Knowledgebase

Working With Payment Provider APIs Print

  • 0

Money over an interface.

WHAT MAKES THEM DIFFERENT

Errors have financial consequences Outcomes may be uncertain Regulation applies

WHAT TO NEVER DO

Handle raw card details yourself, unless you are equipped for that obligation.

WHAT TO DO INSTEAD

Use the provider's hosted fields or redirect, so the details never reach your server.

WHAT AN IDEMPOTENCY KEY IS FOR HERE

Ensuring a retried charge does not charge twice.

WHAT TO TREAT A TIMEOUT AS

Unknown, never failure.

WHAT TO DO ABOUT IT

Query the transaction's status before acting.

WHAT TO RELY ON FOR THE FINAL OUTCOME

The provider's notification, not the immediate response.

WHY

Payments complete asynchronously, and the initial response is not the end.

WHAT TO VERIFY ON EVERY NOTIFICATION

The signature That the amount and currency match what you expected That you have not already processed it

WHY THE AMOUNT CHECK MATTERS

It prevents a forged or altered notification granting value.

WHAT TO RECORD

Every request and response, with identifiers.

WHY

Disputes are resolved from records.

WHAT TO RECONCILE

Your records against the provider's settlement reports.

HOW OFTEN

Daily.

WHAT TO BUILD

A way to see a transaction's full history.

WHAT TO TEST

Failed payments, refunds and disputes, not only success.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot