Paiements
Créer un paiement
POST/v1/payment-intentspayments:write
Requires payments:write. Cookie mutations require CSRF; connection mutations also require recent MFA. No client_secret is returned. On a live connection, once the space's offered 500 € are collected without a PayHaze subscription: 402 production_offer_used, nothing is created (D21, D25).
En-têtes
AuthorizationBearer pos_key_…obligatoire- Clé de serveur, pour tout l’espace. Jamais dans un navigateur.
X-Merchant-IDstringobligatoire- L’espace marchand concerné (mrc_…).
Idempotency-Keystringobligatoire
Corps
merchant_referencestring, 1 à 128obligatoireamountstringobligatoire- EUR decimal string, local initial profile 0.50..999999.99; exact integer conversion.
currency"EUR"obligatoirecapture_mode"automatic" | "manual"obligatoire- Manual requires the connected account capability. One final capture, including partial capture when supported.
connection_idstring- The account to use. Omit it (or send an empty string) to let PayHaze route the payment: admissible accounts only (capture mode, currency, health, daily cap), then the active rules or PayHaze's lowest estimated cost. The decision is stored and readable at /v1/payment-intents/{id}/route; the payment never changes account afterwards.
payment_method_idstring- A saved method of the register (18c): charged at once on its own account, which is chosen for it (connection_id may be omitted); never presented to another account (409 payment_method_not_portable). The buyer is present: if the bank asks for them, the state is REQUIRES_ACTION and a checkout session (with return_url) lets them confirm. Unknown in this space: 404 payment_method_not_found; revoked: 409 payment_method_revoked. Nothing is created by a refused request.
customer_referencestring, 1 à 128- The buyer as the shop names them (e.g. wc-customer-42), without control characters. Required with save_method; with payment_method_id it must be the saved method's own buyer (else 400).
save_methodobject- The buyer agreed on the shop to keep their card for their next purchases and for payments the merchant starts without them (18c, contrat C4). Card and wallets only. Once the payment succeeds or is authorized, the card enters the register (usage merchant_initiated, consent source checkout) and saved_method shows it. Not with payment_method_id. An account that cannot keep a card (Adyen, Checkout.com): 409 capability_unsupported, nothing is created.
Réponses
- 202Demande enregistrée
- 400Requête invalide
- 401Clé absente ou invalide
- 402Service restreint
- 403Autorisation ou espace refusé
- 404Ressource introuvable
- 409Conflit avec une demande existante
- 422Impossible à traiter
- 429Trop de demandes, réessayez plus tard
- 503Service momentanément indisponible
Une erreur ne vaut jamais paiement. Le corps donne code, message, request_id et retry_action ; renvoyez la même Idempotency-Key si retry_action le propose.