Skip to main content

Use this merchant-backend operation to process an existing order token or an order supplied in the request. DEUNA applies the payment connections, routing, risk, and capture behavior configured for the merchant.

Headers#

4
X-Api-KeystringRequired
Private merchant application key validated by the API Gateway.
Example YOUR_PRIVATE_API_KEY
AuthorizationstringOptional
Optional authenticated-user context for customer-specific payment methods and stored instruments.
Example Bearer USER_ACCESS_TOKEN
X-Store-CodestringOptional
Store context when the merchant has store-specific configuration.
Example main
Content-TypestringRequired
Must be application/json.

Path parameters#

0
This endpoint has no path parameters.

Request body#

8
order_tokenstringOptional
Token of an existing order. Supply either this field or an order object that DEUNA can create.
orderobjectOptional
Inline order details when the payment should create and process the order in one request.
payer_infoobjectRequired
Customer identity. The API validates that payer_info.email is present.
Show child attributes
payer_info.emailstringRequired
Customer email used to identify the payer.
payer_info.external_user_idstringOptional
Customer identifier in the merchant system.
payment_sourceobjectRequired
The instrument and connection data used to process the payment.
Show child attributes
payment_source.method_typestringRequired
Payment method type, such as credit_card or a supported wallet.
payment_source.payment_methodstringOptional
Token produced by a DEUNA client integration.
payment_source.payment_method_idstringOptional
Merchant payment processor identifier when the flow requires one.
payment_source.card_infoobjectOptional
Tokenized or PCI-compliant card details for card flows.
anti_fraud_infoobjectOptional
Customer, device, browser, and risk context consumed by configured anti-fraud services.
callback_urlsobjectOptional
Customer redirect destinations for success, pending, rejection, cancellation, or failure states.
specific_fieldsobjectOptional
Provider- or payment-method-specific fields required by the selected connection.
subscriptionobjectOptional
Subscription context when the purchase creates or renews a supported subscription.

Start with a complete industry order#

The order field above accepts the same business context modeled by the Orders API. For a clearer recovery and retry flow, create the order first, keep its order_token, and send the token in this request.

Response#

Returns the processed order, including its order_token, order type, resulting status, payment information, and subscription information when applicable. Treat the returned state as authoritative and continue asynchronous tracking through merchant webhooks.

Status codes

200The order payment was processed. Inspect the returned order and payment status for the business outcome.
400The request is invalid or lacks required payer or payment-source data.
401The private API key or customer authorization context is invalid.
409The operation conflicts with the current order state or with a previous idempotent request.
429The rate limit was exceeded. Honor Retry-After when returned.

Idempotency#

The Gateway applies idempotency to this purchase operation. Send a stable X-Idempotency-Key for the same business attempt and reuse the same key and body after a network timeout. Use a new key for a materially different attempt.

  • Generate the key in the merchant backend, not in browser or mobile code.
  • Never reuse a key with a different request body.
  • Reconcile an uncertain outcome by retrieving the order before starting a new attempt.

See the complete endpoint entry, Authentication, and Error codes.