Processing Payments with Saved Card Tokens
The Collect Payment API (POST /v2/payments) allows merchants to initiate seamless payments using previously vaulted cards by supplying the customer's cardToken and CVV, eliminating the need to re-enter primary account numbers.
Endpoint & Environments
| Environment | Method | URL |
|---|---|---|
| Test | POST | <redacted URL> |
| Production | POST | <redacted URL> |
Headers
| Header | Type | Required | Description |
|---|---|---|---|
Content-Type | String | Mandatory | Must be application/json. |
Date | String | Mandatory | Current UTC timestamp formatted as HTTP Date (e.g. Mon, 05 Oct 2026 08:30:00 GMT). |
Authorization | String | Mandatory | PayU HMAC signature header:hmac username="<YOUR_MERCHANT_KEY>", algorithm="sha512", headers="date", signature="<SIGNATURE>" |
Request Parameters
The table has 8 rows, so here it is in HTML format. Also, noting that no Example column was present in the original, it has been omitted:
Mandatory parameters
| Parameter | Description |
|---|---|
accountId | String Merchant key registered with PayU (character limit: 50). |
txnId | String Unique transaction identifier generated by merchant (character limit: 50). |
order | Object Contains order charge specification and optional user-defined fields (udf1–udf5). |
customer | Object Customer profile details (email, phone, name). |
paymentMethod | Object Payment instrument details specifying saved card tokens. |
callBackActions | Object Redirect URLs for post-authentication lifecycle (successAction, failureAction, cancelAction, termAction). |
additionalInfo | Object Integration flow parameters. Must include "txnS2sFlow": "4". |
Optional parameters
| Parameter | Description |
|---|---|
billingDetails | Object Billing address details (address1, city, state, country, postalCode). |
paymentMethod Object (Saved Card)
paymentMethod Object (Saved Card)The table has 7 rows, so here it is in HTML format:
Mandatory parameters
| Parameter | Description |
|---|---|
name | String Set to "CreditCard" or "DebitCard". |
paymentCard | Object Contains stored card token details. |
paymentCard.cardToken | String Unique token representing the saved card in PayU Vault. |
Conditional parameters
| Parameter | Description |
|---|---|
paymentCard.cvv | String Card Verification Value. Mandatory for 3DS authentication unless CVV-less merchant terminal profile is configured. |
Optional parameters
| Parameter | Description |
|---|---|
paymentCard.cardTokenType | String Set to "PAYU" or "NETWORK" when token was created via network tokenization. |
paymentCard.tavv | String Cryptogram obtained from the Get Payment Details API (for network tokens). |
paymentCard.last4Digits | String Last 4 digits of the card number (e.g. "2346"). |
Note: Per your configuration, physical card fields (
cardNumber,validThrough, andownerName) may be retained in the request object schema if required by specific hybrid integrations, while merchants utilizing standard PayU Vault tokenization passcardTokenandcvv.
Sample Request
curl --location --request POST 'https://apitest.payu.in/v2/payments' \
--header 'Content-Type: application/json' \
--header 'Accept: application/json' \
--data-raw '{
"accountId": "<YOUR_MERCHANT_KEY>",
"txnId": "txn_saved_card_001",
"userCredentials": "<YOUR_MERCHANT_KEY>:<CUSTOMER_ID>",
"paymentMethod": {
"name": "CreditCard",
"bankCode": "CC",
"paymentCard": {
"cardToken": "b5f2d8785768087678fm9",
"cardTokenType": "PAYU",
"last4Digits": "0603",
"cvv": "123"
}
},
"order": {
"productInfo": "Premium Subscription",
"orderedItem": [
{
"itemId": "SUB001",
"description": "Monthly Premium Plan",
"quantity": 1,
"amount": 1000.00
}
],
"userDefinedFields": {
"udf1": "recurring_payment",
"udf2": "monthly",
"udf3": "premium",
"udf4": "auto_renewal",
"udf5": "customer456"
},
"paymentChargeSpecification": {
"price": 1000.00
}
},
"additionalInfo": {
"txnS2sFlow": "4",
"enforcePaymethod": "CC",
"createOrder": true
},
"callBackActions": {
"successAction": "https://yoursite.com/payment/success",
"failureAction": "https://yoursite.com/payment/failure",
"cancelAction": "https://yoursite.com/payment/cancel"
},
"billingDetails": {
"firstName": "John",
"lastName": "Doe",
"address1": "123 Business Street",
"phone": "9876543210",
"email": "[email protected]",
"city": "Mumbai",
"state": "Maharashtra",
"country": "India",
"zipCode": "400001"
}
}'import requests
import json
url = "https://apitest.payu.in/v2/payments"
headers = {
"Content-Type": "application/json",
"Accept": "application/json"
}
payload = {
"accountId": "<YOUR_MERCHANT_KEY>",
"txnId": "txn_saved_card_001",
"userCredentials": "<YOUR_MERCHANT_KEY>:<CUSTOMER_ID>",
"paymentMethod": {
"name": "CreditCard",
"bankCode": "CC",
"paymentCard": {
"cardToken": "b5f2d8785768087678fm9",
"cardTokenType": "PAYU",
"last4Digits": "0603",
"cvv": "123"
}
},
"order": {
"productInfo": "Premium Subscription",
"orderedItem": [
{
"itemId": "SUB001",
"description": "Monthly Premium Plan",
"quantity": 1,
"amount": 1000.00
}
],
"userDefinedFields": {
"udf1": "recurring_payment",
"udf2": "monthly",
"udf3": "premium",
"udf4": "auto_renewal",
"udf5": "customer456"
},
"paymentChargeSpecification": {
"price": 1000.00
}
},
"additionalInfo": {
"txnS2sFlow": "4",
"enforcePaymethod": "CC",
"createOrder": True
},
"callBackActions": {
"successAction": "https://yoursite.com/payment/success",
"failureAction": "https://yoursite.com/payment/failure",
"cancelAction": "https://yoursite.com/payment/cancel"
},
"billingDetails": {
"firstName": "John",
"lastName": "Doe",
"address1": "123 Business Street",
"phone": "9876543210",
"email": "[email protected]",
"city": "Mumbai",
"state": "Maharashtra",
"country": "India",
"zipCode": "400001"
}
}
response = requests.post(url, headers=headers, data=json.dumps(payload))
print("Status Code:", response.status_code)
print("Response:", response.text)using System;
using System.Net.Http;
using System.Text;
using System.Threading.Tasks;
class Program
{
static async Task Main(string[] args)
{
using HttpClient client = new HttpClient();
client.DefaultRequestHeaders.Add("Accept", "application/json");
string jsonBody = @"{
""accountId"": ""<YOUR_MERCHANT_KEY>"",
""txnId"": ""txn_saved_card_001"",
""userCredentials"": ""<YOUR_MERCHANT_KEY>:<CUSTOMER_ID>"",
""paymentMethod"": {
""name"": ""CreditCard"",
""bankCode"": ""CC"",
""paymentCard"": {
""cardToken"": ""b5f2d8785768087678fm9"",
""cardTokenType"": ""PAYU"",
""last4Digits"": ""0603"",
""cvv"": ""123""
}
},
""order"": {
""productInfo"": ""Premium Subscription"",
""orderedItem"": [
{
""itemId"": ""SUB001"",
""description"": ""Monthly Premium Plan"",
""quantity"": 1,
""amount"": 1000.00
}
],
""userDefinedFields"": {
""udf1"": ""recurring_payment"",
""udf2"": ""monthly"",
""udf3"": ""premium"",
""udf4"": ""auto_renewal"",
""udf5"": ""customer456""
},
""paymentChargeSpecification"": {
""price"": 1000.00
}
},
""additionalInfo"": {
""txnS2sFlow"": ""4"",
""enforcePaymethod"": ""CC"",
""createOrder"": true
},
""callBackActions"": {
""successAction"": ""https://yoursite.com/payment/success"",
""failureAction"": ""https://yoursite.com/payment/failure"",
""cancelAction"": ""https://yoursite.com/payment/cancel""
},
""billingDetails"": {
""firstName"": ""John"",
""lastName"": ""Doe"",
""address1"": ""123 Business Street"",
""phone"": ""9876543210"",
""email"": ""[email protected]"",
""city"": ""Mumbai"",
""state"": ""Maharashtra"",
""country"": ""India"",
""zipCode"": ""400001""
}
}";
StringContent content = new StringContent(jsonBody, Encoding.UTF8, "application/json");
HttpResponseMessage response = await client.PostAsync("https://apitest.payu.in/v2/payments", content);
Console.WriteLine("Status Code: " + (int)response.StatusCode);
Console.WriteLine("Response: " + await response.Content.ReadAsStringAsync());
}
}const url = "https://apitest.payu.in/v2/payments";
const headers = {
"Content-Type": "application/json",
"Accept": "application/json"
};
const body = JSON.stringify({
accountId: "<YOUR_MERCHANT_KEY>",
txnId: "txn_saved_card_001",
userCredentials: "<YOUR_MERCHANT_KEY>:<CUSTOMER_ID>",
paymentMethod: {
name: "CreditCard",
bankCode: "CC",
paymentCard: {
cardToken: "b5f2d8785768087678fm9",
cardTokenType: "PAYU",
last4Digits: "0603",
cvv: "123"
}
},
order: {
productInfo: "Premium Subscription",
orderedItem: [
{
itemId: "SUB001",
description: "Monthly Premium Plan",
quantity: 1,
amount: 1000.00
}
],
userDefinedFields: {
udf1: "recurring_payment",
udf2: "monthly",
udf3: "premium",
udf4: "auto_renewal",
udf5: "customer456"
},
paymentChargeSpecification: {
price: 1000.00
}
},
additionalInfo: {
txnS2sFlow: "4",
enforcePaymethod: "CC",
createOrder: true
},
callBackActions: {
successAction: "https://yoursite.com/payment/success",
failureAction: "https://yoursite.com/payment/failure",
cancelAction: "https://yoursite.com/payment/cancel"
},
billingDetails: {
firstName: "John",
lastName: "Doe",
address1: "123 Business Street",
phone: "9876543210",
email: "[email protected]",
city: "Mumbai",
state: "Maharashtra",
country: "India",
zipCode: "400001"
}
});
const response = await fetch(url, {
method: "POST",
headers: headers,
body: body
});
console.log("Status Code:", response.status);
console.log("Response:", await response.text());import java.io.OutputStream;
import java.io.BufferedReader;
import java.io.InputStreamReader;
import java.net.HttpURLConnection;
import java.net.URL;
public class Main {
public static void main(String[] args) throws Exception {
URL url = new URL("https://apitest.payu.in/v2/payments");
HttpURLConnection conn = (HttpURLConnection) url.openConnection();
conn.setRequestMethod("POST");
conn.setDoOutput(true);
conn.setRequestProperty("Content-Type", "application/json");
conn.setRequestProperty("Accept", "application/json");
String jsonBody = "{"
+ "\"accountId\":\"<YOUR_MERCHANT_KEY>\","
+ "\"txnId\":\"txn_saved_card_001\","
+ "\"userCredentials\":\"<YOUR_MERCHANT_KEY>:<CUSTOMER_ID>\","
+ "\"paymentMethod\":{"
+ "\"name\":\"CreditCard\","
+ "\"bankCode\":\"CC\","
+ "\"paymentCard\":{"
+ "\"cardToken\":\"b5f2d8785768087678fm9\","
+ "\"cardTokenType\":\"PAYU\","
+ "\"last4Digits\":\"0603\","
+ "\"cvv\":\"123\""
+ "}"
+ "},"
+ "\"order\":{"
+ "\"productInfo\":\"Premium Subscription\","
+ "\"orderedItem\":[{"
+ "\"itemId\":\"SUB001\","
+ "\"description\":\"Monthly Premium Plan\","
+ "\"quantity\":1,"
+ "\"amount\":1000.00"
+ "}],"
+ "\"userDefinedFields\":{"
+ "\"udf1\":\"recurring_payment\","
+ "\"udf2\":\"monthly\","
+ "\"udf3\":\"premium\","
+ "\"udf4\":\"auto_renewal\","
+ "\"udf5\":\"customer456\""
+ "},"
+ "\"paymentChargeSpecification\":{"
+ "\"price\":1000.00"
+ "}"
+ "},"
+ "\"additionalInfo\":{"
+ "\"txnS2sFlow\":\"4\","
+ "\"enforcePaymethod\":\"CC\","
+ "\"createOrder\":true"
+ "},"
+ "\"callBackActions\":{"
+ "\"successAction\":\"https://yoursite.com/payment/success\","
+ "\"failureAction\":\"https://yoursite.com/payment/failure\","
+ "\"cancelAction\":\"https://yoursite.com/payment/cancel\""
+ "},"
+ "\"billingDetails\":{"
+ "\"firstName\":\"John\","
+ "\"lastName\":\"Doe\","
+ "\"address1\":\"123 Business Street\","
+ "\"phone\":\"9876543210\","
+ "\"email\":\"[email protected]\","
+ "\"city\":\"Mumbai\","
+ "\"state\":\"Maharashtra\","
+ "\"country\":\"India\","
+ "\"zipCode\":\"400001\""
+ "}"
+ "}";
try (OutputStream os = conn.getOutputStream()) {
os.write(jsonBody.getBytes("UTF-8"));
}
int statusCode = conn.getResponseCode();
BufferedReader br = new BufferedReader(new InputStreamReader(conn.getInputStream()));
StringBuilder response = new StringBuilder();
String line;
while ((line = br.readLine()) != null) {
response.append(line);
}
br.close();
System.out.println("Status Code: " + statusCode);
System.out.println("Response: " + response.toString());
}
}<?php
$url = "https://apitest.payu.in/v2/payments";
$headers = [
"Content-Type: application/json",
"Accept: application/json"
];
$body = json_encode([
"accountId" => "<YOUR_MERCHANT_KEY>",
"txnId" => "txn_saved_card_001",
"userCredentials" => "<YOUR_MERCHANT_KEY>:<CUSTOMER_ID>",
"paymentMethod" => [
"name" => "CreditCard",
"bankCode" => "CC",
"paymentCard" => [
"cardToken" => "b5f2d8785768087678fm9",
"cardTokenType" => "PAYU",
"last4Digits" => "0603",
"cvv" => "123"
]
],
"order" => [
"productInfo" => "Premium Subscription",
"orderedItem" => [
[
"itemId" => "SUB001",
"description" => "Monthly Premium Plan",
"quantity" => 1,
"amount" => 1000.00
]
],
"userDefinedFields" => [
"udf1" => "recurring_payment",
"udf2" => "monthly",
"udf3" => "premium",
"udf4" => "auto_renewal",
"udf5" => "customer456"
],
"paymentChargeSpecification" => [
"price" => 1000.00
]
],
"additionalInfo" => [
"txnS2sFlow" => "4",
"enforcePaymethod" => "CC",
"createOrder" => true
],
"callBackActions" => [
"successAction" => "https://yoursite.com/payment/success",
"failureAction" => "https://yoursite.com/payment/failure",
"cancelAction" => "https://yoursite.com/payment/cancel"
],
"billingDetails" => [
"firstName" => "John",
"lastName" => "Doe",
"address1" => "123 Business Street",
"phone" => "9876543210",
"email" => "[email protected]",
"city" => "Mumbai",
"state" => "Maharashtra",
"country" => "India",
"zipCode" => "400001"
]
]);
$ch = curl_init($url);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_HTTPHEADER, $headers);
curl_setopt($ch, CURLOPT_POSTFIELDS, $body);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$response = curl_exec($ch);
$statusCode = curl_getinfo($ch, CURLINFO_HTTP_CODE);
curl_close($ch);
echo "Status Code: " . $statusCode . "\n";
echo "Response: " . $response . "\n";Response Parameters
| Parameter | Type | Description |
|---|---|---|
| status | String | Payment transaction status: PENDING, SUCCESS, or FAILURE. |
| message | String | Descriptive outcome message. |
| result | Object | Transaction execution details. |
| result.paymentId | String | Unique PayU transaction reference ID (mihpayId). |
| result.txnId | String | Merchant transaction identifier supplied in the request. |
| result.authAction | Object | 3DS redirection instructions for cardholder challenge. |
| result.authAction.type | String | Redirection method (e.g. REDIRECT). |
| result.authAction.url | String | Bank 3DS Access Control Server (ACS) redirection URL. |
Sample Response
{
"status": "PENDING",
"message": "Payment initiated successfully. Please redirect the customer to complete 3D Secure authentication.",
"result": {
"paymentId": "403993715535614999",
"txnId": "TXN_SAVED_1728135000",
"authAction": {
"type": "REDIRECT",
"url": "<redacted URL>"
}
}
}Next Steps
- Redirect Customer to 3D Secure ACS:
- Redirect the customer or launch an in-app webview targeting
result.authAction.urlto complete OTP or biometric verification with their issuing bank.
- Redirect the customer or launch an in-app webview targeting
- Process Postback:
- Handle bank callbacks posted to
callBackActions.termActionorcallBackActions.successAction.
- Handle bank callbacks posted to
- Verify Payment Status:
- Validate transaction finality server-to-server using the Verify Payment API using your
txnId.
- Validate transaction finality server-to-server using the Verify Payment API using your
