Cards & Wallets · Getting Started

Using the APIs

Looking for some tips to get started? The following section covers how you should construct your API messages, where you should send them for testing and live processing plus information about response codes and messages.

Get your credentials

In order to handle your request securely and reliably, you will need to submit credentials specific to your organisation with each request. You will also be issued with at least one installation identifier. If your company has multiple websites you may have a separate installation for each.

To get credentials for our Merchant Integration Test Environment (MITE), sign up for an Explorer account. You can use this environment to explore our products and start your integration. We'll email you all the information you need to start using:

  • PaySuite Payment Page ( Hosted Cashier )
  • Your Payment Page ( Cashier API )
  • CardLock

Our Implementations team will provide your Live credentials once your integration is complete and your account is set up and ready to use.

Authenticating your requests

Every request must carry your credentials in the Authorization header using the HTTP Basic scheme: your API user and password joined by a colon, then Base64-encoded. For example:

Request header
POST /acceptor/rest/transactions/{instId}/payment
Authorization: Basic YXBpVXNlcjphcGlQYXNzd29yZA==
Content-Type: application/json

The cURL examples throughout these docs use curl's -u shorthand instead, which encodes the pair and sets the header for you — so you can paste an example straight into a terminal only needing to fill in your own credentials:

cURL
curl -X POST "https://api.mite.pay360.com/acceptor/rest/transactions/{instId}/payment" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json"

Because HTTP Basic sends your credentials with every call, only ever make these calls from your own server — never from a browser or mobile app, where the credentials would be exposed.

Endpoints

All requests to our services must be submitted as HTTPS using TLS v1.2 or higher.

Use the following endpoints to submit requests:

EnvironmentPurposeBase URL
MITE (test)API requestshttps://api.mite.pay360.com
LiveAPI requestshttps://api.pay360.com

Anatomy of a request

All of our API requests are submitted as a URL. This is of the form:

<endpoint path><request path>

For example, a new transaction in the test environment might be:

https://api.mite.pay360.com/acceptor/rest/transactions/{instId}/{resourceId}/action

Additionally, the request path for our server-to-server API calls has the following structure:

PartExamplesDescription
Base URLhttps://api.pay360.comThe base URL for our REST services.
Resource type/acceptor/rest/transactions, /hosted/rest/sessionsThe type of resource you are submitting the request for.
instId—The ID for your installation, as provided by our Client Management team.
resourceId/<CustomerID>, /<TransactionID>The ID for a resource being fetched or operated on. Not present when creating a new resource.
Action/payment, /refundThe action being performed.

The body of the requests and responses use the JSON format. When the operation is successful the response code will be a 200, or 201 where a new resource is created.

Our APIs are continuously evolving. We will not take any fields away without giving advance notice, but we may add new response fields at any time — your integration must be able to cope with the appearance of new fields.

Testing connectivity

You can test basic connectivity to our services using a Ping request.

Your Payment Page

API ping
GET /acceptor/rest/transactions/ping

HTTP/1.1 200

PaySuite Payment Page

Hosted ping
GET /hosted/rest/sessions/ping

HTTP/1.1 200