Quickstart
Take your first payment in five steps, from a new account to a fulfilled order.
Before you start
| You need | Why |
|---|---|
| A 402pay account | It owns your wallet, your keys and every payment. |
| A server | Secret keys only ever live on a server, never in a browser or app. |
| A public HTTPS endpoint | For the webhook that tells you when a payment succeeds. |
url.- 1
Create an account
Sign up with your email and a passkey or a password, enter the code we email you, then add your business and create its wallet. It takes a few minutes. Create an account.
- 2
Create a secret key
In the dashboard, open Developers, then API keys, and create a test key. Its secret starts with
402s_test_and is shown once, so put it in your server's environment.Shellexport PAY402_SECRET_KEY="402s_test_..."During the beta, test and live keys act on the same business: what you create with a test key shows up in your dashboard and in every list, like anything else, and every event'smodeislive. On a live business a test key can read everything, but creating a payment, a checkout or a remainder, or changing what customers see or pay, answers 403test_mode_unavailable, so a test key never moves real money or changes a live checkout. See test and live keys. - 3
Create a payment
Create it from your server when the customer is ready to pay. The response carries a hosted checkout
url.cURLcurl -X POST "https://dash.402pay.co/api/v1/payments" \ -H "Authorization: Bearer $PAY402_SECRET_KEY" \ -H "Content-Type: application/json" \ -d '{ "amount": 4900, "currency": "USD", "reference": "order_1042", "description": "Pro plan, monthly", "success_url": "https://example.com/thanks" }' - 4
Send the customer to checkout
Redirect to the payment's
url. Checkout handles the coin and network, cards, short transfers and the receipt, then sends the customer to yoursuccess_url. - 5
Fulfill the order on a webhook
Add a webhook endpoint for
payment.succeeded, in the dashboard under Developers, then Webhooks, or through the API. Itsurlmust be a publichttps://address, solocalhostand private networks are refused. Save the signing secret in the response: it's shown once.cURLcurl -X POST "https://dash.402pay.co/api/v1/webhooks" \ -H "Authorization: Bearer $PAY402_SECRET_KEY" \ -H "Content-Type: application/json" \ -d '{ "url": "https://example.com/webhooks/402pay", "event_types": ["payment.succeeded"], "description": "Fulfill orders" }'When it arrives, verify the signature and fulfill the order its
referencepoints to.webhooks.jsNode.js// Fulfill once, when the payment succeeds.app.post("/webhooks/402pay", express.raw({ type: "application/json" }), async (req, res) => { if (!verifyWebhook(process.env.PAY402_WEBHOOK_SECRET, req.headers, req.body)) { return res.sendStatus(400); } res.sendStatus(200); const event = JSON.parse(req.body); // A test delivery names a made-up payment, and its data holds only that id. if (event.test) return; if (event.type === "payment.succeeded") { await orders.markPaid(event.data.reference, event.data.id); }});Each delivery is a signed HTTPS request to your endpoint. A local 402pay sends nothing and records each delivery with its signed request and a 200 response. Either way, read every attempt under Developers, then Webhooks, or withGET /webhook-deliveries. See live and simulated businesses.
Next steps
- Testing Build with test keys and rehearse every way a payment can arrive.
- Going live Everything to check before you take real payments, and after.
- Hosted checkout Everything between choosing how to pay and the receipt, on one hosted page.
- Underpayments and overpayments What happens when a customer sends too little, too much, too late or on the wrong network.