server to server
/payments-vault/tokenizationCreate Tokenization.
- Domain
- Payments
- Owning service
- Vault
- Intended for
- Merchant backend · server to server
/payments-vault/tokenization/{uuid}/cvvCreate Cvv.
- Domain
- Payments
- Owning service
- Vault
- Intended for
- Merchant backend · server to server
/post-transactions/{provider}Create Post Transactions.
- Domain
- Payments
- Owning service
- Post-transaction
- Intended for
- Merchant backend · server to server
/telcel-middleware/transactions/inquiryCreate Inquiry.
- Domain
- Payments
- Owning service
- Telcel middleware
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/{request_id_hash}/cancelRun Cancel for Transactions.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/captureRun Capture for Transactions.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/refundCreate Refund.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/statusUpdate Status.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/status/nequiCreate Nequi.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/three-ds-flowList or retrieve Three Ds Flow.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/three-ds-flow/completeRun Complete for Three Ds Flow.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/three-ds-flow/completeRun Complete for Three Ds Flow.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/three-ds-flow/continueRun Continue for Three Ds Flow.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/transfer/{current_store_code}/{new_store_code}Run Transfer for Transactions.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/verifyRun Verify for Transactions.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/voidRun Void for Transactions.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/{transaction_id}/void-asyncRun Void Async for Transactions.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/internal-searchList or retrieve Internal Search.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/payments-methodsList or retrieve Payments Methods.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/payments-methods/{method_type}/installmentsList or retrieve Installments.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/searchRun Search for Transactions.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/update-processing-transactionsList or retrieve Update Processing Transactions.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/verify3dsList or retrieve Verify3ds.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/verify3dsCreate Verify3ds.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/transactions/view_challengeList or retrieve View Challenge.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/manual-reviewCreate Manual Review.
- Domain
- Post-transaction
- Owning service
- Post-transaction
- Intended for
- Merchant backend · server to server
/post-transaction-manual-process/{action}Create Post Transaction Manual Process.
- Domain
- Post-transaction
- Owning service
- Post-transaction
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/files/{file_id}/presigned-urlList or retrieve Presigned Url.
- Domain
- Reports
- Owning service
- Reports and reconciliation
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/subscriptions/{id}/ordersList or retrieve Orders.
- Domain
- Subscriptions
- Owning service
- Orders and checkout
- Intended for
- Merchant backend · server to server
/merchants/installments/plans/{installment_plan_option_id}Retrieve Plans.
- Domain
- Subscriptions
- Owning service
- Installments
- Intended for
- Merchant backend · server to server
/subscriptionsList or retrieve Subscriptions.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptionsCreate Subscriptions.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/{id}Delete Subscriptions.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/{id}Retrieve Subscriptions.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/{id}Update Subscriptions.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/{id}/cancelRun Cancel for Subscriptions.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/{id}/cardsUpdate Cards.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/{id}/historyList or retrieve History.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/{id}/pauseRun Pause for Subscriptions.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/{id}/resumeRun Resume for Subscriptions.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/plansList or retrieve Plans.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/plansCreate Plans.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/plans/{id}Delete Plans.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/plans/{id}Retrieve Plans.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/plans/{id}Update Plans.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/plans/statusesList or retrieve Statuses.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/subscriptions/retriesList or retrieve Retries.
- Domain
- Subscriptions
- Owning service
- Subscription retries
- Intended for
- Merchant backend · server to server
/subscriptions/retriesCreate Retries.
- Domain
- Subscriptions
- Owning service
- Subscription retries
- Intended for
- Merchant backend · server to server
/subscriptions/retries/{id}Delete Retries.
- Domain
- Subscriptions
- Owning service
- Subscription retries
- Intended for
- Merchant backend · server to server
/subscriptions/retries/{id}Retrieve Retries.
- Domain
- Subscriptions
- Owning service
- Subscription retries
- Intended for
- Merchant backend · server to server
/subscriptions/retries/{id}Update Retries.
- Domain
- Subscriptions
- Owning service
- Subscription retries
- Intended for
- Merchant backend · server to server
/subscriptions/statusesList or retrieve Statuses.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Merchant backend · server to server
/trace/logsList or retrieve Logs.
- Domain
- Trace and audit logs
- Owning service
- Trace and audit logs
- Intended for
- Merchant backend · server to server
/trace/logs/visibility/groupedList or retrieve Grouped.
- Domain
- Trace and audit logs
- Owning service
- Trace and audit logs
- Intended for
- Merchant backend · server to server
/v2/trace/logsList or retrieve Logs.
- Domain
- Trace and audit logs
- Owning service
- Trace and audit logs
- Intended for
- Merchant backend · server to server
/hermes/merchants/users/notificationsCreate Notifications.
- Domain
- Users and identity
- Owning service
- Notifications
- Intended for
- Merchant backend · server to server
/merchant-usersList or retrieve Merchant Users.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/{merchant_id}/policiesList or retrieve Policies.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/identity-tokenCreate Identity Token.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/usersCreate Users.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/users/{user_id}Retrieve Users.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/users/{user_id}Create Users.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/users/{user_id}Update Users.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/users/{user_id}/authorizeRun Authorize for Users.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/users/{user_id}/generate-change-password-tokenCreate Generate Change Password Token.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/users/change-passwordCreate Change Password.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/merchants/validate-oauthCreate Validate Oauth.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/users/authorizeRun Authorize for Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Merchant backend · server to server
/users/external-authorizeCreate External Authorize.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Merchant backend · server to server
/v1/users/{user_id}/transactions/{transaction_id}Retrieve Transactions.
- Domain
- Users and identity
- Owning service
- Payments
- Intended for
- Merchant backend · server to server
/v2/auth/identity/change-passwordCreate Change Password.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/auth/identity/userList or retrieve User.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/auth/log-streamCreate Log Stream.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/auth/loginRun Login for Auth.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/auth/mfa-syncCreate Mfa Sync.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/auth/session/bootstrapRun Bootstrap for Session.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/auth/user-org-syncCreate User Org Sync.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/generate-custom-tokenList or retrieve Generate Custom Token.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants/usersCreate Users.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants/users/{user_id}Update Users.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants/users/{user_id}/banRun Ban for Users.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants/users/{user_id}/inviteRun Invite for Users.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants/users/{user_id}/mfa/resetRun Reset for Mfa.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants/users/{user_id}/security-blockDelete Security Block.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants/users/{user_id}/security-blockList or retrieve Security Block.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants/users/{user_id}/security-blockCreate Security Block.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants/users/mfa/disableRun Disable for Mfa.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/v2/merchants/users/passwordUpdate Password.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Merchant backend · server to server
/vaults/activeList or retrieve Active.
- Domain
- Vault
- Owning service
- Vault
- Intended for
- Merchant backend · server to server
/vaults/activeUpdate Active.
- Domain
- Vault
- Owning service
- Vault
- Intended for
- Merchant backend · server to server
/hermes/events/create-campaignCreate Create Campaign.
- Domain
- Webhooks and notifications
- Owning service
- Notifications
- Intended for
- Merchant backend · server to server
/hermes/template/{merchantID}Create Template.
- Domain
- Webhooks and notifications
- Owning service
- Notifications
- Intended for
- Merchant backend · server to server
/hermes/template/{templateID}Delete Template.
- Domain
- Webhooks and notifications
- Owning service
- Notifications
- Intended for
- Merchant backend · server to server
/hermes/template/defaultCreate Default.
- Domain
- Webhooks and notifications
- Owning service
- Notifications
- Intended for
- Merchant backend · server to server
/notifications/{userId}Update Notifications.
- Domain
- Webhooks and notifications
- Owning service
- Notifications
- Intended for
- Merchant backend · server to server
Customer application · user to serverUse from customer-facing web or mobile flows with the user identity and device context shown.62
/payments-cards/users/{user_id}/cardsList or retrieve Cards.
- Domain
- Cards and vault
- Owning service
- Payment cards
- Intended for
- Customer application · user to server
/payments-cards/users/{user_id}/cardsCreate Cards.
- Domain
- Cards and vault
- Owning service
- Payment cards
- Intended for
- Customer application · user to server
/payments-cards/users/{user_id}/cards/{card_id}Delete Cards.
- Domain
- Cards and vault
- Owning service
- Payment cards
- Intended for
- Customer application · user to server
/payments-cards/users/{user_id}/cards/{card_id}Retrieve Cards.
- Domain
- Cards and vault
- Owning service
- Payment cards
- Intended for
- Customer application · user to server
/users/{user_id}/cardsList or retrieve Cards.
- Domain
- Cards and vault
- Owning service
- Payments
- Intended for
- Customer application · user to server
/users/{user_id}/cardsCreate Cards.
- Domain
- Cards and vault
- Owning service
- Payments
- Intended for
- Customer application · user to server
/users/{user_id}/cards/{card_id}Delete Cards.
- Domain
- Cards and vault
- Owning service
- Payments
- Intended for
- Customer application · user to server
/users/{user_id}/cards/{card_id}Retrieve Cards.
- Domain
- Cards and vault
- Owning service
- Payments
- Intended for
- Customer application · user to server
/users/{user_id}/cards/{card_id}/refresh-cvvRun Refresh Cvv for Cards.
- Domain
- Cards and vault
- Owning service
- Payments
- Intended for
- Customer application · user to server
/users/{user_id}/cards/{card_id}/set-as-defaultRun Set As Default for Cards.
- Domain
- Cards and vault
- Owning service
- Payments
- Intended for
- Customer application · user to server
/users/{user_id}/cards/{card_id}/tokensCreate Tokens.
- Domain
- Cards and vault
- Owning service
- Payments
- Intended for
- Customer application · user to server
/v2/users/{user_id}/cardsCreate Cards.
- Domain
- Cards and vault
- Owning service
- Payments
- Intended for
- Customer application · user to server
/{merchant_id}/checkoutList or retrieve Checkout.
- Domain
- Checkout
- Owning service
- Orders and checkout
- Intended for
- Customer application · user to server
/checkout/{merchant_id}/configurationUpdate Configuration.
- Domain
- Checkout
- Owning service
- Orders and checkout
- Intended for
- Customer application · user to server
/checkout/{merchant_id}/configurationCreate Configuration.
- Domain
- Checkout
- Owning service
- Orders and checkout
- Intended for
- Customer application · user to server
/checkout/readyList or retrieve Ready.
- Domain
- Checkout
- Owning service
- Orders and checkout
- Intended for
- Customer application · user to server
/checkout/statusList or retrieve Status.
- Domain
- Checkout
- Owning service
- Users and identity
- Intended for
- Customer application · user to server
/shortener/{hash_id}Create Shortener.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Customer application · user to server
/transactions/{transaction_id}/consent/{consent_id}/redirectList or retrieve Redirect.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Customer application · user to server
/transactions/next-action/{next_action_id}Retrieve Next Action.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Customer application · user to server
/usersList or retrieve Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/{user_id}Delete Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/{user_id}Update Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/{user_id}/accepted-policiesList or retrieve Accepted Policies.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/{user_id}/accepted-policiesCreate Accepted Policies.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/{user_id}/accepted-policies/preferencesCreate Preferences.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/{user_id}/addressesList or retrieve Addresses.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/{user_id}/addressesCreate Addresses.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/{user_id}/addresses/{address_id}Delete Addresses.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/{user_id}/addresses/{address_id}Retrieve Addresses.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/{user_id}/addresses/{address_id}Update Addresses.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/{user_id}/change-passwordCreate Change Password.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/{user_id}/transactionsList or retrieve Transactions.
- Domain
- Users and identity
- Owning service
- Payments
- Intended for
- Customer application · user to server
/users/addresses/{address_id}Retrieve Addresses.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/auth/verifyRun Verify for Auth.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/bulkCreate Bulk.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/change-passwordCreate Change Password.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/forgot-passwordCreate Forgot Password.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/generateRun Generate for Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/loginRun Login for Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/login/device-fingerprintCreate Device Fingerprint.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/logoutRun Logout for Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/meList or retrieve Me.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/payment-methods/{payment_method_id}/tokens/{payment_method}Delete Tokens.
- Domain
- Users and identity
- Owning service
- Payments
- Intended for
- Customer application · user to server
/users/payment-methods/tokensCreate Tokens.
- Domain
- Users and identity
- Owning service
- Payments
- Intended for
- Customer application · user to server
/users/probeRun Probe for Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/probe/{id}Run Probe for Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/registerRun Register for Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/request-codeRun Request Code for Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/sessionsList or retrieve Sessions.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/sessions/{session_id}/deviceList or retrieve Device.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/sign-messageCreate Sign Message.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/signupRun Signup for Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/web/forgot-passwordList or retrieve Forgot Password.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/web/loginRun Login for Web.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/web/password-loginList or retrieve Password Login.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/web/passwordlessList or retrieve Passwordless.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/users/web/signupRun Signup for Web.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/v2/usersList or retrieve Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/v2/users/{user_id}Retrieve Users.
- Domain
- Users and identity
- Owning service
- Users and identity
- Intended for
- Customer application · user to server
/v2/users/{user_id}/addressesList or retrieve Addresses.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
/v2/users/loginRun Login for Users.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Customer application · user to server
Network or partner backendUsed by an authorized network, platform or integration partner backend.15
/networks/{network_id}/processorsList or retrieve Processors.
- Domain
- Connections
- Owning service
- Payments
- Intended for
- Network or partner backend
/networks/ordersList or retrieve Orders.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Network or partner backend
/networks/orders/filters-optionsList or retrieve Filters Options.
- Domain
- Orders
- Owning service
- Orders and checkout
- Intended for
- Network or partner backend
/networks/fieldsList or retrieve Fields.
- Domain
- Reports
- Owning service
- Reports
- Intended for
- Network or partner backend
/networks/reports/{id}/downloadRun Download for Reports.
- Domain
- Reports
- Owning service
- Reports
- Intended for
- Network or partner backend
/networks/reports/adhocCreate Adhoc.
- Domain
- Reports
- Owning service
- Reports
- Intended for
- Network or partner backend
/networks/reports/adhoc/{report_id}Retrieve Adhoc.
- Domain
- Reports
- Owning service
- Reports
- Intended for
- Network or partner backend
/networks/reports/adhoc/{report_id}/logsList or retrieve Logs.
- Domain
- Reports
- Owning service
- Reports
- Intended for
- Network or partner backend
/networks/reports/adhoc/filesList or retrieve Files.
- Domain
- Reports
- Owning service
- Reports
- Intended for
- Network or partner backend
/networks/reports/schedulesList or retrieve Schedules.
- Domain
- Reports
- Owning service
- Reports
- Intended for
- Network or partner backend
/networks/reports/schedulesCreate Schedules.
- Domain
- Reports
- Owning service
- Reports
- Intended for
- Network or partner backend
/networks/reports/schedules/{id}Delete Schedules.
- Domain
- Reports
- Owning service
- Reports
- Intended for
- Network or partner backend
/networks/reports/schedules/{id}Retrieve Schedules.
- Domain
- Reports
- Owning service
- Reports
- Intended for
- Network or partner backend
/networks/reports/schedules/{id}Update Schedules.
- Domain
- Reports
- Owning service
- Reports
- Intended for
- Network or partner backend
/networks/reports/schedules/{id}Update Schedules.
- Domain
- Reports
- Owning service
- Reports
- Intended for
- Network or partner backend
Provider callback · provider to DEUNACallback receiver for payment, fraud or platform providers; merchants do not call these routes.27
/transactions/webhooks/processors/{processor_name}Create Processors.
- Domain
- Connections
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/processors/{processor_name}/refundsCreate Refunds.
- Domain
- Connections
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/processors/{processor_name}/uninstallRun Uninstall for Processors.
- Domain
- Connections
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/merchants/{merchant_id}/chargebacks/kushkiCreate Kushki.
- Domain
- Disputes
- Owning service
- Chargebacks
- Intended for
- Provider callback · provider to DEUNA
/merchants/{merchant_id}/chargebacks/stripeCreate Stripe.
- Domain
- Disputes
- Owning service
- Chargebacks
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/addiCreate Addi.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/aplazoCreate Aplazo.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/conektaCreate Conekta.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/dlocalCreate Dlocal.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/kueskiCreate Kueski.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/mercadopagoCreate Mercadopago.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/openpayCreate Openpay.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/opm-speiCreate Opm Spei.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/oxxoCreate Oxxo.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/paypalplatform/{transaction_id}Create Paypalplatform.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/payuCreate Payu.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/stpCreate Stp.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/stripe_oxxoCreate Stripe Oxxo.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/webpayCreate Webpay.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/wompiCreate Wompi.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/transactions/webhooks/zipUpdate Zip.
- Domain
- Payments
- Owning service
- Payments
- Intended for
- Provider callback · provider to DEUNA
/subscriptions/webhook-configurationsDelete Webhook Configurations.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Provider callback · provider to DEUNA
/subscriptions/webhook-configurationsList or retrieve Webhook Configurations.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Provider callback · provider to DEUNA
/subscriptions/webhook-configurationsUpdate Webhook Configurations.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Provider callback · provider to DEUNA
/subscriptions/webhook-configurationsCreate Webhook Configurations.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Provider callback · provider to DEUNA
/subscriptions/webhook-configurations/event-typesList or retrieve Event Types.
- Domain
- Subscriptions
- Owning service
- Subscriptions
- Intended for
- Provider callback · provider to DEUNA
/hermes/waf/report-data/bts-deliveryCreate Bts Delivery.
- Domain
- Webhooks and notifications
- Owning service
- Notifications
- Intended for
- Provider callback · provider to DEUNA
Public browser or infrastructureUnauthenticated browser redirects, public metadata, assets or health surfaces.3
/users/.well-known/jwks.jsonList or retrieve Jwks.Json.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Public browser or infrastructure
/users/static/css/{file}Retrieve Css.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Public browser or infrastructure
/users/static/js/{file}Retrieve Js.
- Domain
- Users and identity
- Owning service
- Merchant management
- Intended for
- Public browser or infrastructure
Core integration endpoints#
The operations below retain stable anchors used by integration guides and provide additional context for the most common merchant workflows.
Orders API#
Create an order
POST /merchants/orders
Creates an order and returns the order_token used by DEUNA widgets and payment operations.
The required object varies by order type: Checkout and Subscriptions orders require the items array, while Airline orders require airline information. The base contract does not mark an individual item property as universally required. See the item field reference and vertical field guide.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/merchants/orders' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Idempotency-Key: IDEMPOTENCY_KEY' \
--header 'X-Prediction-Id: PREDICTION_ID_VALUE' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/merchants/orders", {
method: "POST",
headers: {
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Idempotency-Key": "IDEMPOTENCY_KEY",
"X-Prediction-Id": "PREDICTION_ID_VALUE",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/merchants/orders",
headers={
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Idempotency-Key": "IDEMPOTENCY_KEY",
"X-Prediction-Id": "PREDICTION_ID_VALUE",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/merchants/orders",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Idempotency-Key: IDEMPOTENCY_KEY",
"X-Prediction-Id: PREDICTION_ID_VALUE",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/merchants/orders"))
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Idempotency-Key", "IDEMPOTENCY_KEY")
.header("X-Prediction-Id", "PREDICTION_ID_VALUE")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/merchants/orders", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Idempotency-Key", "IDEMPOTENCY_KEY")
request.Header.Set("X-Prediction-Id", "PREDICTION_ID_VALUE")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Get an order
GET /merchants/orders/{order_token}
Retrieves the current order, payment, and processing state for an order token.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/merchants/orders/{order_token}' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'x-merchant-id: MERCHANT_ID'const response = await fetch("https://api.sandbox.deuna.io/merchants/orders/{order_token}", {
method: "GET",
headers: {
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"x-merchant-id": "MERCHANT_ID"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/merchants/orders/{order_token}",
headers={
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"x-merchant-id": "MERCHANT_ID"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/merchants/orders/{order_token}",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"Authorization: Bearer USER_ACCESS_TOKEN",
"x-merchant-id: MERCHANT_ID"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/merchants/orders/{order_token}"))
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("x-merchant-id", "MERCHANT_ID")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/merchants/orders/{order_token}", nil)
if err != nil { panic(err) }
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("x-merchant-id", "MERCHANT_ID")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Get payment methods for an order
GET /merchants/orders/{order_token}/payments-methods
Returns the payment methods available to a specific order and merchant configuration.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/merchants/orders/{order_token}/payments-methods' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Store-Code: STORE_CODE'const response = await fetch("https://api.sandbox.deuna.io/merchants/orders/{order_token}/payments-methods", {
method: "GET",
headers: {
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Store-Code": "STORE_CODE"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/merchants/orders/{order_token}/payments-methods",
headers={
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Store-Code": "STORE_CODE"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/merchants/orders/{order_token}/payments-methods",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Store-Code: STORE_CODE"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/merchants/orders/{order_token}/payments-methods"))
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Store-Code", "STORE_CODE")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/merchants/orders/{order_token}/payments-methods", nil)
if err != nil { panic(err) }
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Store-Code", "STORE_CODE")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Create wallet consent
POST /merchants/orders/{order_token}/consent
Creates the customer authorization required by supported wallet connections. The response can include a provider redirect_url. See Consent flows.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/merchants/orders/{order_token}/consent' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Store-Code: STORE_CODE' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/merchants/orders/{order_token}/consent", {
method: "POST",
headers: {
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Store-Code": "STORE_CODE",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/merchants/orders/{order_token}/consent",
headers={
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Store-Code": "STORE_CODE",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/merchants/orders/{order_token}/consent",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Store-Code: STORE_CODE",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/merchants/orders/{order_token}/consent"))
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Store-Code", "STORE_CODE")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/merchants/orders/{order_token}/consent", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Store-Code", "STORE_CODE")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Get wallet consent
GET /merchants/orders/{order_token}/consent
Returns the latest consent state. For connections that support provider polling, DEUNA refreshes an eligible pending consent before returning it.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/merchants/orders/{order_token}/consent' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Store-Code: STORE_CODE'const response = await fetch("https://api.sandbox.deuna.io/merchants/orders/{order_token}/consent", {
method: "GET",
headers: {
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Store-Code": "STORE_CODE"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/merchants/orders/{order_token}/consent",
headers={
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Store-Code": "STORE_CODE"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/merchants/orders/{order_token}/consent",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Store-Code: STORE_CODE"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/merchants/orders/{order_token}/consent"))
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Store-Code", "STORE_CODE")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/merchants/orders/{order_token}/consent", nil)
if err != nil { panic(err) }
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Store-Code", "STORE_CODE")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Payments API#
Create a payment
POST /v2/merchants/orders/purchase
Processes a payment for an existing order token or for the order supplied in the request. See the detailed payment request guide.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/v2/merchants/orders/purchase' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'Cookie: COOKIE_VALUE' \
--header 'X-Device-Id: DEVICE_ID' \
--header 'X-Merchant-ID: MERCHANT_ID' \
--header 'X-Prediction-Id: PREDICTION_ID_VALUE' \
--header 'X-Session-Id: SESSION_ID' \
--header 'X-Store-Code: STORE_CODE' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/v2/merchants/orders/purchase", {
method: "POST",
headers: {
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"Cookie": "COOKIE_VALUE",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-ID": "MERCHANT_ID",
"X-Prediction-Id": "PREDICTION_ID_VALUE",
"X-Session-Id": "SESSION_ID",
"X-Store-Code": "STORE_CODE",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/v2/merchants/orders/purchase",
headers={
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"Cookie": "COOKIE_VALUE",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-ID": "MERCHANT_ID",
"X-Prediction-Id": "PREDICTION_ID_VALUE",
"X-Session-Id": "SESSION_ID",
"X-Store-Code": "STORE_CODE",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/v2/merchants/orders/purchase",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"Authorization: Bearer USER_ACCESS_TOKEN",
"Cookie: COOKIE_VALUE",
"X-Device-Id: DEVICE_ID",
"X-Merchant-ID: MERCHANT_ID",
"X-Prediction-Id: PREDICTION_ID_VALUE",
"X-Session-Id: SESSION_ID",
"X-Store-Code: STORE_CODE",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/v2/merchants/orders/purchase"))
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("Cookie", "COOKIE_VALUE")
.header("X-Device-Id", "DEVICE_ID")
.header("X-Merchant-ID", "MERCHANT_ID")
.header("X-Prediction-Id", "PREDICTION_ID_VALUE")
.header("X-Session-Id", "SESSION_ID")
.header("X-Store-Code", "STORE_CODE")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/v2/merchants/orders/purchase", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("Cookie", "COOKIE_VALUE")
request.Header.Set("X-Device-Id", "DEVICE_ID")
request.Header.Set("X-Merchant-ID", "MERCHANT_ID")
request.Header.Set("X-Prediction-Id", "PREDICTION_ID_VALUE")
request.Header.Set("X-Session-Id", "SESSION_ID")
request.Header.Set("X-Store-Code", "STORE_CODE")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Capture a payment
POST /v2/merchants/orders/{order_token}/capture
Captures all or part of an authorized payment. Call it from the merchant backend only when the connection supports separate authorization and capture.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/v2/merchants/orders/{order_token}/capture' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/v2/merchants/orders/{order_token}/capture", {
method: "POST",
headers: {
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/v2/merchants/orders/{order_token}/capture",
headers={
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/v2/merchants/orders/{order_token}/capture",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/v2/merchants/orders/{order_token}/capture"))
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/v2/merchants/orders/{order_token}/capture", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Void an authorization
POST /merchants/orders/{order_token}/void
Releases an eligible authorization before capture. A successful synchronous request returns HTTP 204 No Content; asynchronous processor flows must still be tracked to their final payment status.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/merchants/orders/{order_token}/void' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/merchants/orders/{order_token}/void", {
method: "POST",
headers: {
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/merchants/orders/{order_token}/void",
headers={
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/merchants/orders/{order_token}/void",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/merchants/orders/{order_token}/void"))
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/merchants/orders/{order_token}/void", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Refund a payment
POST /v2/merchants/orders/{order_token}/refund
Creates a full or partial refund for a processed payment.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/v2/merchants/orders/{order_token}/refund' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/v2/merchants/orders/{order_token}/refund", {
method: "POST",
headers: {
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/v2/merchants/orders/{order_token}/refund",
headers={
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/v2/merchants/orders/{order_token}/refund",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/v2/merchants/orders/{order_token}/refund"))
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/v2/merchants/orders/{order_token}/refund", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}User Network API#
These operations support customer identity, addresses, and securely stored payment instruments. Browser and mobile applications use customer authorization. Trusted merchant backends use the authorization shown for each route in the inventory above.
Authentication
Register a user
POST /users/register
Creates a user that can authenticate and securely reuse stored payment methods.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/users/register' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'X-Merchant-Id: MERCHANT_ID' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/users/register", {
method: "POST",
headers: {
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-Id": "MERCHANT_ID",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/users/register",
headers={
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-Id": "MERCHANT_ID",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/users/register",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"X-Merchant-Id: MERCHANT_ID",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/users/register"))
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("X-Merchant-Id", "MERCHANT_ID")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/users/register", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("X-Merchant-Id", "MERCHANT_ID")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Request an OTP
POST /users/request-code
Sends the one-time code used by the passwordless authentication flow.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/users/request-code' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'X-Device-Id: DEVICE_ID' \
--header 'X-Merchant-Id: MERCHANT_ID' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/users/request-code", {
method: "POST",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/users/request-code",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/users/request-code",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"X-Device-Id: DEVICE_ID",
"X-Merchant-Id: MERCHANT_ID",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/users/request-code"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("X-Device-Id", "DEVICE_ID")
.header("X-Merchant-Id", "MERCHANT_ID")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/users/request-code", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("X-Device-Id", "DEVICE_ID")
request.Header.Set("X-Merchant-Id", "MERCHANT_ID")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Log in with an OTP
POST /users/login
Exchanges a valid one-time code for a user authorization token.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/users/login' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'X-Device-Id: DEVICE_ID' \
--header 'X-Merchant-Id: MERCHANT_ID' \
--header 'X-Qa-Api-Key: QA_API_KEY_VALUE' \
--header 'X-Recaptcha-Token: RECAPTCHA_TOKEN_VALUE' \
--header 'X-Session-ID: SESSION_ID' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/users/login", {
method: "POST",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID",
"X-Qa-Api-Key": "QA_API_KEY_VALUE",
"X-Recaptcha-Token": "RECAPTCHA_TOKEN_VALUE",
"X-Session-ID": "SESSION_ID",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/users/login",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID",
"X-Qa-Api-Key": "QA_API_KEY_VALUE",
"X-Recaptcha-Token": "RECAPTCHA_TOKEN_VALUE",
"X-Session-ID": "SESSION_ID",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/users/login",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"X-Device-Id: DEVICE_ID",
"X-Merchant-Id: MERCHANT_ID",
"X-Qa-Api-Key: QA_API_KEY_VALUE",
"X-Recaptcha-Token: RECAPTCHA_TOKEN_VALUE",
"X-Session-ID: SESSION_ID",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/users/login"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("X-Device-Id", "DEVICE_ID")
.header("X-Merchant-Id", "MERCHANT_ID")
.header("X-Qa-Api-Key", "QA_API_KEY_VALUE")
.header("X-Recaptcha-Token", "RECAPTCHA_TOKEN_VALUE")
.header("X-Session-ID", "SESSION_ID")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/users/login", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("X-Device-Id", "DEVICE_ID")
request.Header.Set("X-Merchant-Id", "MERCHANT_ID")
request.Header.Set("X-Qa-Api-Key", "QA_API_KEY_VALUE")
request.Header.Set("X-Recaptcha-Token", "RECAPTCHA_TOKEN_VALUE")
request.Header.Set("X-Session-ID", "SESSION_ID")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}External authorization
POST /users/external-authorize
Authenticates a user through a merchant-managed identity flow.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/users/external-authorize' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Auth-Message: AUTH_MESSAGE_VALUE' \
--header 'X-Device-Id: DEVICE_ID' \
--header 'X-Merchant-Id: MERCHANT_ID' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/users/external-authorize", {
method: "POST",
headers: {
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Auth-Message": "AUTH_MESSAGE_VALUE",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/users/external-authorize",
headers={
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Auth-Message": "AUTH_MESSAGE_VALUE",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/users/external-authorize",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Auth-Message: AUTH_MESSAGE_VALUE",
"X-Device-Id: DEVICE_ID",
"X-Merchant-Id: MERCHANT_ID",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/users/external-authorize"))
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Auth-Message", "AUTH_MESSAGE_VALUE")
.header("X-Device-Id", "DEVICE_ID")
.header("X-Merchant-Id", "MERCHANT_ID")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/users/external-authorize", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Auth-Message", "AUTH_MESSAGE_VALUE")
request.Header.Set("X-Device-Id", "DEVICE_ID")
request.Header.Set("X-Merchant-Id", "MERCHANT_ID")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Users
GET /users/me
Returns the authenticated user profile.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/users/me' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Device-Id: DEVICE_ID' \
--header 'X-Merchant-Id: MERCHANT_ID'const response = await fetch("https://api.sandbox.deuna.io/users/me", {
method: "GET",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/users/me",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/users/me",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Device-Id: DEVICE_ID",
"X-Merchant-Id: MERCHANT_ID"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/users/me"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Device-Id", "DEVICE_ID")
.header("X-Merchant-Id", "MERCHANT_ID")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/users/me", nil)
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Device-Id", "DEVICE_ID")
request.Header.Set("X-Merchant-Id", "MERCHANT_ID")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}GET /v2/users/{user_id}
Retrieves a user by ID for an authorized customer context.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/v2/users/{user_id}' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN'const response = await fetch("https://api.sandbox.deuna.io/v2/users/{user_id}", {
method: "GET",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/v2/users/{user_id}",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/v2/users/{user_id}",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/v2/users/{user_id}"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/v2/users/{user_id}", nil)
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Addresses
GET /users/{user_id}/addresses
Lists the addresses associated with a user.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/users/{user_id}/addresses' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Device-Id: DEVICE_ID' \
--header 'X-Merchant-Id: MERCHANT_ID'const response = await fetch("https://api.sandbox.deuna.io/users/{user_id}/addresses", {
method: "GET",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/users/{user_id}/addresses",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/users/{user_id}/addresses",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Device-Id: DEVICE_ID",
"X-Merchant-Id: MERCHANT_ID"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/users/{user_id}/addresses"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Device-Id", "DEVICE_ID")
.header("X-Merchant-Id", "MERCHANT_ID")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/users/{user_id}/addresses", nil)
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Device-Id", "DEVICE_ID")
request.Header.Set("X-Merchant-Id", "MERCHANT_ID")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}POST /users/{user_id}/addresses
Creates an address for a user.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/users/{user_id}/addresses' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Device-Id: DEVICE_ID' \
--header 'X-Merchant-Id: MERCHANT_ID' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/users/{user_id}/addresses", {
method: "POST",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/users/{user_id}/addresses",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/users/{user_id}/addresses",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Device-Id: DEVICE_ID",
"X-Merchant-Id: MERCHANT_ID",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/users/{user_id}/addresses"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Device-Id", "DEVICE_ID")
.header("X-Merchant-Id", "MERCHANT_ID")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/users/{user_id}/addresses", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Device-Id", "DEVICE_ID")
request.Header.Set("X-Merchant-Id", "MERCHANT_ID")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}PATCH /users/{user_id}/addresses/{address_id}
Updates an existing address. The inventory shows the Bearer authorization and merchant context required by these routes.
cURL example
curl --request PATCH \
--url 'https://api.sandbox.deuna.io/users/{user_id}/addresses/{address_id}' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Device-Id: DEVICE_ID' \
--header 'X-Merchant-Id: MERCHANT_ID' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/users/{user_id}/addresses/{address_id}", {
method: "PATCH",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"PATCH",
"https://api.sandbox.deuna.io/users/{user_id}/addresses/{address_id}",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Device-Id": "DEVICE_ID",
"X-Merchant-Id": "MERCHANT_ID",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/users/{user_id}/addresses/{address_id}",
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Device-Id: DEVICE_ID",
"X-Merchant-Id: MERCHANT_ID",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/users/{user_id}/addresses/{address_id}"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Device-Id", "DEVICE_ID")
.header("X-Merchant-Id", "MERCHANT_ID")
.header("Content-Type", "application/json")
.method("PATCH", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("PATCH", "https://api.sandbox.deuna.io/users/{user_id}/addresses/{address_id}", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Device-Id", "DEVICE_ID")
request.Header.Set("X-Merchant-Id", "MERCHANT_ID")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Cards
Store a card
POST /v2/users/{user_id}/cards
Stores a tokenized card for later use. Raw card data must not pass through merchant servers unless the merchant has the required PCI scope.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/v2/users/{user_id}/cards' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Merchant-ID: MERCHANT_ID' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/v2/users/{user_id}/cards", {
method: "POST",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Merchant-ID": "MERCHANT_ID",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/v2/users/{user_id}/cards",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Merchant-ID": "MERCHANT_ID",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/v2/users/{user_id}/cards",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Merchant-ID: MERCHANT_ID",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/v2/users/{user_id}/cards"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Merchant-ID", "MERCHANT_ID")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/v2/users/{user_id}/cards", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Merchant-ID", "MERCHANT_ID")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}List stored cards
GET /payments-cards/users/{user_id}/cards
Returns the cards stored for the authenticated user. Verification metadata is conditional. Unverified cards omit all verification fields.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/payments-cards/users/{user_id}/cards' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY'const response = await fetch("https://api.sandbox.deuna.io/payments-cards/users/{user_id}/cards", {
method: "GET",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Api-Key": "YOUR_PRIVATE_API_KEY"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/payments-cards/users/{user_id}/cards",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Api-Key": "YOUR_PRIVATE_API_KEY"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/payments-cards/users/{user_id}/cards",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Api-Key: YOUR_PRIVATE_API_KEY"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/payments-cards/users/{user_id}/cards"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/payments-cards/users/{user_id}/cards", nil)
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Retrieve a stored card
GET /payments-cards/users/{user_id}/cards/{card_id}
Returns one stored card. When DEUNA has successfully verified the card, the response includes the verification fields shown below.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/payments-cards/users/{user_id}/cards/{card_id}' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY'const response = await fetch("https://api.sandbox.deuna.io/payments-cards/users/{user_id}/cards/{card_id}", {
method: "GET",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Api-Key": "YOUR_PRIVATE_API_KEY"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/payments-cards/users/{user_id}/cards/{card_id}",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Api-Key": "YOUR_PRIVATE_API_KEY"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/payments-cards/users/{user_id}/cards/{card_id}",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Api-Key: YOUR_PRIVATE_API_KEY"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/payments-cards/users/{user_id}/cards/{card_id}"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/payments-cards/users/{user_id}/cards/{card_id}", nil)
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}{
"data": {
"id": "8b5d0b45-e34f-4fd3-8cb5-79a7041f86ec",
"company": "visa",
"last_four": "4242",
"expiration_date": "12/29",
"is_valid": true,
"verified_by": "card_verifier",
"verified_at": "2026-10-03T12:00:00Z"
}
}| Field | When it is returned | Meaning |
|---|---|---|
is_valid | Only after successful verification | Always true when present. An absent field means the card has not been successfully verified; it does not mean that a verification attempt failed. |
verified_by | Only after successful verification | card_verifier identifies a zero-amount authorization. payment identifies verification through a payment transaction. A processor-specific verifier can be returned when a processor validates the card during tokenization. |
verified_at | Only after successful verification | ISO 8601 timestamp recorded when DEUNA marked the card as verified. |
A payment verifies a card only after its transaction reaches processing, processed, authorized, or captured. Failed and pending transactions do not verify the card. See Card tokenization for how verification relates to stored-card reuse.
Remove a stored wallet account
DELETE /users/payment-methods/{payment_method_id}/tokens/{payment_method}
Removes the authenticated user's stored wallet account and its reusable consent. See Consent flows.
cURL example
curl --request DELETE \
--url 'https://api.sandbox.deuna.io/users/payment-methods/{payment_method_id}/tokens/{payment_method}' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'X-Merchant-ID: MERCHANT_ID'const response = await fetch("https://api.sandbox.deuna.io/users/payment-methods/{payment_method_id}/tokens/{payment_method}", {
method: "DELETE",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Merchant-ID": "MERCHANT_ID"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"DELETE",
"https://api.sandbox.deuna.io/users/payment-methods/{payment_method_id}/tokens/{payment_method}",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"X-Merchant-ID": "MERCHANT_ID"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/users/payment-methods/{payment_method_id}/tokens/{payment_method}",
CURLOPT_CUSTOMREQUEST => "DELETE",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"X-Merchant-ID: MERCHANT_ID"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/users/payment-methods/{payment_method_id}/tokens/{payment_method}"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("X-Merchant-ID", "MERCHANT_ID")
.method("DELETE", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("DELETE", "https://api.sandbox.deuna.io/users/payment-methods/{payment_method_id}/tokens/{payment_method}", nil)
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("X-Merchant-ID", "MERCHANT_ID")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Get card BIN information
GET /cards/bin/{bin}
Returns card network, issuer, and type metadata for a six-digit BIN.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/cards/bin/{bin}' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'X-Merchant-Id: MERCHANT_ID'const response = await fetch("https://api.sandbox.deuna.io/cards/bin/{bin}", {
method: "GET",
headers: {
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-Id": "MERCHANT_ID"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/cards/bin/{bin}",
headers={
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-Id": "MERCHANT_ID"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/cards/bin/{bin}",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"X-Merchant-Id: MERCHANT_ID"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/cards/bin/{bin}"))
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("X-Merchant-Id", "MERCHANT_ID")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/cards/bin/{bin}", nil)
if err != nil { panic(err) }
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("X-Merchant-Id", "MERCHANT_ID")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Merchant API#
Payment methods
GET /merchants/stores/payments-methods
Returns the payment methods enabled for a store. Pass the store code in the required X-Store-Code header.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/merchants/stores/payments-methods' \
--header 'X-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'X-Idempotency-Key: IDEMPOTENCY_KEY' \
--header 'X-Merchant-Id: MERCHANT_ID' \
--header 'X-Prediction-Id: PREDICTION_ID_VALUE' \
--header 'X-Store-Code: STORE_CODE'const response = await fetch("https://api.sandbox.deuna.io/merchants/stores/payments-methods", {
method: "GET",
headers: {
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Idempotency-Key": "IDEMPOTENCY_KEY",
"X-Merchant-Id": "MERCHANT_ID",
"X-Prediction-Id": "PREDICTION_ID_VALUE",
"X-Store-Code": "STORE_CODE"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/merchants/stores/payments-methods",
headers={
"X-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Idempotency-Key": "IDEMPOTENCY_KEY",
"X-Merchant-Id": "MERCHANT_ID",
"X-Prediction-Id": "PREDICTION_ID_VALUE",
"X-Store-Code": "STORE_CODE"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/merchants/stores/payments-methods",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"X-Api-Key: YOUR_PRIVATE_API_KEY",
"X-Idempotency-Key: IDEMPOTENCY_KEY",
"X-Merchant-Id: MERCHANT_ID",
"X-Prediction-Id: PREDICTION_ID_VALUE",
"X-Store-Code: STORE_CODE"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/merchants/stores/payments-methods"))
.header("X-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("X-Idempotency-Key", "IDEMPOTENCY_KEY")
.header("X-Merchant-Id", "MERCHANT_ID")
.header("X-Prediction-Id", "PREDICTION_ID_VALUE")
.header("X-Store-Code", "STORE_CODE")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/merchants/stores/payments-methods", nil)
if err != nil { panic(err) }
request.Header.Set("X-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("X-Idempotency-Key", "IDEMPOTENCY_KEY")
request.Header.Set("X-Merchant-Id", "MERCHANT_ID")
request.Header.Set("X-Prediction-Id", "PREDICTION_ID_VALUE")
request.Header.Set("X-Store-Code", "STORE_CODE")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Payment Links API#
POST /merchants/payment-links
Creates a payment link from a trusted merchant backend.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/merchants/payment-links' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/merchants/payment-links", {
method: "POST",
headers: {
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/merchants/payment-links",
headers={
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/merchants/payment-links",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/merchants/payment-links"))
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/merchants/payment-links", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}GET /merchants/payment-links/{payment_link_id}
Retrieves a payment link and its current state.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/merchants/payment-links/{payment_link_id}'const response = await fetch("https://api.sandbox.deuna.io/merchants/payment-links/{payment_link_id}", {
method: "GET"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/merchants/payment-links/{payment_link_id}",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/merchants/payment-links/{payment_link_id}",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/merchants/payment-links/{payment_link_id}"))
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/merchants/payment-links/{payment_link_id}", nil)
if err != nil { panic(err) }
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}PATCH /merchants/payment-links/{payment_link_id}
Updates an existing payment link.
cURL example
curl --request PATCH \
--url 'https://api.sandbox.deuna.io/merchants/payment-links/{payment_link_id}' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/merchants/payment-links/{payment_link_id}", {
method: "PATCH",
headers: {
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"PATCH",
"https://api.sandbox.deuna.io/merchants/payment-links/{payment_link_id}",
headers={
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/merchants/payment-links/{payment_link_id}",
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/merchants/payment-links/{payment_link_id}"))
.header("Content-Type", "application/json")
.method("PATCH", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("PATCH", "https://api.sandbox.deuna.io/merchants/payment-links/{payment_link_id}", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}See the Payment Links integration guide for the end-to-end flow.
Subscriptions API#
Plans
GET /subscriptions/plans
Lists subscription plans available to the authenticated merchant.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/subscriptions/plans' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'x-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'X-Merchant-ID: MERCHANT_ID'const response = await fetch("https://api.sandbox.deuna.io/subscriptions/plans", {
method: "GET",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"x-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-ID": "MERCHANT_ID"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/subscriptions/plans",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"x-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-ID": "MERCHANT_ID"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/subscriptions/plans",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"x-Api-Key: YOUR_PRIVATE_API_KEY",
"X-Merchant-ID: MERCHANT_ID"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/subscriptions/plans"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("x-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("X-Merchant-ID", "MERCHANT_ID")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/subscriptions/plans", nil)
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("x-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("X-Merchant-ID", "MERCHANT_ID")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}POST /subscriptions/plans
Creates a subscription plan.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/subscriptions/plans' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'x-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'X-Merchant-ID: MERCHANT_ID' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/subscriptions/plans", {
method: "POST",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"x-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-ID": "MERCHANT_ID",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/subscriptions/plans",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"x-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-ID": "MERCHANT_ID",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/subscriptions/plans",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"x-Api-Key: YOUR_PRIVATE_API_KEY",
"X-Merchant-ID: MERCHANT_ID",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/subscriptions/plans"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("x-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("X-Merchant-ID", "MERCHANT_ID")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/subscriptions/plans", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("x-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("X-Merchant-ID", "MERCHANT_ID")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Subscriptions
List subscriptions
GET /subscriptions
Returns subscriptions available to the authenticated merchant.
cURL example
curl --request GET \
--url 'https://api.sandbox.deuna.io/subscriptions' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'x-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'X-Merchant-ID: MERCHANT_ID'const response = await fetch("https://api.sandbox.deuna.io/subscriptions", {
method: "GET",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"x-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-ID": "MERCHANT_ID"
}
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"GET",
"https://api.sandbox.deuna.io/subscriptions",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"x-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-ID": "MERCHANT_ID"
},
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/subscriptions",
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"x-Api-Key: YOUR_PRIVATE_API_KEY",
"X-Merchant-ID: MERCHANT_ID"
]
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/subscriptions"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("x-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("X-Merchant-ID", "MERCHANT_ID")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
)
func main() {
request, err := http.NewRequest("GET", "https://api.sandbox.deuna.io/subscriptions", nil)
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("x-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("X-Merchant-ID", "MERCHANT_ID")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Create a subscription
POST /subscriptions
Creates a subscription using an existing plan and payment method.
cURL example
curl --request POST \
--url 'https://api.sandbox.deuna.io/subscriptions' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'x-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'X-Merchant-ID: MERCHANT_ID' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/subscriptions", {
method: "POST",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"x-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-ID": "MERCHANT_ID",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"POST",
"https://api.sandbox.deuna.io/subscriptions",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"x-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-ID": "MERCHANT_ID",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/subscriptions",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"x-Api-Key: YOUR_PRIVATE_API_KEY",
"X-Merchant-ID: MERCHANT_ID",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/subscriptions"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("x-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("X-Merchant-ID", "MERCHANT_ID")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("POST", "https://api.sandbox.deuna.io/subscriptions", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("x-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("X-Merchant-ID", "MERCHANT_ID")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}Update a subscription
PATCH /subscriptions/{id}
Updates an active subscription’s supported attributes.
cURL example
curl --request PATCH \
--url 'https://api.sandbox.deuna.io/subscriptions/{id}' \
--header 'Authorization: Bearer USER_ACCESS_TOKEN' \
--header 'x-Api-Key: YOUR_PRIVATE_API_KEY' \
--header 'X-Merchant-ID: MERCHANT_ID' \
--header 'Content-Type: application/json' \
--data @request.jsonconst response = await fetch("https://api.sandbox.deuna.io/subscriptions/{id}", {
method: "PATCH",
headers: {
"Authorization": "Bearer USER_ACCESS_TOKEN",
"x-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-ID": "MERCHANT_ID",
"Content-Type": "application/json"
},
body: "@request.json"
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();import requests
response = requests.request(
"PATCH",
"https://api.sandbox.deuna.io/subscriptions/{id}",
headers={
"Authorization": "Bearer USER_ACCESS_TOKEN",
"x-Api-Key": "YOUR_PRIVATE_API_KEY",
"X-Merchant-ID": "MERCHANT_ID",
"Content-Type": "application/json"
},
data="@request.json",
)
response.raise_for_status()
data = response.json()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.deuna.io/subscriptions/{id}",
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
"Authorization: Bearer USER_ACCESS_TOKEN",
"x-Api-Key: YOUR_PRIVATE_API_KEY",
"X-Merchant-ID: MERCHANT_ID",
"Content-Type: application/json"
],
CURLOPT_POSTFIELDS => "@request.json"
]);
$response = curl_exec($curl);
curl_close($curl);import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class Example {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.sandbox.deuna.io/subscriptions/{id}"))
.header("Authorization", "Bearer USER_ACCESS_TOKEN")
.header("x-Api-Key", "YOUR_PRIVATE_API_KEY")
.header("X-Merchant-ID", "MERCHANT_ID")
.header("Content-Type", "application/json")
.method("PATCH", HttpRequest.BodyPublishers.ofString("@request.json"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request, HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
request, err := http.NewRequest("PATCH", "https://api.sandbox.deuna.io/subscriptions/{id}", strings.NewReader("@request.json"))
if err != nil { panic(err) }
request.Header.Set("Authorization", "Bearer USER_ACCESS_TOKEN")
request.Header.Set("x-Api-Key", "YOUR_PRIVATE_API_KEY")
request.Header.Set("X-Merchant-ID", "MERCHANT_ID")
request.Header.Set("Content-Type", "application/json")
response, err := http.DefaultClient.Do(request)
if err != nil { panic(err) }
defer response.Body.Close()
body, _ := io.ReadAll(response.Body)
fmt.Println(string(body))
}