DocsTableau de bord

Caisse

Donner la carte saisie chez PayHaze (navigateur)

POST/checkout/{id}/card

21q, test cards only until PayHaze's PCI certification: offered when the checkout says card_fields=payhaze (the account takes PayHaze's cards). The card is checked (Luhn, expiry not past, security code of the brand's length), kept in PayHaze's vault for an hour at most, never logged nor stored by the platform; the security code is checked, then dropped. The worker then presents it to the account; a refusal another account may not repeat is tried again at once, once, at the best next account (Routing: retry_elsewhere). 400 invalid_card; 409 checkout_not_ready when the account takes no card from PayHaze or a card awaits its answer. Requires the HttpOnly cookie bound to this checkout ID, acquired by the one-use launch form. Merchant sessions and API keys do not grant buyer authority.

En-têtes

Originstringobligatoire

Paramètres

iddans le cheminobligatoire

Corps

numberstring, 0 à 32obligatoire
12 to 19 digits, spaces or dashes allowed.
exp_monthstringobligatoire
exp_yearstringobligatoire
cvcstringobligatoire

Réponses

202Demande enregistrée
400Requête invalide
401Clé absente ou invalide
403Autorisation ou espace refusé
404Ressource introuvable
409Conflit avec une demande existante
410N’existe plus
429Trop de demandes, réessayez plus tard
503Service momentanément indisponible

Une erreur ne vaut jamais paiement. Le corps donne code, message, request_id et retry_action ; renvoyez la même Idempotency-Key si retry_action le propose.