Quickstart
From zero to a card payment in the MITE sandbox, on either integration.
Cards & Wallets is part of the Advanced Payments family, so the API credentials and account setup are shared with Pay by Bank.
There are two ways to take a card payment, and one explorer account lets you try both: send the card details to our API yourself and use your own payment page, or have us collect them on our payment page. Take each one for a spin below, then see Integration Options for what each asks of you.
Get an account
If you don't already have an explorer account sign up for one here to get access to our Merchant Integration Test Environment (MITE).
From the email received, take a note of your API username and password, and of the installation id (instId) of each installation — Your Payment Page and the PaySuite Payment Page installations have their own ids, and you need the right one for each integration. See Using the APIs for authentication and the base URLs to use.
Try your own payment page
When you integrate in this way, you collect the card details yourself and send them server-to-server to our API, using the instId for Your Payment Page — take the card details from the test cards rather than a real card.
Taking your first card payment
POST /acceptor/rest/transactions/{instId}/payment{
"transaction": {
"currency": "GBP",
"amount": 15.00,
"commerceType": "ECOM"
},
"paymentMethod": {
"card": {
"pan": "9902000000000018",
"cv2": "456",
"expiryDate": "1230",
"cardHolderName": "John Smith"
}
}
}curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"transaction": {
"currency": "GBP",
"amount": 15.00,
"commerceType": "ECOM"
},
"paymentMethod": {
"card": {
"pan": "9902000000000018",
"cv2": "456",
"expiryDate": "1230",
"cardHolderName": "John Smith"
}
}
}'HTTP/1.1 201 Created
{
"processing": {
"model": "MANAGE",
"authResponse": {
"statusCode": "00",
"acquirerName": "Barclays Merchant Services",
"message": "AUTH CODE:386975",
"authCode": "386975",
"gatewayReference": "c8b02dd7918aa1b094b6c85d0a260c97",
"gatewayMessage": "AUTH CODE:386975",
"avsAddressCheck": "NOT_CHECKED",
"avsPostcodeCheck": "NOT_CHECKED",
"cv2Check": "MATCHED",
"status": "AUTHORISED"
},
"route": "CPE"
},
"paymentMethod": {
"registered": false,
"card": {
"cardFingerprint": "l313hfHapXJiLXyROD3X6P75k9E=",
"new": true,
"cardType": "VISA_DEBIT",
"cardUsageType": "DEBIT",
"cardScheme": "VISA",
"cardCategory": "DEBIT",
"maskedPan": "990200******0018",
"expiryDate": "1230",
"issuer": "PAY360 TESTING",
"issuerCountry": "GBR",
"cardHolderName": "John Smith"
},
"billingAddress": {},
"paymentClass": "CARD",
"reuse": {
"storage": "NONE"
}
},
"customFields": {
"fieldState": []
},
"threeDSecure": {
"versionsAttempted": [
{
"version": 2,
"availability": "ISSUER_NO_3DS"
}
]
},
"transaction": {
"transactionId": "10254747396",
"status": "SUCCESS",
"stage": "COMPLETE",
"type": "PAYMENT",
"amount": 15.00,
"consumerSpend": 15.00,
"currency": "GBP",
"transactionTime": "2026-09-11T10:51:14.537+01:00",
"receivedTime": "2026-09-11T10:51:14.537+01:00",
"customerInitiated": true
},
"outcome": {
"status": "SUCCESS",
"reasonCode": "S100",
"reasonMessage": "Authorised"
},
"strongCustomerAuthentication": {
"transactionType": "GOODS_OR_SERVICES"
},
"trace": "T_YHFJ4OjfWFuvFDm8uR77A",
"link": [
{
"href": "https://api.mite.pay360.com/acceptor/rest/transactions/5315271/10254747396",
"rel": "transaction"
}
]
}- An outcome.reasonCode of S100 means the payment was authorised. See Response Codes and Messages for the other outcomes, and Test Cards for the PANs that simulate declines and 3D Secure.
Try the PaySuite payment page
When you integrate in this way, we collect the card details instead: you just create a hosted session against your PaySuite Payment Page instId, then send your customer to the payment page we return. You can be that customer — this is the one you can click through yourself.
- Create the session with the request below.
- Open the
redirectUrlfrom the response in your browser. - Pay with the test card
9900000000005159, any future expiry date and any CSV.
Create a payment session
POST /hosted/rest/sessions/{instId}/payments{
"session": {
"returnUrl": {
"url": "https://www.example.com/return"
}
},
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 25.00
}
},
"merchantReference": "aReference"
}
}curl -X POST "{targetEnvironmentPath}/hosted/rest/sessions/{instId}/payments" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"session": {
"returnUrl": {
"url": "https://www.example.com/return"
}
},
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 25.00
}
},
"merchantReference": "aReference"
}
}'HTTP/1.1 201 Created
{
"sessionId": "SMjo-nVACrY1K8pP7Vfs-iQOF",
"redirectUrl": "https://secure.mite.pay360.com/hosted/SMjo-nVACrY1K8pP7Vfs-iQOF/begin/SMjo-nVACrY1K8pP7Vfs-iQOF",
"status": "SUCCESS"
}- Open the redirectUrl in your browser, then pay with the test card 9900000000005159 — it is enrolled in 3D Secure and authorises, so you see the whole flow. Other test cards simulate declines.
- The customer's browser returns to your returnUrl once processing has finished. Keep the sessionId to retrieve the session status, which is where the transaction id comes from.
Next steps
- Integration Options — which integration fits your requirements, and what each one asks of you.
- PaySuite payment page — the hosted integration you tried above, where we host the payment form for you.
- Your payment page — build the payment flow yourself using our API.
- Transaction types — the types of transactions we offer.