Skip to main content
0 of 4 complete
On this page

This Quickstart uses the merchant-backend purchase endpoint. Before you begin, complete account setup, choose your integration, and confirm that your sandbox merchant has:

  • A private API key stored on your server.
  • At least one active payment connection and a routing strategy.
  • An order token and a payment-method token created by your selected client integration.
  • A public HTTPS endpoint that can receive DEUNA webhooks.
01

Prepare the server request#

Load the sandbox private key from your server’s secret storage. Keep the order token and payment-method token produced by the same sandbox flow available for the request body.

.envShell
DEUNA_PRIVATE_API_KEY=YOUR_SANDBOX_PRIVATE_API_KEY
02

Process the order payment#

Send the order and tokenized payment method to the verified merchant purchase endpoint. Reuse the same X-Idempotency-Key and request body if a network timeout makes the outcome uncertain.

curl --request POST \
  --url https://api.sandbox.deuna.io/v2/merchants/orders/purchase \
  --header "X-Api-Key: ${DEUNA_PRIVATE_API_KEY}" \
  --header "X-Idempotency-Key: order_1042-attempt_1" \
  --header "Content-Type: application/json" \
  --data '{
    "order_token": "YOUR_SANDBOX_ORDER_TOKEN",
    "payer_info": {
      "email": "buyer@example.com",
      "external_user_id": "customer_1042"
    },
    "payment_source": {
      "method_type": "credit_card",
      "payment_method": "YOUR_PAYMENT_METHOD_TOKEN"
    }
  }'

The exact payment_source and any specific_fields depend on the selected payment method and provider. See Process an order payment for the complete request contract.

03

Handle the immediate result#

Read order.payment.data.status and any required next action from the returned order. An HTTP 2xx means DEUNA accepted or processed the request; it does not by itself prove that money moved.

  • Continue fulfillment only for the confirmed success state documented in Payment workflow and statuses.
  • Present any customer action, such as 3DS authentication, before retrying.
  • For pending or uncertain results, retrieve the original order instead of creating a duplicate attempt.
  • Use a new idempotency key only for a materially new payment attempt.
04

Confirm the final state#

Use the synchronous response to update the customer experience, but make fulfillment decisions from the latest verified state. Configure a merchant webhook, verify its signature, deduplicate the event, and then reconcile the order.

server.jsJavaScript
app.post('/webhooks/deuna', express.raw({type: 'application/json'}), async (request, response) => {
  const event = verifyDeunaSignature(request.body, request.headers);
  await storeEventOnce(event.id);
  await reconcileOrder(event.data.order_token);
  response.sendStatus(200);
});

Next steps#