Skip to content

Quickstart

Accept your first payment in five steps, from a new account to a fulfilled order.

Before you start

You needWhy
A 402pay accountIt owns your wallet, your keys and every payment.
A serverSecret keys only ever live on a server, never in a browser or app.
A public HTTPS endpointFor the webhook that tells you when a payment succeeds.
Never put a secret key in browser or mobile code. Anyone who opens the developer tools could read it and act as your business. Create payments on your server and send the customer only the checkout url.
  1. 1

    Create an account

    Sign up with your email and a passkey or a password, enter the code we email you, then add your business and create its wallet. It takes a few minutes. Create an account.

  2. 2

    Create a secret key

    In the dashboard, open Developers, then API keys, and create a secret key. Its secret starts with 402s_live_ and is shown once, so put it in your server's environment.

    Shell
    export PAY402_SECRET_KEY="402s_live_..."
    There is no test mode: every payment you create is real and moves real money, so start with small amounts.
  3. 3

    Create a payment

    Create it from your server when the customer is ready to pay. The response carries a hosted checkout url.

    cURL
    curl -X POST "https://api.402pay.co/api/v1/payments" \
      -H "Authorization: Bearer $PAY402_SECRET_KEY" \
      -H "Content-Type: application/json" \
      -d '{
        "amount": "49.00",
        "currency": "USD",
        "reference": "order_1042",
        "description": "Pro plan, monthly",
        "success_url": "https://example.com/thanks"
      }'
  4. 4

    Send the customer to checkout

    Redirect to the payment's url. Checkout handles the coin and network, cards, short transfers and the receipt, then sends the customer to your success_url.

  5. 5

    Fulfill the order on a webhook

    Add a webhook endpoint for payment.succeeded, in the dashboard under Developers, then Webhooks, or through the API. Its url must be a public https:// address, so localhost and private networks are refused. Save the signing secret in the response: it's shown once.

    cURL
    curl -X POST "https://api.402pay.co/api/v1/webhooks" \
      -H "Authorization: Bearer $PAY402_SECRET_KEY" \
      -H "Content-Type: application/json" \
      -d '{
        "url": "https://example.com/webhooks/402pay",
        "event_types": ["payment.succeeded"],
        "description": "Fulfill orders"
      }'

    When it arrives, verify the signature and fulfill the order its reference points to.

    webhooks.jsNode.js
    // Fulfill once, when the payment succeeds.
    app.post("/webhooks/402pay", express.raw({ type: "application/json" }), async (req, res) => {
      if (!verifyWebhook(process.env.PAY402_WEBHOOK_SECRET, req.headers, req.body)) {
        return res.sendStatus(400);
      }
      res.sendStatus(200);
    
      const event = JSON.parse(req.body);
      // A test delivery names a made-up payment, and its data holds only that id.
      if (event.test) return;
      if (event.type === "payment.succeeded") {
        await orders.markPaid(event.data.reference, event.data.id);
      }
    });
    Each delivery is a signed HTTPS request to your endpoint. Read every attempt under Developers, then Webhooks, or with GET /webhook-deliveries.

Next steps