The PayU v2 seamless Net Banking integration allows merchants to present their own bank selection interface and initiate net banking transactions directly via the POST /v2/payments API.
NoteThis documentation covers seamless Net Banking integration. For PayU-hosted checkout, refer to Collect Payment API - PayU Hosted v2 Payment.
Environment
| Test Environment | https://apitest.payu.in/v2/payments |
| Production Environment | https://api.payu.in/v2/payments |
Request header
| Parameter | Description |
|---|---|
| date | The current date and time. For example, format of the date is Wed, 28 Jun 2023 11:25:19 GMT. |
| authorization | The actual HMAC signature generated using the specified algorithm (sha512) and includes the hashed data. For more information, refer to authorization fields description. |
authorization fields description
| Field | Description |
|---|---|
| username | Represents the username or identifier for the client or merchant, for example smsplus. |
| algorithm | Use SHA512 algorithm for hashing and send this as header value. |
| headers | Specifies which headers have been used in generating the hash, for example date. |
| signature | The HMAC signature generated using the specified algorithm. For more information, refer to hashing algorithm. |
hashing algorithm
You must hash the request parameters using the following hash logic:
Hash logic: sha512(`<Body data>` + '|' + date + '|' + merchant_secret)
Where <Body data> contains the request body posted with the request.
Sample header code
var merchant_key = '<YOUR_TEST_KEY>';
var merchant_secret = 'YOUR_TEST_SALT';
// date
var date = new Date();
date = date.toUTCString();
// authorization
var authorization = getAuthHeader(date);
function getAuthHeader(date) {
var AUTH_TYPE = 'sha512';
var data = isEmpty(request['data']) ? "" : request['data'];
var hash_string = data + '|' + date + '|' + merchant_secret;
var hash = CryptoJS.SHA512(hash_string).toString(CryptoJS.enc.Hex);
return `hmac username="${merchant_key}", algorithm="${AUTH_TYPE}", headers="date", signature="${hash}"`;
}Request body
| Parameter | Description | Example |
|---|---|---|
accountIdmandatory |
Merchant key provided by PayU. Character limit: 50 | "MERCHANT123" |
txnIdmandatory |
Unique transaction ID generated by merchant. Character limit: 50 | "TXN_NB_20261005" |
currencymandatory |
Currency code. Must be set to "INR". |
"INR" |
paymentMethodmandatory |
Net Banking payment method details. See paymentMethod object | {"name": "NetBanking", "bankCode": "SBIN"} |
ordermandatory |
Order details containing product information and pricing. See order object | {"productInfo": "Net Banking Payment", "paymentChargeSpecification": {"price": 10000.00}} |
billingDetailsmandatory |
Customer billing and contact information. See billingDetails object | {"firstName": "John", "email": "[email protected]", "phone": "9876543210"} |
callBackActionsmandatory |
Callback URLs for transaction outcome redirection. See callBackActions object | {"successAction": " |
additionalInfomandatory |
Transaction routing options and flow configuration. See additionalInfo object | {"txnS2sFlow": "4", "createOrder": true} |
paymentMethod object
| Parameter | Description |
|---|---|
namemandatory | String Payment method type. Must be set to "NetBanking". Character limit: 15 |
bankCodemandatory |
|
order Object
| Parameter | Description | Example |
|---|---|---|
productInfomandatory | Product details. Type: String | Product details |
orderedItemoptional | Details about the items ordered. Type: Array of Objects | |
userDefinedFieldsoptional | Custom fields for additional information. Type: Object. Fields: udf1, udf2, udf3, udf4, udf5, udf6, udf7, udf8, udf9, udf10. | |
paymentChargeSpecificationmandatory | Includes amount and charges. Type: Object. For more information, refer to paymentChargeSpecification object fields description |
paymentChargeSpecification object fields description
| Parameter | Description | Example |
|---|---|---|
pricemandatory | The transaction amount. Type: Number | 1000 |
netAmountDebitoptional | Net amount to be debited. Type: Number | 1000 |
taxSpecificationoptional | Tax details of the product/order. Type: Object | |
convenienceFeeoptional | Fees format. Type: String | CC:12 |
offersoptional | Offers applied or available for the payment. Type: Object |
userDefinedFields object fields description
| Field | Description |
|---|---|
| udf1 | User defined field. |
| udf2 | User defined field. |
| udf3 | User defined field. |
| udf4 | User defined field. |
| udf5 | User defined field. |
| udf6 | User defined field. |
| udf7 | User defined field. |
| udf8 | User defined field. |
| udf9 | User defined field. |
| udf10 | User defined field. |
billingDetails Object
| Parameter | Description | Example |
|---|---|---|
firstNamemandatory |
First name of the billing contact. | Ashish |
lastNameoptional |
Last name of the billing contact. | Kumar |
address1mandatory |
Primary billing address. | 123 Main Street |
address2optional |
Secondary billing address. | Apt 4B |
phoneoptional |
Phone number of the billing contact. | 9123456789 |
emailmandatory |
Email address of the billing contact. | [email protected] |
cityoptional |
City of the billing address. | Bharatpur |
stateoptional |
State of the billing address. | Rajasthan |
countryoptional |
Country of the billing address. | India |
zipCodeoptional |
Postal/Zip code of the billing address. | 321028 |
callBackActions Object
| Parameter | Description | Example |
|---|---|---|
successActionmandatory |
URL to be called on payment success. | https://example.com/success |
failureActionmandatory |
URL to be called on payment failure. | https://example.com/failure |
cancelActionmandatory |
URL to be called if user cancels the payment. | https://example.com/cancel |
codActionoptional |
URL for Cash on Delivery (COD) action. | https://example.com/cod |
additionalInfo Object
| Parameter | Description | Example |
|---|---|---|
txnS2sFlowmandatory |
Set to "4" for standard seamless bank redirection flow. |
4 |
createOrderoptional |
A flag to store order details in PayU (true / false). |
true |
enforcePaymethodoptional |
Enforces Net Banking mode. Set to "NB". |
NB |
beneficiaryDetailoptional (mandatory for TPV) |
Customer bank account details required strictly for Third-Party Verification (TPV) transactions. Omit for standard Net Banking. See beneficiaryDetail object. | Refer to beneficiaryDetail section |
beneficiaryDetail object (Only for TPV Accounts)
| Parameter | Description | Example |
|---|---|---|
beneficiaryNamemandatory for TPV |
String Name of the bank account holder registered with merchant. Character limit: 100 |
"John Doe" |
beneficiaryAccountNumbermandatory for TPV |
String Bank account number of the customer to be verified by bank. Character limit: 50 |
"123456789012" |
beneficiaryAccountTypemandatory for TPV |
String Type of customer bank account (e.g., "SAVINGS", "CURRENT"). Character limit: 20 |
"SAVINGS" |
Sample request
curl -X POST 'https://apitest.payu.in/v2/payments' \
-H 'date: Mon, 05 Oct 2026 10:00:00 GMT' \
-H 'authorization: hmac username="<YOUR_TEST_KEY>", algorithm="sha512", headers="date", signature="<SIGNATURE>"' \
-H 'content-type: application/json' \
-d '{
"accountId": "<YOUR_TEST_KEY>",
"txnId": "TXN_NB_20261005",
"currency": "INR",
"paymentMethod": {
"name": "NetBanking",
"bankCode": "SBIN"
},
"order": {
"productInfo": "Net Banking Payment",
"paymentChargeSpecification": {
"price": 10000.00,
"convenienceFee": "NB:15"
},
"userDefinedFields": {
"udf1": "Net Banking Transaction",
"udf2": "Seamless Payment"
}
},
"billingDetails": {
"firstName": "John",
"lastName": "Doe",
"email": "[email protected]",
"phone": "9876543210",
"address1": "123 Main Street",
"city": "New Delhi",
"state": "Delhi",
"country": "India",
"zipCode": "110001"
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>"
},
"additionalInfo": {
"txnS2sFlow": "4",
"createOrder": true
}
}'import requests
import json
url = "https://apitest.payu.in/v2/payments"
headers = {
"date": "Mon, 05 Oct 2026 10:00:00 GMT",
"authorization": 'hmac username="<YOUR_TEST_KEY>", algorithm="sha512", headers="date", signature="<SIGNATURE>"',
"content-type": "application/json"
}
payload = {
"accountId": "<YOUR_TEST_KEY>",
"txnId": "TXN_NB_20261005",
"currency": "INR",
"paymentMethod": {
"name": "NetBanking",
"bankCode": "SBIN"
},
"order": {
"productInfo": "Net Banking Payment",
"paymentChargeSpecification": {
"price": 10000.00
}
},
"billingDetails": {
"firstName": "John",
"lastName": "Doe",
"email": "[email protected]",
"phone": "9876543210",
"address1": "123 Main Street",
"city": "New Delhi",
"state": "Delhi",
"country": "India",
"zipCode": "110001"
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>"
},
"additionalInfo": {
"txnS2sFlow": "4",
"createOrder": True
}
}
response = requests.post(url, headers=headers, json=payload)
print(response.json())<?php
$url = "https://apitest.payu.in/v2/payments";
$payload = json_encode([
"accountId" => "<YOUR_TEST_KEY>",
"txnId" => "TXN_NB_20261005",
"currency" => "INR",
"paymentMethod" => [
"name" => "NetBanking",
"bankCode" => "SBIN"
],
"order" => [
"productInfo" => "Net Banking Payment",
"paymentChargeSpecification" => [
"price" => 10000.00
]
],
"billingDetails" => [
"firstName" => "John",
"lastName" => "Doe",
"email" => "[email protected]",
"phone" => "9876543210",
"address1" => "123 Main Street",
"city" => "New Delhi",
"state" => "Delhi",
"country" => "India",
"zipCode" => "110001"
],
"callBackActions" => [
"successAction" => "<redacted URL>",
"failureAction" => "<redacted URL>",
"cancelAction" => "<redacted URL>"
],
"additionalInfo" => [
"txnS2sFlow" => "4",
"createOrder" => true
]
]);
$ch = curl_init($url);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_HTTPHEADER, [
"date: Mon, 05 Oct 2026 10:00:00 GMT",
"authorization: hmac username=\"<YOUR_TEST_KEY>\", algorithm=\"sha512\", headers=\"date\", signature=\"<SIGNATURE>\"",
"content-type: application/json"
]);
curl_setopt($ch, CURLOPT_POSTFIELDS, $payload);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$response = curl_exec($ch);
curl_close($ch);
echo $response;
?>import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class PayUNetBankingRequest {
public static void main(String[] args) throws Exception {
HttpClient client = HttpClient.newHttpClient();
String payload = """
{
"accountId": "<YOUR_TEST_KEY>",
"txnId": "TXN_NB_20261005",
"currency": "INR",
"paymentMethod": {
"name": "NetBanking",
"bankCode": "SBIN"
},
"order": {
"productInfo": "Net Banking Payment",
"paymentChargeSpecification": {
"price": 10000.00
}
},
"billingDetails": {
"firstName": "John",
"lastName": "Doe",
"email": "[email protected]",
"phone": "9876543210",
"address1": "123 Main Street",
"city": "New Delhi",
"state": "Delhi",
"country": "India",
"zipCode": "110001"
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>"
},
"additionalInfo": {
"txnS2sFlow": "4",
"createOrder": true
}
}
""";
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://apitest.payu.in/v2/payments"))
.header("date", "Mon, 05 Oct 2026 10:00:00 GMT")
.header("authorization", "hmac username=\"<YOUR_TEST_KEY>\", algorithm=\"sha512\", headers=\"date\", signature=\"<SIGNATURE>\"")
.header("content-type", "application/json")
.POST(HttpRequest.BodyPublishers.ofString(payload))
.build();
HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
System.out.println(response.body());
}
}const url = "https://apitest.payu.in/v2/payments";
const payload = {
accountId: "<YOUR_TEST_KEY>",
txnId: "TXN_NB_20261005",
currency: "INR",
paymentMethod: {
name: "NetBanking",
bankCode: "SBIN"
},
order: {
productInfo: "Net Banking Payment",
paymentChargeSpecification: {
price: 10000.00
}
},
billingDetails: {
firstName: "John",
lastName: "Doe",
email: "[email protected]",
phone: "9876543210",
address1: "123 Main Street",
city: "New Delhi",
state: "Delhi",
country: "India",
zipCode: "110001"
},
callBackActions: {
successAction: "<redacted URL>",
failureAction: "<redacted URL>",
cancelAction: "<redacted URL>"
},
additionalInfo: {
txnS2sFlow: "4",
createOrder: true
}
};
fetch(url, {
method: "POST",
headers: {
"date": "Mon, 05 Oct 2026 10:00:00 GMT",
"authorization": 'hmac username="<YOUR_TEST_KEY>", algorithm="sha512", headers="date", signature="<SIGNATURE>"',
"content-type": "application/json"
},
body: JSON.stringify(payload)
})
.then(res => res.json())
.then(data => console.log(data))
.catch(err => console.error("Error:", err));Response parameters
| Parameter | Description |
|---|---|
| message | This parameter contains the status message of the transaction. |
| status | This parameter returns the status of web service call. The status can be any of the following: `0` - If web service call failed. `1` - If web service call succeeded. |
| result | This parameter contains the payment status details in a JSON format including payment ID of the transaction. For more detailes, refer to the result JSON Object fields description table (next accordion) |
Sample response
The response provides a checkoutUrl to redirect the customer to their bank portal:
{
"status": "PENDING",
"result": {
"checkoutUrl": "<redacted URL>"
},
"txnId": "TXN_NB_20261005",
"paymentId": "1999110000001769",
"message": "Redirect customer to bank portal"
}Verify Payment
ImportantAfter the customer completes authentication at the bank portal, they will be redirected to your
callBackActions.successActionorcallBackActions.failureAction. You must call the Verify Payment API using yourtxnIdto determine the definitive transaction status.
Error Codes
| Code | HTTP Status | Description | Resolution |
|---|---|---|---|
INVALID_BANK_CODE | 400 | Unknown or unsupported Net Banking code | Verify code from supported net banking codes |
INVALID_AMOUNT | 400 | Amount value invalid | Ensure price is positive number |
INVALID_CURRENCY | 400 | Unsupported currency | Set currency: "INR" |
AUTHENTICATION_FAILED | 401 | Invalid authorization header | Check HMAC SHA512 signature |
DUPLICATE_REFERENCE | 409 | txnId already used | Use unique transaction ID |
PAYMENT_DECLINED | 422 | Bank declined transaction | Customer should retry or choose another payment method |
Next Steps
Next Steps
- Redirect Customer to Bank Portal:
- Extract
result.paymentUrland redirect the customer to their issuing bank's secure login/authentication portal.
- Extract
- Listen for Redirect Callbacks:
- Once authentication is complete at the bank, PayU posts the transaction outcome to your
callBackActions.successAction,failureAction, orcancelAction.
- Once authentication is complete at the bank, PayU posts the transaction outcome to your
- Confirm Final Status Server-to-Server:
- Net Banking transactions occasionally encounter customer drop-offs or bank session timeouts. Run a server-side check via the Verify Payment API to confirm the final debited status.
- Third-Party Verification (TPV) Checks (If Applicable):
- For investment or regulated trading accounts where
beneficiaryDetailwas supplied, verify that the returned bank account number matches the customer's registered profile.
- For investment or regulated trading accounts where
