This scenario is applicable if you wanted to collect payments using network tokens.
HTTP Method: POST
Applicable scenarios
- Merchant has the card token, TAVV(Cryptogram), and the last four digits of the card
- The token could be created by the merchant or through another partner
Note: This scenario is applicable if you are PCI compliant and got the network token and TAVV from any other aggregator or schemes and then sending the card transaction request in the form of authentication.
Request headers
| Parameter | Description |
|---|---|
| date | The current date and time. For example, format of the date is Wed, 28 Jun 2023 11:25:19 GMT. |
| authorization | The actual HMAC signature generated using the specified algorithm (sha512) and includes the hashed data. For more information, refer to authorization fields description. |
authorization fields description
| Field | Description |
|---|---|
| username | Represents the username or identifier for the client or merchant, for example smsplus. |
| algorithm | Use SHA512 algorithm for hashing and send this as header value. |
| headers | Specifies which headers have been used in generating the hash, for example date. |
| signature | The HMAC signature generated using the specified algorithm. For more information, refer to hashing algorithm. |
hashing algorithm
You must hash the request parameters using the following hash logic:
Hash logic: sha512(`<Body data>` + '|' + date + '|' + merchant_secret)
Where <Body data> contains the request body posted with the request.
Sample header code
var merchant_key = '<YOUR_TEST_KEY>';
var merchant_secret = 'YOUR_TEST_SALT';
// date
var date = new Date();
date = date.toUTCString();
// authorization
var authorization = getAuthHeader(date);
function getAuthHeader(date) {
var AUTH_TYPE = 'sha512';
var data = isEmpty(request['data']) ? "" : request['data'];
var hash_string = data + '|' + date + '|' + merchant_secret;
var hash = CryptoJS.SHA512(hash_string).toString(CryptoJS.enc.Hex);
return `hmac username="${merchant_key}", algorithm="${AUTH_TYPE}", headers="date", signature="${hash}"`;
}Request Parameters
paymentMethod Object (Network Token)
paymentMethod Object (Network Token)The table has 7 rows, so here it is in HTML format:
Mandatory parameters
| Parameter | Description |
|---|---|
name | String Set to "CreditCard" or "DebitCard". |
paymentCard | Object Token details issued by the card network. |
paymentCard.cardToken | String Network token string issued by Visa, Mastercard, or RuPay. |
paymentCard.cardTokenType | String Set to "NETWORK". |
paymentCard.tavv | String Dynamic cryptogram generated for the transaction (obtained via Get Payment Details API). |
paymentCard.last4Digits | String Last 4 digits of the underlying primary account number (e.g. "2346"). |
Optional parameters
| Parameter | Description |
|---|---|
paymentCard.cvv | String 3-digit CVV (if required by merchant terminal profile). |
Sample Request
curl --location --request POST '<redacted URL>' \
--header 'Content-Type: application/json' \
--header 'Date: Mon, 05 Oct 2026 08:30:00 GMT' \
--header 'Authorization: hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"' \
--data-raw '{
"accountId": "merchant_key",
"txnId": "TXN_NETTOK_1728135000",
"order": {
"currency": "INR",
"paymentChargeSpecification": {
"price": 1000.00
}
},
"customer": {
"email": "[email protected]",
"phone": "9876543210",
"name": "Jane Smith"
},
"paymentMethod": {
"name": "CreditCard",
"paymentCard": {
"cardToken": "29850879bf39848ca078727b8e1a95165a41cea1",
"cardTokenType": "NETWORK",
"tavv": "/wAAAAAAPtP+g6IAmbSeg1gAAAA=",
"last4Digits": "2346",
"cvv": "123"
}
},
"billingDetails": {
"address1": "456 Commerce Avenue",
"city": "Mumbai",
"state": "Maharashtra",
"country": "India",
"postalCode": "400001"
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>",
"termAction": "<redacted URL>"
},
"additionalInfo": {
"txnS2sFlow": "4"
}
}'import requests
import json
url = "<redacted URL>"
payload = {
"accountId": "merchant_key",
"txnId": "TXN_NETTOK_1728135000",
"order": {
"currency": "INR",
"paymentChargeSpecification": {
"price": 1000.00
}
},
"customer": {
"email": "[email protected]",
"phone": "9876543210",
"name": "Jane Smith"
},
"paymentMethod": {
"name": "CreditCard",
"paymentCard": {
"cardToken": "29850879bf39848ca078727b8e1a95165a41cea1",
"cardTokenType": "NETWORK",
"tavv": "/wAAAAAAPtP+g6IAmbSeg1gAAAA=",
"last4Digits": "2346",
"cvv": "123"
}
},
"billingDetails": {
"address1": "456 Commerce Avenue",
"city": "Mumbai",
"state": "Maharashtra",
"country": "India",
"postalCode": "400001"
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>",
"termAction": "<redacted URL>"
},
"additionalInfo": {
"txnS2sFlow": "4"
}
}
headers = {
"Content-Type": "application/json",
"Date": "Mon, 05 Oct 2026 08:30:00 GMT",
"Authorization": 'hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
}
response = requests.post(url, headers=headers, json=payload)
print(response.json())<?php
$curl = curl_init();
$payload = json_encode([
"accountId" => "merchant_key",
"txnId" => "TXN_NETTOK_1728135000",
"order" => [
"currency" => "INR",
"paymentChargeSpecification" => [
"price" => 1000.00
]
],
"customer" => [
"email" => "[email protected]",
"phone" => "9876543210",
"name" => "Jane Smith"
],
"paymentMethod" => [
"name" => "CreditCard",
"paymentCard" => [
"cardToken" => "29850879bf39848ca078727b8e1a95165a41cea1",
"cardTokenType" => "NETWORK",
"tavv" => "/wAAAAAAPtP+g6IAmbSeg1gAAAA=",
"last4Digits" => "2346",
"cvv" => "123"
]
],
"billingDetails" => [
"address1" => "456 Commerce Avenue",
"city" => "Mumbai",
"state" => "Maharashtra",
"country" => "India",
"postalCode" => "400001"
],
"callBackActions" => [
"successAction" => "<redacted URL>",
"failureAction" => "<redacted URL>",
"cancelAction" => "<redacted URL>",
"termAction" => "<redacted URL>"
],
"additionalInfo" => [
"txnS2sFlow" => "4"
]
]);
curl_setopt_array($curl, [
CURLOPT_URL => '<redacted URL>',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_POSTFIELDS => $payload,
CURLOPT_HTTPHEADER => [
'Content-Type: application/json',
'Date: Mon, 05 Oct 2026 08:30:00 GMT',
'Authorization: hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
],
]);
$response = curl_exec($curl);
curl_close($curl);
echo $response;import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class NetworkTokenPayment {
public static void main(String[] args) throws Exception {
String payload = """
{
"accountId": "merchant_key",
"txnId": "TXN_NETTOK_1728135000",
"order": {
"currency": "INR",
"paymentChargeSpecification": {
"price": 1000.00
}
},
"customer": {
"email": "[email protected]",
"phone": "9876543210",
"name": "Jane Smith"
},
"paymentMethod": {
"name": "CreditCard",
"paymentCard": {
"cardToken": "29850879bf39848ca078727b8e1a95165a41cea1",
"cardTokenType": "NETWORK",
"tavv": "/wAAAAAAPtP+g6IAmbSeg1gAAAA=",
"last4Digits": "2346",
"cvv": "123"
}
},
"billingDetails": {
"address1": "456 Commerce Avenue",
"city": "Mumbai",
"state": "Maharashtra",
"country": "India",
"postalCode": "400001"
},
"callBackActions": {
"successAction": "<redacted URL>",
"failureAction": "<redacted URL>",
"cancelAction": "<redacted URL>",
"termAction": "<redacted URL>"
},
"additionalInfo": {
"txnS2sFlow": "4"
}
}
""";
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("<redacted URL>"))
.header("Content-Type", "application/json")
.header("Date", "Mon, 05 Oct 2026 08:30:00 GMT")
.header("Authorization", "hmac username=\"merchant_key\", algorithm=\"sha512\", headers=\"date\", signature=\"<SIGNATURE>\"")
.POST(HttpRequest.BodyPublishers.ofString(payload))
.build();
HttpClient client = HttpClient.newHttpClient();
HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
System.out.println(response.body());
}
}const axios = require('axios');
const data = {
accountId: "merchant_key",
txnId: "TXN_NETTOK_1728135000",
order: {
currency: "INR",
paymentChargeSpecification: {
price: 1000.00
}
},
customer: {
email: "[email protected]",
phone: "9876543210",
name: "Jane Smith"
},
paymentMethod: {
name: "CreditCard",
paymentCard: {
cardToken: "29850879bf39848ca078727b8e1a95165a41cea1",
cardTokenType: "NETWORK",
tavv: "/wAAAAAAPtP+g6IAmbSeg1gAAAA=",
last4Digits: "2346",
cvv: "123"
}
},
billingDetails: {
address1: "456 Commerce Avenue",
city: "Mumbai",
state: "Maharashtra",
country: "India",
postalCode: "400001"
},
callBackActions: {
successAction: "<redacted URL>",
failureAction: "<redacted URL>",
cancelAction: "<redacted URL>",
termAction: "<redacted URL>"
},
additionalInfo: {
txnS2sFlow: "4"
}
};
const config = {
method: 'post',
url: '<redacted URL>',
headers: {
'Content-Type': 'application/json',
'Date': 'Mon, 05 Oct 2026 08:30:00 GMT',
'Authorization': 'hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
},
data: data
};
axios(config)
.then(response => console.log(JSON.stringify(response.data)))
.catch(error => console.error(error));Response Parameters
| Parameter | Type | Description |
|---|---|---|
| status | String | Transaction state: PENDING, SUCCESS, or FAILURE. |
| message | String | Status description. |
| result | Object | Execution metadata. |
| result.paymentId | String | PayU transaction identifier (mihpayId). |
| result.txnId | String | Merchant transaction identifier. |
| result.authAction | Object | Redirection challenge metadata. |
| result.authAction.type | String | Method of challenge: REDIRECT. |
| result.authAction.url | String | 3DS Access Control Server (ACS) redirection endpoint. |
Sample Response
{
"status": "PENDING",
"message": "Payment initiated successfully. Please redirect the customer to complete 3D Secure authentication.",
"result": {
"paymentId": "403993715535615888",
"txnId": "TXN_NETTOK_1728135000",
"authAction": {
"type": "REDIRECT",
"url": "<redacted URL>"
}
}
}Next Steps
- Complete 3DS Authentication:
- Redirect the cardholder to
result.authAction.urlto complete issuing bank challenge verification.
- Redirect the cardholder to
- Handle Postbacks:
- Capture authentication response at
callBackActions.termActionorcallBackActions.successAction.
- Capture authentication response at
- Verify Transaction State:
- Query the Verify Payment API to verify payment capture.
