Using the APIs
Looking for some tips to get started? The following section covers how you should construct your API messages, where you should send them for testing and live processing plus information about response codes and messages.
Get your credentials
In order to handle your request securely and reliably, you will need to submit credentials specific to your organisation with each request. You will also be issued with at least one installation identifier. If your company has multiple websites you may have a separate installation for each.
To get credentials for our Merchant Integration Test Environment (MITE), sign up for an Explorer account. You can use this environment to explore our products and start your integration. We'll email you all the information you need to start using:
- PaySuite Payment Page ( Hosted Cashier )
- Your Payment Page ( Cashier API )
- CardLock
Our Implementations team will provide your Live credentials once your integration is complete and your account is set up and ready to use.
Authenticating your requests
Every request must carry your credentials in the Authorization header using the HTTP
Basic scheme: your API user and password joined by a colon, then Base64-encoded. For
example:
POST /acceptor/rest/transactions/{instId}/payment
Authorization: Basic YXBpVXNlcjphcGlQYXNzd29yZA==
Content-Type: application/jsonThe cURL examples throughout these docs use curl's -u shorthand instead, which encodes
the pair and sets the header for you — so you can paste an example straight into a
terminal only needing to fill in your own credentials:
curl -X POST "https://api.mite.pay360.com/acceptor/rest/transactions/{instId}/payment" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json"Because HTTP Basic sends your credentials with every call, only ever make these calls from your own server — never from a browser or mobile app, where the credentials would be exposed.
Endpoints
All requests to our services must be submitted as HTTPS using TLS v1.2 or higher.
Use the following endpoints to submit requests:
| Environment | Purpose | Base URL |
|---|---|---|
| MITE (test) | API requests | https://api.mite.pay360.com |
| Live | API requests | https://api.pay360.com |
Anatomy of a request
All of our API requests are submitted as a URL. This is of the form:
<endpoint path><request path>
For example, a new transaction in the test environment might be:
https://api.mite.pay360.com/acceptor/rest/transactions/{instId}/{resourceId}/action
Additionally, the request path for our server-to-server API calls has the following structure:
| Part | Examples | Description |
|---|---|---|
| Base URL | https://api.pay360.com | The base URL for our REST services. |
| Resource type | /acceptor/rest/transactions, /hosted/rest/sessions | The type of resource you are submitting the request for. |
| instId | — | The ID for your installation, as provided by our Client Management team. |
| resourceId | /<CustomerID>, /<TransactionID> | The ID for a resource being fetched or operated on. Not present when creating a new resource. |
| Action | /payment, /refund | The action being performed. |
The body of the requests and responses use the JSON format. When the operation is
successful the response code will be a 200, or 201 where a new resource is created.
Testing connectivity
You can test basic connectivity to our services using a Ping request.
Your Payment Page
GET /acceptor/rest/transactions/ping
HTTP/1.1 200PaySuite Payment Page
GET /hosted/rest/sessions/ping
HTTP/1.1 200