Classic Integration
You can collect card payments using classic seamless integration. For seamless Classic integration, the additionalInfo.txnS2sFlow field is set to 4.
The Classic Seamless Integration supports both physical card details and saved card tokens, providing a complete server-to-server payment solution with 3DS authentication redirection.
Environment
| Test Environment | https://apitest.payu.in/v2/payments |
| Production Environment | https://api.payu.in/v2/payments |
Request header
| Parameter | Description |
|---|---|
| date | The current date and time. For example, format of the date is Wed, 28 Jun 2023 11:25:19 GMT. |
| authorization | The actual HMAC signature generated using the specified algorithm (sha512) and includes the hashed data. For more information, refer to authorization fields description. |
authorization fields description
| Field | Description |
|---|---|
| username | Represents the username or identifier for the client or merchant, for example smsplus. |
| algorithm | Use SHA512 algorithm for hashing and send this as header value. |
| headers | Specifies which headers have been used in generating the hash, for example date. |
| signature | The HMAC signature generated using the specified algorithm. For more information, refer to hashing algorithm. |
hashing algorithm
You must hash the request parameters using the following hash logic:
Hash logic: sha512(`<Body data>` + '|' + date + '|' + merchant_secret)
Where <Body data> contains the request body posted with the request.
Sample header code
var merchant_key = '<YOUR_TEST_KEY>';
var merchant_secret = 'YOUR_TEST_SALT';
// date
var date = new Date();
date = date.toUTCString();
// authorization
var authorization = getAuthHeader(date);
function getAuthHeader(date) {
var AUTH_TYPE = 'sha512';
var data = isEmpty(request['data']) ? "" : request['data'];
var hash_string = data + '|' + date + '|' + merchant_secret;
var hash = CryptoJS.SHA512(hash_string).toString(CryptoJS.enc.Hex);
return `hmac username="${merchant_key}", algorithm="${AUTH_TYPE}", headers="date", signature="${hash}"`;
}Request body
The table has 7 rows, so here it is in HTML format:
Mandatory parameters
| Parameter | Description |
|---|---|
name | String Set to "CreditCard" or "DebitCard". |
paymentCard | Object Token details issued by the card network. |
paymentCard.cardToken | String Network token string issued by Visa, Mastercard, or RuPay. |
paymentCard.cardTokenType | String Set to "NETWORK". |
paymentCard.tavv | String Dynamic cryptogram generated for the transaction (obtained via Get Payment Details API). |
paymentCard.last4Digits | String Last 4 digits of the underlying primary account number (e.g. "2346"). |
Optional parameters
| Parameter | Description |
|---|---|
paymentCard.cvv | String 3-digit CVV (if required by merchant terminal profile). |
paymentMethod object fields description
Mandatory parameters
| Parameter | Description | Example |
|---|---|---|
name | String This field must contain the payment mode code. For Classic Integration, use "CreditCard" or "DebitCard". For more information, refer to Payment Mode Codes. | CreditCard |
bankCode | String This field must contain the card type code. For more information, refer to Card Type Codes and Supported Banks for Cards. | CC |
Conditional parameters
| Parameter | Description | Example |
|---|---|---|
paymentCard | Object This object contains the physical card or saved card token details. For more information, refer to paymentCard object fields description. Mandatory for cards. |
paymentCard object fields description
| Parameter | Description | Example |
|---|---|---|
cardNumbermandatory for physical card |
Card number. | 5***77***517***7 |
validThroughmandatory for physical card |
Expiry date in MM/YYYY format. | |
ownerNameoptional |
Name of the card owner. | |
cvvmandatory for physical card |
CVV number of the card. | 123 |
tavvmandatory for saved card |
Cryptogram of the card for tokenized payments. | AAABA***mQAAAABjRWWZEEFgFz |
last4Digitsmandatory for saved card |
Last four digits of the card. | 0603 |
cardTokenTypemandatory for saved card |
Card token type. Valid values: PAYU, NETWORK, ISSUER. | PAYU |
cardTokenmandatory for saved card |
Card token of the stored card. | b5**7857680876***m9 |
order object fields description
| Parameter | Description | Example |
|---|---|---|
productInfomandatory | Product details. Type: String | Product details |
orderedItemoptional | Details about the items ordered. Type: Array of Objects | |
userDefinedFieldsoptional | Custom fields for additional information. Type: Object. Fields: udf1, udf2, udf3, udf4, udf5, udf6, udf7, udf8, udf9, udf10. | |
paymentChargeSpecificationmandatory | Includes amount and charges. Type: Object. For more information, refer to paymentChargeSpecification object fields description |
paymentChargeSpecification object fields description
| Parameter | Description | Example |
|---|---|---|
pricemandatory | The transaction amount. Type: Number | 1000 |
netAmountDebitoptional | Net amount to be debited. Type: Number | 1000 |
taxSpecificationoptional | Tax details of the product/order. Type: Object | |
convenienceFeeoptional | Fees format. Type: String | CC:12 |
offersoptional | Offers applied or available for the payment. Type: Object |
userDefinedFields object fields description
| Field | Description |
|---|---|
| udf1 | User defined field. |
| udf2 | User defined field. |
| udf3 | User defined field. |
| udf4 | User defined field. |
| udf5 | User defined field. |
| udf6 | User defined field. |
| udf7 | User defined field. |
| udf8 | User defined field. |
| udf9 | User defined field. |
| udf10 | User defined field. |
additionalInfo object fields description
Conditional parameters
| Parameter | Description | Example |
|---|---|---|
txnS2sFlow | String Indicates the transaction S2S flow type and must be set to "4" for Classic Integration. Mandatory for S2S. | 4 |
Recommended parameters
| Parameter | Description | Example |
|---|---|---|
authenticationFlow | String Indicates the authentication flow type. Set to "REDIRECT" for Classic 3DS redirection. | REDIRECT |
Optional parameters
| Parameter | Description | Example |
|---|---|---|
createOrder | Boolean Whether to create an order during the payment process. | false |
preAuthorize | String Set to "1" for authorization-only transactions. | 1 |
callBackActions object fields description
Mandatory parameters
| Parameter | Description | Example |
|---|---|---|
successAction | String URL where the customer is redirected upon successful payment. | <redacted URL> |
failureAction | String URL where the customer is redirected upon failed payment. | <redacted URL> |
Optional parameters
| Parameter | Description | Example |
|---|---|---|
cancelAction | String URL where the customer is redirected if the transaction is cancelled. | <redacted URL> |
billingDetails object fields description
| Parameter | Description | Example |
|---|---|---|
firstNamemandatory |
First name of the billing contact. | Ashish |
lastNameoptional |
Last name of the billing contact. | Kumar |
address1mandatory |
Primary billing address. | 123 Main Street |
address2optional |
Secondary billing address. | Apt 4B |
phoneoptional |
Phone number of the billing contact. | 9123456789 |
emailmandatory |
Email address of the billing contact. | [email protected] |
cityoptional |
City of the billing address. | Bharatpur |
stateoptional |
State of the billing address. | Rajasthan |
countryoptional |
Country of the billing address. | India |
zipCodeoptional |
Postal/Zip code of the billing address. | 321028 |
Sample request
curl --location '<redacted URL>' \
--header 'date: <CURRENT_DATE_GMT>' \
--header 'authorization: hmac username="<YOUR_TEST_KEY>", algorithm="sha512", headers="date", signature="<YOUR_SIGNATURE>"' \
--header 'Content-Type: application/json' \
--data-raw '{
"accountId": "<YOUR_TEST_KEY>",
"txnId": "ZP6267f0d2996ce",
"amount": 10,
"paymentMethod": {
"name": "CreditCard",
"bankCode": "CC",
"paymentCard": {
"cardNumber": "5004461234560000",
"validThrough": "<SANDBOX_CARD_EXPIRY_MM_YY>",
"ownerName": "John Doe",
"cvv": "987"
}
},
"order": {
"productInfo": "Classic Integration Payment",
"orderedItem": [
{
"itemId": "1",
"description": "Product Description",
"quantity": 1,
"amount": 10.0
}
],
"userDefinedFields": {
"udf1": "",
"udf2": "",
"udf3": "",
"udf4": "",
"udf5": ""
},
"paymentChargeSpecification": {
"price": 10,
"netAmountDebit": 10
}
},
"additionalInfo": {
"txnS2sFlow": "4",
"authenticationFlow": "REDIRECT",
"createOrder": false
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>"
},
"billingDetails": {
"firstName": "John",
"lastName": "Doe",
"address1": "123 Main Street",
"city": "Mumbai",
"state": "Maharashtra",
"country": "India",
"zipCode": "400001",
"phone": "9876543210",
"email": "[email protected]"
}
}'import requests
import json
url = "<redacted URL>"
headers = {
"Content-Type": "application/json",
"date": "<CURRENT_DATE_GMT>",
"authorization": "hmac username=\"<YOUR_TEST_KEY>\", algorithm=\"sha512\", headers=\"date\", signature=\"<YOUR_SIGNATURE>\""
}
payload = {
"accountId": "<YOUR_TEST_KEY>",
"txnId": "ZP6267f0d2996ce",
"amount": 10,
"paymentMethod": {
"name": "CreditCard",
"bankCode": "CC",
"paymentCard": {
"cardNumber": "5004461234560000",
"validThrough": "<SANDBOX_CARD_EXPIRY_MM_YY>",
"ownerName": "John Doe",
"cvv": "987"
}
},
"order": {
"productInfo": "Classic Integration Payment",
"paymentChargeSpecification": {
"price": 10,
"netAmountDebit": 10
}
},
"additionalInfo": {
"txnS2sFlow": "4",
"authenticationFlow": "REDIRECT",
"createOrder": False
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>"
},
"billingDetails": {
"firstName": "John",
"lastName": "Doe",
"address1": "123 Main Street",
"city": "Mumbai",
"state": "Maharashtra",
"country": "India",
"zipCode": "400001",
"phone": "9876543210",
"email": "[email protected]"
}
}
response = requests.post(url, headers=headers, json=payload)
print(response.json())<?php
$url = "<redacted URL>";
$payload = json_encode([
"accountId" => "<YOUR_TEST_KEY>",
"txnId" => "ZP6267f0d2996ce",
"amount" => 10,
"paymentMethod" => [
"name" => "CreditCard",
"bankCode" => "CC",
"paymentCard" => [
"cardNumber" => "5004461234560000",
"validThrough" => "<SANDBOX_CARD_EXPIRY_MM_YY>",
"ownerName" => "John Doe",
"cvv" => "987"
]
],
"order" => [
"productInfo" => "Classic Integration Payment",
"paymentChargeSpecification" => [
"price" => 10,
"netAmountDebit" => 10
]
],
"additionalInfo" => [
"txnS2sFlow" => "4",
"authenticationFlow" => "REDIRECT",
"createOrder" => false
],
"callBackActions" => [
"successAction" => "<redacted URL>",
"failureAction" => "<redacted URL>",
"cancelAction" => "<redacted URL>"
],
"billingDetails" => [
"firstName" => "John",
"lastName" => "Doe",
"address1" => "123 Main Street",
"city" => "Mumbai",
"state" => "Maharashtra",
"country" => "India",
"zipCode" => "400001",
"phone" => "9876543210",
"email" => "[email protected]"
]
]);
$ch = curl_init($url);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_HTTPHEADER, [
"Content-Type: application/json",
"date: <CURRENT_DATE_GMT>",
"authorization: hmac username=\"<YOUR_TEST_KEY>\", algorithm=\"sha512\", headers=\"date\", signature=\"<YOUR_SIGNATURE>\""
]);
curl_setopt($ch, CURLOPT_POSTFIELDS, $payload);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$response = curl_exec($ch);
curl_close($ch);
echo $response;
?>import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class ClassicRequest {
public static void main(String[] args) throws Exception {
HttpClient client = HttpClient.newHttpClient();
String payload = """
{
"accountId": "<YOUR_TEST_KEY>",
"txnId": "ZP6267f0d2996ce",
"amount": 10,
"paymentMethod": {
"name": "CreditCard",
"bankCode": "CC",
"paymentCard": {
"cardNumber": "5004461234560000",
"validThrough": "<SANDBOX_CARD_EXPIRY_MM_YY>",
"ownerName": "John Doe",
"cvv": "987"
}
},
"order": {
"productInfo": "Classic Integration Payment",
"paymentChargeSpecification": {
"price": 10,
"netAmountDebit": 10
}
},
"additionalInfo": {
"txnS2sFlow": "4",
"authenticationFlow": "REDIRECT",
"createOrder": false
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>"
},
"billingDetails": {
"firstName": "John",
"lastName": "Doe",
"phone": "9876543210",
"email": "[email protected]"
}
}
""";
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("<redacted URL>"))
.header("Content-Type", "application/json")
.header("date", "<CURRENT_DATE_GMT>")
.header("authorization", "hmac username=\"<YOUR_TEST_KEY>\", algorithm=\"sha512\", headers=\"date\", signature=\"<YOUR_SIGNATURE>\"")
.POST(HttpRequest.BodyPublishers.ofString(payload))
.build();
HttpResponse<String> response = client.send(request,
HttpResponse.BodyHandlers.ofString());
System.out.println(response.body());
}
}const url = "<redacted URL>";
const payload = {
accountId: "<YOUR_TEST_KEY>",
txnId: "ZP6267f0d2996ce",
amount: 10,
paymentMethod: {
name: "CreditCard",
bankCode: "CC",
paymentCard: {
cardNumber: "5004461234560000",
validThrough: "<SANDBOX_CARD_EXPIRY_MM_YY>",
ownerName: "John Doe",
cvv: "987"
}
},
order: {
productInfo: "Classic Integration Payment",
paymentChargeSpecification: {
price: 10,
netAmountDebit: 10
}
},
additionalInfo: {
txnS2sFlow: "4",
authenticationFlow: "REDIRECT",
createOrder: false
},
callBackActions: {
successAction: "<redacted URL>",
failureAction: "<redacted URL>",
cancelAction: "<redacted URL>"
},
billingDetails: {
firstName: "John",
lastName: "Doe",
phone: "9876543210",
email: "[email protected]"
}
};
const options = {
method: "POST",
headers: {
"Content-Type": "application/json",
"date": "<CURRENT_DATE_GMT>",
"authorization": "hmac username=\"<YOUR_TEST_KEY>\", algorithm=\"sha512\", headers=\"date\", signature=\"<YOUR_SIGNATURE>\""
},
body: JSON.stringify(payload)
};
fetch(url, options)
.then(response => response.json())
.then(data => console.log(data))
.catch(error => console.error("Error:", error));Sample response
{
"status": "PENDING",
"result": {
"redirectUrl": "https://secure.payu.in/ResponseHandler.php",
"paymentId": "21667772394",
"redirectTemplate": "<EXAMPLE_BASE64_REDIRECT_FORM>",
"card": {
"binData": {
"pureS2SSupported": false,
"issuingBank": "ICICI",
"category": "creditcard",
"cardType": "MAST",
"isDomestic": true
}
}
}
}Response parameters
| Parameter | Description | Example |
|---|---|---|
status |
Status of the initial request (typically PENDING while awaiting redirection and 3DS completion). |
PENDING |
result.redirectUrl |
URL where the customer's browser is directed to complete 3DS authentication. |
https://secure.payu.in/ResponseHandler.php |
result.paymentId |
Unique identifier for the payment transaction generated by PayU. |
21667772394 |
result.redirectTemplate |
Auto-posting HTML/JavaScript form snippet for directing customer browser to bank ACS page. |
<form ...> |
result.card.binData.issuingBank |
Name of the issuing bank for the card. |
ICICI |
result.card.binData.category |
Card category (creditcard, debitcard). |
creditcard |
result.card.binData.cardType |
Card scheme/network (VISA, MAST, RUPAY, AMEX). |
MAST |
result.card.binData.isDomestic |
Indicates if card was issued domestically. |
true |
Reference:To check the transaction status, refer to Verify Payment API. The Verify Payment API is mandatory for Classic Integration to obtain final transaction status.
Sample Responses
Success Response (Post 3DS Authentication)
{
"status": "SUCCESS",
"result": {
"paymentId": "21667772394",
"orderId": "ZP6267f0d2996ce",
"amount": 10.00,
"currency": "INR"
},
"message": "Transaction successful"
}Pending Response
{
"status": "PENDING",
"result": {
"paymentId": "21667772394",
"redirectUrl": "https://secure.payu.in/ResponseHandler.php"
},
"message": "Awaiting customer authentication"
}Failure Response
{
"status": "FAILED",
"error": {
"code": "PAYMENT_DECLINED",
"message": "Transaction declined by issuing bank"
},
"result": {
"paymentId": "21667772394"
}
}Error Codes
| Code | HTTP Status | Description | Resolution |
|---|---|---|---|
INVALID_AMOUNT | 400 | Invalid amount value | Check amount format and value |
INVALID_CURRENCY | 400 | Unsupported currency | Use supported currency codes |
AUTHENTICATION_FAILED | 401 | Invalid signature or key | Verify HMAC credentials and signature header |
DUPLICATE_REFERENCE | 409 | Reference ID already used | Use unique transaction reference ID |
PAYMENT_DECLINED | 422 | Payment declined | Issuing bank declined authorization |
For complete error code list, see Error Codes Reference.
Next Steps
- Redirect Customer to
redirectUrlor renderredirectTemplateto complete 3DS authentication - Verify transaction using Verify Payment API
- Handle webhooks for status updates
- Check Dashboard for settlement and reconciliation
Always verify payment status before order fulfillment.
Updated 20 minutes ago
