Direct Authorization Integration
PayU enables merchants to process direct authorization for pre-authenticated transactions (external MPI/3DSS). This section describes how to integrate with PayU's direct authorization flow. Initiate an authorization request with the payment details provided post a successful authentication through the MPI/3DSS as explained in this API Reference.
In the Direct Authorization Flow, 3DS authentication has already been performed outside PayU. PayU receives the authentication verification values (such as CAVV/ECI) and directly requests transaction authorization from the acquiring bank, bypassing customer redirection.
Note:This API is backward compatible and you can continue to use the existing integration parameters to process 3DS 1.0.2 transactions.
Environment
| Test Environment | https://apitest.payu.in/v2/payments |
| Production Environment | https://api.payu.in/v2/payments |
Request header
| Parameter | Description |
|---|---|
| date | The current date and time. For example, format of the date is Wed, 28 Jun 2023 11:25:19 GMT. |
| authorization | The actual HMAC signature generated using the specified algorithm (sha512) and includes the hashed data. For more information, refer to authorization fields description. |
authorization fields description
| Field | Description |
|---|---|
| username | Represents the username or identifier for the client or merchant, for example smsplus. |
| algorithm | Use SHA512 algorithm for hashing and send this as header value. |
| headers | Specifies which headers have been used in generating the hash, for example date. |
| signature | The HMAC signature generated using the specified algorithm. For more information, refer to hashing algorithm. |
hashing algorithm
You must hash the request parameters using the following hash logic:
Hash logic: sha512(`<Body data>` + '|' + date + '|' + merchant_secret)
Where <Body data> contains the request body posted with the request.
Sample header code
var merchant_key = '<YOUR_TEST_KEY>';
var merchant_secret = 'YOUR_TEST_SALT';
// date
var date = new Date();
date = date.toUTCString();
// authorization
var authorization = getAuthHeader(date);
function getAuthHeader(date) {
var AUTH_TYPE = 'sha512';
var data = isEmpty(request['data']) ? "" : request['data'];
var hash_string = data + '|' + date + '|' + merchant_secret;
var hash = CryptoJS.SHA512(hash_string).toString(CryptoJS.enc.Hex);
return `hmac username="${merchant_key}", algorithm="${AUTH_TYPE}", headers="date", signature="${hash}"`;
}Request body
Mandatory parameters
| Parameter | Description | Example |
|---|---|---|
accountId |
String The merchant key provided by PayU during onboarding. |
<YOUR_TEST_KEY> |
txnId |
String Transaction ID provided by the merchant and this must be unique for every transaction. |
ZP6267f0d2996ce |
amount |
Number The transaction amount to be charged. |
10 |
paymentMethod |
Object Details about the payment method used. For Direct Authorization Flow:• name: "CreditCard" or "DebitCard" • bankCode: Card type code • paymentCard: Card details object |
{"name": "CreditCard", "bankCode": "CC"} |
order |
Object Details about the transaction order including product information, ordered items, user-defined fields, and payment charge specifications. For more information, refer to order object fields description. |
|
additionalInfo |
Object Additional information including S2S flow configuration. For more information, refer to additionalInfo object fields description. |
|
callBackActions |
Object Actions to perform on the payment server in different scenarios. For more information, refer to callBackActions object fields description. |
|
billingDetails |
Object Billing details of the customer including name, address, phone number, email, etc. For more information, refer to billingDetails object fields description. |
Conditional parameters
| Parameter | Description | Example |
|---|---|---|
authorization | Object 3DS authorization information received from MPI/3DSS for direct authentication. Mandatory for S2S Direct Auth. For more information, refer to authorization object fields description. |
Optional parameters
| Parameter | Description | Example |
|---|---|---|
threeDS2RequestData | Object 3DS2 protocol request data for 3DS 2.x transactions. For more information, refer to threeDS2RequestData object fields description. |
paymentMethod object fields description
| Field | Description | Example |
|---|---|---|
name |
|
CreditCard |
bankCode |
|
CC |
paymentCard |
|
paymentCard object fields description
| Parameter | Description | Example |
|---|---|---|
cardNumbermandatory for physical card |
Card number. | 5***77***517***7 |
validThroughmandatory for physical card |
Expiry date in MM/YYYY format. | |
ownerNameoptional |
Name of the card owner. | |
cvvmandatory for physical card |
CVV number of the card. | 123 |
tavvmandatory for saved card |
Cryptogram of the card for tokenized payments. | AAABA***mQAAAABjRWWZEEFgFz |
last4Digitsmandatory for saved card |
Last four digits of the card. | 0603 |
cardTokenTypemandatory for saved card |
Card token type. Valid values: PAYU, NETWORK, ISSUER. | PAYU |
cardTokenmandatory for saved card |
Card token of the stored card. | b5**7857680876***m9 |
order object fields description
| Parameter | Description | Example |
|---|---|---|
productInfomandatory | Product details. Type: String | Product details |
orderedItemoptional | Details about the items ordered. Type: Array of Objects | |
userDefinedFieldsoptional | Custom fields for additional information. Type: Object. Fields: udf1, udf2, udf3, udf4, udf5, udf6, udf7, udf8, udf9, udf10. | |
paymentChargeSpecificationmandatory | Includes amount and charges. Type: Object. For more information, refer to paymentChargeSpecification object fields description |
paymentChargeSpecification object fields description
| Parameter | Description | Example |
|---|---|---|
pricemandatory | The transaction amount. Type: Number | 1000 |
netAmountDebitoptional | Net amount to be debited. Type: Number | 1000 |
taxSpecificationoptional | Tax details of the product/order. Type: Object | |
convenienceFeeoptional | Fees format. Type: String | CC:12 |
offersoptional | Offers applied or available for the payment. Type: Object |
userDefinedFields object fields description
| Field | Description |
|---|---|
| udf1 | User defined field. |
| udf2 | User defined field. |
| udf3 | User defined field. |
| udf4 | User defined field. |
| udf5 | User defined field. |
| udf6 | User defined field. |
| udf7 | User defined field. |
| udf8 | User defined field. |
| udf9 | User defined field. |
| udf10 | User defined field. |
additionalInfo object fields description
| Parameter | Description | Example |
|---|---|---|
enforcePaymethodoptional |
Force a transaction with a specified method (e.g., CC, DC). | CC |
forcePgidoptional |
Forces identification for payment gateway. | PG123 |
partnerHoldTimeoptional |
Time held by the partner for the transaction. | 60 |
userCredentialsoptional |
Credentials for user authentication. | string |
userTokenoptional |
Token for the customer. | user_token_123 |
subventionAmountoptional |
Amount paid through EMI subvention payments. | 100 |
authOnlyoptional |
Initiates an authentication-only payment (true/false). | false |
createOrderoptional |
A flag to store the order details (true/false). | true |
txnS2sFlowoptional |
For defining seamless/non-seamless flows in handling payments. | seamless |
Direct Authorization Flow-specific parameters:
Conditional parameters
| Parameter | Description | Example |
|---|---|---|
txnS2sFlow | String Indicates the transaction S2S flow type. Must be set to "3" for Direct Authorization Flow. Mandatory for Direct Auth. | 3 |
Optional parameters
| Parameter | Description | Example |
|---|---|---|
createOrder | Boolean Whether to create an order during the payment process. | false |
placeOrder | Boolean Use to indicate if saved order details should be utilized. | false |
callBackActions object fields description
| Field | Description | Example |
|---|---|---|
successAction |
|
|
failureAction |
|
|
cancelAction |
|
billingDetails object fields description
| Parameter | Description | Example |
|---|---|---|
firstNamemandatory |
First name of the billing contact. | Ashish |
lastNameoptional |
Last name of the billing contact. | Kumar |
address1mandatory |
Primary billing address. | 123 Main Street |
address2optional |
Secondary billing address. | Apt 4B |
phoneoptional |
Phone number of the billing contact. | 9123456789 |
emailmandatory |
Email address of the billing contact. | [email protected] |
cityoptional |
City of the billing address. | Bharatpur |
stateoptional |
State of the billing address. | Rajasthan |
countryoptional |
Country of the billing address. | India |
zipCodeoptional |
Postal/Zip code of the billing address. | 321028 |
authorization object fields description
| Field | Description | Example |
|---|---|---|
eci |
|
05 |
cavv |
|
AAABAWFlmQAAAABjRWWZEEFgFz |
flowType |
|
Frictionless |
threeDSTransID |
|
67b4c71f-19bf-4d97-bd09-4e3687dc9e42 |
threeDSServerTransID |
|
eea30d14-71cf-41af-b961-f95b7d67dc93 |
threeDSTransStatus |
|
Y |
threeDSTransStatusReason |
|
01 |
acquirer_bin |
|
401200 |
threeDS2RequestData object fields description
| Parameter | Description | Example |
|---|---|---|
threeDSVersionoptional |
The version of 3D Secure used. | 2.2.0 |
deviceChanneloptional |
The device used for the transaction channel. | APP |
Sample request
curl --location 'https://apitest.payu.in/v2/payments' \
--header 'date: <CURRENT_DATE_GMT>' \
--header 'authorization: hmac username="<YOUR_TEST_KEY>", algorithm="sha512", headers="date", signature="<YOUR_SIGNATURE>"' \
--header 'Content-Type: application/json' \
--data-raw '{
"accountId": "<YOUR_TEST_KEY>",
"txnId": "ZP6267f0d2996ce",
"amount": 10,
"paymentMethod": {
"name": "CreditCard",
"bankCode": "CC",
"paymentCard": {
"cardNumber": "5004461234560000",
"validThrough": "<SANDBOX_CARD_EXPIRY_MM_YY>",
"ownerName": "John Doe",
"cvv": "987"
}
},
"order": {
"productInfo": "Direct Authorization Payment",
"orderedItem": [
{
"itemId": "1",
"description": "Product Description",
"quantity": 1,
"amount": 10.0
}
],
"paymentChargeSpecification": {
"price": 10,
"netAmountDebit": 10
}
},
"additionalInfo": {
"createOrder": false,
"placeOrder": false,
"txnS2sFlow": "3"
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>"
},
"billingDetails": {
"firstName": "John",
"lastName": "Doe",
"address1": "123 Main Street",
"city": "Mumbai",
"state": "Maharashtra",
"country": "India",
"zipCode": "400001",
"phone": "9876543210",
"email": "[email protected]"
},
"authorization": {
"eci": "05",
"cavv": "AAABAWFlmQAAAABjRWWZEEFgFz",
"flowType": "Frictionless",
"threeDSTransID": "67b4c71f-19bf-4d97-bd09-4e3687dc9e42",
"threeDSServerTransID": "eea30d14-71cf-41af-b961-f95b7d67dc93",
"threeDSTransStatus": "Y",
"threeDSTransStatusReason": "01",
"acquirer_bin": "401200"
},
"threeDS2RequestData": {
"threeDSVersion": "2.2.0",
"deviceChannel": "APP"
}
}'import requests
import json
url = "https://apitest.payu.in/v2/payments"
headers = {
"Content-Type": "application/json",
"date": "<CURRENT_DATE_GMT>",
"authorization": "hmac username=\"<YOUR_TEST_KEY>\", algorithm=\"sha512\", headers=\"date\", signature=\"<YOUR_SIGNATURE>\""
}
payload = {
"accountId": "<YOUR_TEST_KEY>",
"txnId": "ZP6267f0d2996ce",
"amount": 10,
"paymentMethod": {
"name": "CreditCard",
"bankCode": "CC",
"paymentCard": {
"cardNumber": "5004461234560000",
"validThrough": "<SANDBOX_CARD_EXPIRY_MM_YY>",
"ownerName": "John Doe",
"cvv": "987"
}
},
"order": {
"productInfo": "Direct Authorization Payment",
"orderedItem": [
{
"itemId": "1",
"description": "Product Description",
"quantity": 1,
"amount": 10.0
}
],
"paymentChargeSpecification": {
"price": 10,
"netAmountDebit": 10
}
},
"additionalInfo": {
"createOrder": False,
"placeOrder": False,
"txnS2sFlow": "3"
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>"
},
"billingDetails": {
"firstName": "John",
"lastName": "Doe",
"address1": "123 Main Street",
"city": "Mumbai",
"state": "Maharashtra",
"country": "India",
"zipCode": "400001",
"phone": "9876543210",
"email": "[email protected]"
},
"authorization": {
"eci": "05",
"cavv": "AAABAWFlmQAAAABjRWWZEEFgFz",
"flowType": "Frictionless",
"threeDSTransID": "67b4c71f-19bf-4d97-bd09-4e3687dc9e42",
"threeDSServerTransID": "eea30d14-71cf-41af-b961-f95b7d67dc93",
"threeDSTransStatus": "Y",
"threeDSTransStatusReason": "01",
"acquirer_bin": "401200"
},
"threeDS2RequestData": {
"threeDSVersion": "2.2.0",
"deviceChannel": "APP"
}
}
response = requests.post(url, headers=headers, json=payload)
print(response.json())<?php
$url = "https://apitest.payu.in/v2/payments";
$payload = json_encode([
"accountId" => "<YOUR_TEST_KEY>",
"txnId" => "ZP6267f0d2996ce",
"amount" => 10,
"paymentMethod" => [
"name" => "CreditCard",
"bankCode" => "CC",
"paymentCard" => [
"cardNumber" => "5004461234560000",
"validThrough" => "<SANDBOX_CARD_EXPIRY_MM_YY>",
"ownerName" => "John Doe",
"cvv" => "987"
]
],
"order" => [
"productInfo" => "Direct Authorization Payment",
"orderedItem" => [
[
"itemId" => "1",
"description" => "Product Description",
"quantity" => 1,
"amount" => 10.0
]
],
"paymentChargeSpecification" => [
"price" => 10,
"netAmountDebit" => 10
]
],
"additionalInfo" => [
"createOrder" => false,
"placeOrder" => false,
"txnS2sFlow" => "3"
],
"callBackActions" => [
"successAction" => "<redacted URL>",
"failureAction" => "<redacted URL>",
"cancelAction" => "<redacted URL>"
],
"billingDetails" => [
"firstName" => "John",
"lastName" => "Doe",
"address1" => "123 Main Street",
"city" => "Mumbai",
"state" => "Maharashtra",
"country" => "India",
"zipCode" => "400001",
"phone" => "9876543210",
"email" => "[email protected]"
],
"authorization" => [
"eci" => "05",
"cavv" => "AAABAWFlmQAAAABjRWWZEEFgFz",
"flowType" => "Frictionless",
"threeDSTransID" => "67b4c71f-19bf-4d97-bd09-4e3687dc9e42",
"threeDSServerTransID" => "eea30d14-71cf-41af-b961-f95b7d67dc93",
"threeDSTransStatus" => "Y",
"threeDSTransStatusReason" => "01",
"acquirer_bin" => "401200"
],
"threeDS2RequestData" => [
"threeDSVersion" => "2.2.0",
"deviceChannel" => "APP"
]
]);
$ch = curl_init($url);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_HTTPHEADER, [
"Content-Type: application/json",
"date: <CURRENT_DATE_GMT>",
"authorization: hmac username=\"<YOUR_TEST_KEY>\", algorithm=\"sha512\", headers=\"date\", signature=\"<YOUR_SIGNATURE>\""
]);
curl_setopt($ch, CURLOPT_POSTFIELDS, $payload);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$response = curl_exec($ch);
curl_close($ch);
echo $response;
?>import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class DirectAuthRequest {
public static void main(String[] args) throws Exception {
HttpClient client = HttpClient.newHttpClient();
String payload = """
{
"accountId": "<YOUR_TEST_KEY>",
"txnId": "ZP6267f0d2996ce",
"amount": 10,
"paymentMethod": {
"name": "CreditCard",
"bankCode": "CC",
"paymentCard": {
"cardNumber": "5004461234560000",
"validThrough": "<SANDBOX_CARD_EXPIRY_MM_YY>",
"ownerName": "John Doe",
"cvv": "987"
}
},
"order": {
"productInfo": "Direct Authorization Payment",
"paymentChargeSpecification": {
"price": 10,
"netAmountDebit": 10
}
},
"additionalInfo": {
"createOrder": false,
"placeOrder": false,
"txnS2sFlow": "3"
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>"
},
"billingDetails": {
"firstName": "John",
"lastName": "Doe",
"phone": "9876543210",
"email": "[email protected]"
},
"authorization": {
"eci": "05",
"cavv": "AAABAWFlmQAAAABjRWWZEEFgFz",
"flowType": "Frictionless",
"threeDSTransID": "67b4c71f-19bf-4d97-bd09-4e3687dc9e42",
"threeDSTransStatus": "Y",
"acquirer_bin": "401200"
}
}
""";
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://apitest.payu.in/v2/payments"))
.header("Content-Type", "application/json")
.header("date", "<CURRENT_DATE_GMT>")
.header("authorization", "hmac username=\"<YOUR_TEST_KEY>\", algorithm=\"sha512\", headers=\"date\", signature=\"<YOUR_SIGNATURE>\"")
.POST(HttpRequest.BodyPublishers.ofString(payload))
.build();
HttpResponse<String> response = client.send(request,
HttpResponse.BodyHandlers.ofString());
System.out.println(response.body());
}
}const url = "https://apitest.payu.in/v2/payments";
const payload = {
accountId: "<YOUR_TEST_KEY>",
txnId: "ZP6267f0d2996ce",
amount: 10,
paymentMethod: {
name: "CreditCard",
bankCode: "CC",
paymentCard: {
cardNumber: "5004461234560000",
validThrough: "<SANDBOX_CARD_EXPIRY_MM_YY>",
ownerName: "John Doe",
cvv: "987"
}
},
order: {
productInfo: "Direct Authorization Payment",
paymentChargeSpecification: {
price: 10,
netAmountDebit: 10
}
},
additionalInfo: {
createOrder: false,
placeOrder: false,
txnS2sFlow: "3"
},
callBackActions: {
successAction: "<redacted URL>",
failureAction: "<redacted URL>",
cancelAction: "<redacted URL>"
},
billingDetails: {
firstName: "John",
lastName: "Doe",
phone: "9876543210",
email: "[email protected]"
},
authorization: {
eci: "05",
cavv: "AAABAWFlmQAAAABjRWWZEEFgFz",
flowType: "Frictionless",
threeDSTransID: "67b4c71f-19bf-4d97-bd09-4e3687dc9e42",
threeDSTransStatus: "Y",
acquirer_bin: "401200"
}
};
const options = {
method: "POST",
headers: {
"Content-Type": "application/json",
"date": "<CURRENT_DATE_GMT>",
"authorization": "hmac username=\"<YOUR_TEST_KEY>\", algorithm=\"sha512\", headers=\"date\", signature=\"<YOUR_SIGNATURE>\""
},
body: JSON.stringify(payload)
};
fetch(url, options)
.then(response => response.json())
.then(data => console.log(data))
.catch(error => console.error("Error:", error));Sample response
{
"status": "SUCCESS",
"result": {
"paymentId": "21667772394",
"referenceId": "ZP6267f0d2996ce"
}
}Response parameters
| Parameter | Description | Example |
|---|---|---|
status |
Direct authorization outcome status (SUCCESS, FAILED). |
SUCCESS |
result.paymentId |
Unique identifier for the payment transaction generated by PayU. |
21667772394 |
result.referenceId |
Merchant transaction reference identifier corresponding to the txnId provided in the request. |
ZP6267f0d2996ce |
Reference:To check the transaction status, refer to Verify Payment API. The Verify Payment API provides complete transaction confirmation and settlement status.
Sample Responses
Success Response
{
"status": "SUCCESS",
"result": {
"paymentId": "21667772394",
"referenceId": "ZP6267f0d2996ce"
}
}Pending Response
{
"status": "PENDING",
"result": {
"paymentId": "21667772394",
"referenceId": "ZP6267f0d2996ce"
},
"message": "Awaiting final confirmation from bank"
}Failure Response
{
"status": "FAILED",
"error": {
"code": "PAYMENT_DECLINED",
"message": "Declined by issuing bank"
},
"result": {
"paymentId": "21667772394",
"referenceId": "ZP6267f0d2996ce"
}
}Error Codes
| Code | HTTP Status | Description | Resolution |
|---|---|---|---|
INVALID_AMOUNT | 400 | Invalid amount value | Check amount format and value |
INVALID_CURRENCY | 400 | Unsupported currency | Use supported currency codes |
AUTHENTICATION_FAILED | 401 | Invalid signature or key | Verify HMAC credentials and signature header |
DUPLICATE_REFERENCE | 409 | Reference ID already used | Use unique transaction reference ID |
PAYMENT_DECLINED | 422 | Payment declined | Issuing bank declined authorization |
For complete error code list, see Error Codes Reference.
Next Steps
- Verify transaction using Verify Payment API
- Handle webhooks for asynchronous transaction status updates
- Check Dashboard for settlement and reconciliation
Always verify payment status before order fulfillment.
Updated about 1 hour ago
