Card payments
Collect a card payment by opening a hosted checkout, then confirm the result with a webhook. If the webhook does not arrive, read the payment with the status endpoint.
Both calls are POST to https://api.senjaropay.com. Send Content-Type: application/json, x-api-key, and x-api-secret.
Send x-idempotency-key only on POST /senjaropay/merchant/card/pay. The status call does not use it.
Authentication
Generate the idempotency key in your backend when you create a payment. Do not reuse a key across different payments.
Reuse a key only when you are retrying the same card payment request (same amount, customer, and webhook). A repeated key returns the original result and does not open a second checkout.
Create a card payment
SenjaroPay creates a pending payment and returns checkout_url. Redirect the customer to that URL to enter card details. Store data.reference. You will need it for webhooks and for status checks.
The session stops accepting payment at data.expires_at.
Request
Response
data.status is pending until the customer finishes checkout. Do not fulfill the order on this response.
Request fields
Check status
Use this when the webhook is late, dropped, or fails your signature check. It reads the payment. It does not create a new charge.
Pass the reference returned by card pay. Authenticate with x-api-key and x-api-secret only.
Request
Response
Poll with backoff, and stop when data.status is no longer pending or when expires_at from the create response has passed. Make fulfillment idempotent on reference so a late webhook and a status check cannot both fulfill the same order.
Errors
Examples on this page are mock values. Keep API keys in server-side secrets.
