The Collect Payment API (POST /v2/payments) allows PCI-DSS compliant merchants to process card transactions for guest shoppers by submitting raw card attributes (Primary Account Number, expiry date, cardholder name, and CVV).
Endpoint & Environments
| Environment | Method | URL |
|---|---|---|
| Test | POST | <redacted URL> |
| Production | POST | <redacted URL> |
Headers
| Header | Type | Required | Description |
|---|---|---|---|
Content-Type | String | Mandatory | Must be application/json. |
Date | String | Mandatory | Current UTC timestamp formatted as HTTP Date (e.g. Mon, 05 Oct 2026 08:30:00 GMT). |
Authorization | String | Mandatory | PayU HMAC signature header:hmac username="<YOUR_MERCHANT_KEY>", algorithm="sha512", headers="date", signature="<SIGNATURE>" |
Request Parameters
The table has 8 rows, so here it is in HTML format:
Mandatory parameters
| Parameter | Description |
|---|---|
accountId | String Merchant key registered with PayU (character limit: 50). |
txnId | String Unique transaction ID generated by merchant (character limit: 50). |
order | Object Contains order charge specification and user-defined fields (udf1–udf5). |
customer | Object Shopper profile details (email, phone, name). |
paymentMethod | Object Payment instrument parameters containing raw card details. |
callBackActions | Object Postback redirect endpoints (successAction, failureAction, cancelAction, termAction). |
additionalInfo | Object S2S flow configuration. Must include "txnS2sFlow": "4". |
Optional parameters
| Parameter | Description |
|---|---|
billingDetails | Object Shopper billing address (address1, city, state, country, postalCode). |
paymentMethod Object (Plain Card Details)
paymentMethod Object (Plain Card Details)The table has 6 rows, so here it is in HTML format:
Mandatory parameters
| Parameter | Description |
|---|---|
name | String Set to "CreditCard" or "DebitCard". |
paymentCard | Object Raw card credential attributes. |
paymentCard.cardNumber | String 15- or 16-digit Primary Account Number (PAN). |
paymentCard.validThrough | String Expiry date formatted strictly as MM/YYYY (e.g. "12/2029"). |
paymentCard.ownerName | String Name embossed on the card. |
paymentCard.cvv | String 3- or 4-digit Card Verification Value. |
Sample Request
curl --location --request POST '<redacted URL>' \
--header 'Content-Type: application/json' \
--header 'Date: Mon, 05 Oct 2026 08:30:00 GMT' \
--header 'Authorization: hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"' \
--data-raw '{
"accountId": "merchant_key",
"txnId": "TXN_GUEST_1728135000",
"order": {
"currency": "INR",
"paymentChargeSpecification": {
"price": 1000.00
}
},
"customer": {
"email": "[email protected]",
"phone": "9876543210",
"name": "John Doe"
},
"paymentMethod": {
"name": "CreditCard",
"paymentCard": {
"cardNumber": "5497774415170603",
"validThrough": "12/2029",
"ownerName": "John Doe",
"cvv": "123"
}
},
"billingDetails": {
"address1": "123 Market Street",
"city": "Bengaluru",
"state": "Karnataka",
"country": "India",
"postalCode": "560100"
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>",
"termAction": "<redacted URL>"
},
"additionalInfo": {
"txnS2sFlow": "4"
}
}'import requests
import json
url = "<redacted URL>"
payload = {
"accountId": "merchant_key",
"txnId": "TXN_GUEST_1728135000",
"order": {
"currency": "INR",
"paymentChargeSpecification": {
"price": 1000.00
}
},
"customer": {
"email": "[email protected]",
"phone": "9876543210",
"name": "John Doe"
},
"paymentMethod": {
"name": "CreditCard",
"paymentCard": {
"cardNumber": "5497774415170603",
"validThrough": "12/2029",
"ownerName": "John Doe",
"cvv": "123"
}
},
"billingDetails": {
"address1": "123 Market Street",
"city": "Bengaluru",
"state": "Karnataka",
"country": "India",
"postalCode": "560100"
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>",
"termAction": "<redacted URL>"
},
"additionalInfo": {
"txnS2sFlow": "4"
}
}
headers = {
"Content-Type": "application/json",
"Date": "Mon, 05 Oct 2026 08:30:00 GMT",
"Authorization": 'hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
}
response = requests.post(url, headers=headers, json=payload)
print(response.json())<?php
$curl = curl_init();
$payload = json_encode([
"accountId" => "merchant_key",
"txnId" => "TXN_GUEST_1728135000",
"order" => [
"currency" => "INR",
"paymentChargeSpecification" => [
"price" => 1000.00
]
],
"customer" => [
"email" => "[email protected]",
"phone" => "9876543210",
"name" => "John Doe"
],
"paymentMethod" => [
"name" => "CreditCard",
"paymentCard" => [
"cardNumber" => "5497774415170603",
"validThrough" => "12/2029",
"ownerName" => "John Doe",
"cvv" => "123"
]
],
"billingDetails" => [
"address1" => "123 Market Street",
"city" => "Bengaluru",
"state" => "Karnataka",
"country" => "India",
"postalCode" => "560100"
],
"callBackActions" => [
"successAction" => "<redacted URL>",
"failureAction" => "<redacted URL>",
"cancelAction" => "<redacted URL>",
"termAction" => "<redacted URL>"
],
"additionalInfo" => [
"txnS2sFlow" => "4"
]
]);
curl_setopt_array($curl, [
CURLOPT_URL => '<redacted URL>',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_POSTFIELDS => $payload,
CURLOPT_HTTPHEADER => [
'Content-Type: application/json',
'Date: Mon, 05 Oct 2026 08:30:00 GMT',
'Authorization: hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
],
]);
$response = curl_exec($curl);
curl_close($curl);
echo $response;import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class GuestCardPayment {
public static void main(String[] args) throws Exception {
String payload = """
{
"accountId": "merchant_key",
"txnId": "TXN_GUEST_1728135000",
"order": {
"currency": "INR",
"paymentChargeSpecification": {
"price": 1000.00
}
},
"customer": {
"email": "[email protected]",
"phone": "9876543210",
"name": "John Doe"
},
"paymentMethod": {
"name": "CreditCard",
"paymentCard": {
"cardNumber": "5497774415170603",
"validThrough": "12/2029",
"ownerName": "John Doe",
"cvv": "123"
}
},
"billingDetails": {
"address1": "123 Market Street",
"city": "Bengaluru",
"state": "Karnataka",
"country": "India",
"postalCode": "560100"
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>",
"termAction": "<redacted URL>"
},
"additionalInfo": {
"txnS2sFlow": "4"
}
}
""";
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("<redacted URL>"))
.header("Content-Type", "application/json")
.header("Date", "Mon, 05 Oct 2026 08:30:00 GMT")
.header("Authorization", "hmac username=\"merchant_key\", algorithm=\"sha512\", headers=\"date\", signature=\"<SIGNATURE>\"")
.POST(HttpRequest.BodyPublishers.ofString(payload))
.build();
HttpClient client = HttpClient.newHttpClient();
HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
System.out.println(response.body());
}
}const axios = require('axios');
const data = {
accountId: "merchant_key",
txnId: "TXN_GUEST_1728135000",
order: {
currency: "INR",
paymentChargeSpecification: {
price: 1000.00
}
},
customer: {
email: "[email protected]",
phone: "9876543210",
name: "John Doe"
},
paymentMethod: {
name: "CreditCard",
paymentCard: {
cardNumber: "5497774415170603",
validThrough: "12/2029",
ownerName: "John Doe",
cvv: "123"
}
},
billingDetails: {
address1: "123 Market Street",
city: "Bengaluru",
state: "Karnataka",
country: "India",
postalCode: "560100"
},
callBackActions: {
successAction: "<redacted URL>",
failureAction: "<redacted URL>",
cancelAction: "<redacted URL>",
termAction: "<redacted URL>"
},
additionalInfo: {
txnS2sFlow: "4"
}
};
const config = {
method: 'post',
url: '<redacted URL>',
headers: {
'Content-Type': 'application/json',
'Date': 'Mon, 05 Oct 2026 08:30:00 GMT',
'Authorization': 'hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
},
data: data
};
axios(config)
.then(response => console.log(JSON.stringify(response.data)))
.catch(error => console.error(error));Response Parameters
| Parameter | Type | Description |
|---|---|---|
| status | String | Payment transaction status: PENDING, SUCCESS, or FAILURE. |
| message | String | Transaction status message. |
| result | Object | Execution metadata. |
| result.paymentId | String | Unique PayU transaction identifier (mihpayId). |
| result.txnId | String | Merchant transaction identifier. |
| result.authAction | Object | 3DS redirection instructions for cardholder challenge. |
| result.authAction.type | String | Redirection method (REDIRECT). |
| result.authAction.url | String | 3DS Access Control Server (ACS) redirection URL. |
Sample Response
{
"status": "PENDING",
"message": "Payment initiated successfully. Please redirect the customer to complete 3D Secure authentication.",
"result": {
"paymentId": "403993715535616777",
"txnId": "TXN_GUEST_1728135000",
"authAction": {
"type": "REDIRECT",
"url": "<redacted URL>"
}
}
}Next Steps
- Perform 3DS Challenge:
- Redirect the cardholder to
result.authAction.urlto authenticate the transaction via bank OTP or biometric prompt.
- Redirect the cardholder to
- Handle Post-Authentication Callback:
- Capture the response at
callBackActions.termActionorcallBackActions.successAction.
- Capture the response at
- Verify Payment State:
- Execute a server-to-server check via the Verify Payment API to ensure transaction settlement before order dispatch.
- Offer Card Tokenization:
- If the customer opted to save their card for future checkouts, invoke the Save Card API using the customer's authorization reference.
