The Get Payment Details API allows merchants to fetch tokenized card payment details and generate a transaction-specific cryptographic authentication value (cryptogram / TAVV) from the card network or token service provider (TSP) to authenticate online card transactions.
Endpoint & Environments
| Environment | Method | URL |
|---|---|---|
| Test | POST | <redacted URL> |
| Production | POST | <redacted URL> |
Headers
| Parameter | Description |
|---|---|
| date | The current date and time. For example, format of the date is Wed, 28 Jun 2023 11:25:19 GMT. |
| authorization | The actual HMAC signature generated using the specified algorithm (sha512) and includes the hashed data. For more information, refer to authorization fields description. |
authorization fields description
| Field | Description |
|---|---|
| username | Represents the username or identifier for the client or merchant, for example smsplus. |
| algorithm | Use SHA512 algorithm for hashing and send this as header value. |
| headers | Specifies which headers have been used in generating the hash, for example date. |
| signature | The HMAC signature generated using the specified algorithm. For more information, refer to hashing algorithm. |
hashing algorithm
You must hash the request parameters using the following hash logic:
Hash logic: sha512(`<Body data>` + '|' + date + '|' + merchant_secret)
Where <Body data> contains the request body posted with the request.
Sample header code
var merchant_key = '<YOUR_TEST_KEY>';
var merchant_secret = 'YOUR_TEST_SALT';
// date
var date = new Date();
date = date.toUTCString();
// authorization
var authorization = getAuthHeader(date);
function getAuthHeader(date) {
var AUTH_TYPE = 'sha512';
var data = isEmpty(request['data']) ? "" : request['data'];
var hash_string = data + '|' + date + '|' + merchant_secret;
var hash = CryptoJS.SHA512(hash_string).toString(CryptoJS.enc.Hex);
return `hmac username="${merchant_key}", algorithm="${AUTH_TYPE}", headers="date", signature="${hash}"`;
}Request Parameters
The table has 5 rows, so here it is in Markdown format:
Mandatory parameters
| Parameter | Description |
|---|---|
userCredential | String Plaintext identifier representing merchant key and customer ID in format <merchantKey>:<customerId> (e.g. sms:user12345). Max 100 characters. |
cardToken | String The unique card token identifier representing the saved card. |
amount | Number Transaction amount (e.g. 1000.00). Cryptograms are cryptographically bound to the amount. |
currency_type | String 3-letter currency code (e.g. INR). |
Optional parameters
| Parameter | Description |
|---|---|
source | String Channel identifier (e.g. merchant_web, merchant_app). |
Sample Request
curl --location --request POST '<redacted URL>' \
--header 'Content-Type: application/json' \
--header 'Date: Mon, 05 Oct 2026 08:30:00 GMT' \
--header 'Authorization: hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"' \
--data-raw '{
"userCredential": "sms:user12345",
"cardToken": "29850879bf39848ca078727b8e1a95165a41cea1",
"amount": 1000.00,
"currency_type": "INR",
"source": "merchant_web"
}'import requests
url = "<redacted URL>"
payload = {
"userCredential": "sms:user12345",
"cardToken": "29850879bf39848ca078727b8e1a95165a41cea1",
"amount": 1000.00,
"currency_type": "INR",
"source": "merchant_web"
}
headers = {
"Content-Type": "application/json",
"Date": "Mon, 05 Oct 2026 08:30:00 GMT",
"Authorization": 'hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
}
response = requests.post(url, headers=headers, json=payload)
print(response.json())<?php
$curl = curl_init();
$payload = json_encode([
"userCredential" => "sms:user12345",
"cardToken" => "29850879bf39848ca078727b8e1a95165a41cea1",
"amount" => 1000.00,
"currency_type" => "INR",
"source" => "merchant_web"
]);
curl_setopt_array($curl, [
CURLOPT_URL => '<redacted URL>',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_POSTFIELDS => $payload,
CURLOPT_HTTPHEADER => [
'Content-Type: application/json',
'Date: Mon, 05 Oct 2026 08:30:00 GMT',
'Authorization: hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
],
]);
$response = curl_exec($curl);
curl_close($curl);
echo $response;import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class GetCryptogram {
public static void main(String[] args) throws Exception {
String payload = """
{
"userCredential": "sms:user12345",
"cardToken": "29850879bf39848ca078727b8e1a95165a41cea1",
"amount": 1000.00,
"currency_type": "INR",
"source": "merchant_web"
}
""";
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("<redacted URL>"))
.header("Content-Type", "application/json")
.header("Date", "Mon, 05 Oct 2026 08:30:00 GMT")
.header("Authorization", "hmac username=\"merchant_key\", algorithm=\"sha512\", headers=\"date\", signature=\"<SIGNATURE>\"")
.POST(HttpRequest.BodyPublishers.ofString(payload))
.build();
HttpClient client = HttpClient.newHttpClient();
HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
System.out.println(response.body());
}
}const axios = require('axios');
const data = {
userCredential: "sms:user12345",
cardToken: "29850879bf39848ca078727b8e1a95165a41cea1",
amount: 1000.00,
currency_type: "INR",
source: "merchant_web"
};
const config = {
method: 'post',
url: '<redacted URL>',
headers: {
'Content-Type': 'application/json',
'Date': 'Mon, 05 Oct 2026 08:30:00 GMT',
'Authorization': 'hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
},
data: data
};
axios(config)
.then(response => console.log(JSON.stringify(response.data)))
.catch(error => console.error(error));Response Parameters
| Parameter | Type | Description |
|---|---|---|
| status | Integer | Status indicator: 1 (Success) or 0 (Failure). |
| msg | String | Outcome description. |
| cardToken | String | The card token identifier queried. |
| cardNo | String | Masked card number (e.g. 512345XXXXXX2346). |
| cardName | String | Name of the cardholder. |
| cardType | String | Network brand (e.g. MAST, VISA, RUPAY). |
| cardMode | String | Card category: CC (Credit Card) or DC (Debit Card). |
| cryptogram | String | Base64-encoded Token Authentication Verification Value (TAVV / cryptogram) to pass into paymentCard.tavv for transaction processing. |
| eci | String | Electronic Commerce Indicator returned by the card network (e.g. 05, 07). |
| oneClickStatus | String | Status of 1-click checkout eligibility for this card instrument (ELIGIBLE / INELIGIBLE). |
| oneClickFlow | String | Supported 1-click checkout authorization flow (DEVICE_BINDING / OTP). |
| cardExpiryMonth | String | 2-digit expiry month. |
| cardExpiryYear | String | 4-digit expiry year. |
Sample Response (Success)
{
"status": 1,
"msg": "Cryptogram generated successfully",
"cardToken": "29850879bf39848ca078727b8e1a95165a41cea1",
"cardNo": "512345XXXXXX2346",
"cardName": "John Doe",
"cardType": "MAST",
"cardMode": "CC",
"cryptogram": "/wAAAAAAPtP+g6IAmbSeg1gAAAA=",
"eci": "05",
"oneClickStatus": "ELIGIBLE",
"oneClickFlow": "OTP",
"cardExpiryMonth": "12",
"cardExpiryYear": "2029"
}Sample Response (Failure)
{
"status": 0,
"msg": "Failed to fetch cryptogram from card network"
}Next Steps
- Pass Cryptogram to Payment API:
- Pass the returned
cryptogramstring intopaymentCard.tavvandeciintoauthorization.eciwhen calling the Using Network Tokens API or Process Transaction with a Saved Card API.
- Pass the returned
- Handle Timeouts & Expirations:
- Cryptograms possess short validity windows (typically 15 minutes). Ensure cryptograms are generated just prior to initiating the payment collection request.
