Caisse
Donner la carte saisie chez PayHaze (navigateur)
POST/checkout/{id}/card
21q, test cards only until PayHaze's PCI certification: offered when the checkout says card_fields=payhaze (the account takes PayHaze's cards). The card is checked (Luhn, expiry not past, security code of the brand's length), kept in PayHaze's vault for an hour at most, never logged nor stored by the platform; the security code is checked, then dropped. The worker then presents it to the account; a refusal another account may not repeat is tried again at once, once, at the best next account (Routing: retry_elsewhere). 400 invalid_card; 409 checkout_not_ready when the account takes no card from PayHaze or a card awaits its answer. Requires the HttpOnly cookie bound to this checkout ID, acquired by the one-use launch form. Merchant sessions and API keys do not grant buyer authority.
En-têtes
Originstringobligatoire
Paramètres
iddans le cheminobligatoire
Corps
numberstring, 0 à 32obligatoire- 12 to 19 digits, spaces or dashes allowed.
exp_monthstringobligatoireexp_yearstringobligatoirecvcstringobligatoire
Réponses
- 202Demande enregistrée
- 400Requête invalide
- 401Clé absente ou invalide
- 403Autorisation ou espace refusé
- 404Ressource introuvable
- 409Conflit avec une demande existante
- 410N’existe plus
- 429Trop de demandes, réessayez plus tard
- 503Service momentanément indisponible
Une erreur ne vaut jamais paiement. Le corps donne code, message, request_id et retry_action ; renvoyez la même Idempotency-Key si retry_action le propose.