async function validatePaymentResult(resultToken) {
const response = await fetch('https://service.pcibooking.net/api/eWalletOperation/validateResults', {
method: 'POST',
headers: {
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'text/plain'
},
body: resultToken
});
const data = await response.json();
return data.valid; // true if the token is authentic
}
import requests
def validate_payment_result(result_token):
response = requests.post(
'https://service.pcibooking.net/api/eWalletOperation/validateResults',
headers={
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'text/plain'
},
data=result_token
)
data = response.json()
return data['valid'] # True if the token is authentic
{
"upgChargeResults": {
"authorizationCode": "0a108f",
"currency": "EUR",
"amount": 55.01,
"operationType": "Charge",
"operationResultCode": "Success",
"operationResultDescription": "Successful operation",
"customGatewayResponse": null,
"gatewayName": "NULLSuccess",
"gatewayReference": "65151a",
"gatewayResultCode": "OK",
"gatewayResultDescription": "Gateway says: Successful operation",
"gatewayResultSubCode": null,
"gatewayResultSubDescription": null,
"gatewayToken": null,
"rejectReasonCode": null
},
"directChargeResults": null,
"tokenAndMaskedCardModel": {
"bankCard": {
"type": "Visa",
"nameOnCard": "Jane Smith",
"issueNumber": "",
"ownerId": "",
"securityCode": "***",
"number": "417666******0027",
"expirationMonth": 12,
"expirationYear": 2028
},
"threeDS": {
"eWallet": null,
"deviceManufacturerId": null,
"authenticationValue": "MDAwMDAwMDAwMDAxMTA2Njk5NFg=",
"eci": "06",
"xid": "c5c20f45-e814-4bc5-94e1-cb35bcb8e0d9",
"version": "2.2.0",
"sli": null,
"acsTransactionId": "d519b384-af79-4fcb-8223-cc74187b2d0e",
"universal_TransactionId": "301d5d26-2a60-465b-a8aa-898aaaffb281"
},
"errorMessage": null,
"cardBrand": "Visa",
"token": "https://service.pcibooking.net/api/payments/paycard/6d895c3025184ae89b5f565374dfb7cc",
"tokenLocation": null
},
"selectedPaymentMethod": "CardPay",
"transactionAmount": 55.01,
"transactionCurrency": "EUR",
"transactionTimestamp": "2026-10-05T17:21:58.2096507Z",
"providerTransactionId": "65151a",
"providerAuthorizationCode": "0a108f",
"providerAccountId": "NULLsuccess",
"attempts": [
{
"seq": 1,
"prv": "CardPay",
"ts": "2026-10-05T17:21:58.2094965Z",
"suc": true,
"fail": null,
"err": null,
"dur": 0,
"fb": false,
"req": null,
"res": null,
"tid": "65151a",
"auth": "0a108f"
}
]
}
{
"code": -125,
"message": "Bad input data",
"moreInfo": "...",
"errorList": null
}
Library Setup & Use
Validate Operation Result
Validate the data returned to the client after a Payments Library operation to ensure it was not altered.
POST
/
api
/
eWalletOperation
/
validateResults
async function validatePaymentResult(resultToken) {
const response = await fetch('https://service.pcibooking.net/api/eWalletOperation/validateResults', {
method: 'POST',
headers: {
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'text/plain'
},
body: resultToken
});
const data = await response.json();
return data.valid; // true if the token is authentic
}
import requests
def validate_payment_result(result_token):
response = requests.post(
'https://service.pcibooking.net/api/eWalletOperation/validateResults',
headers={
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'text/plain'
},
data=result_token
)
data = response.json()
return data['valid'] # True if the token is authentic
{
"upgChargeResults": {
"authorizationCode": "0a108f",
"currency": "EUR",
"amount": 55.01,
"operationType": "Charge",
"operationResultCode": "Success",
"operationResultDescription": "Successful operation",
"customGatewayResponse": null,
"gatewayName": "NULLSuccess",
"gatewayReference": "65151a",
"gatewayResultCode": "OK",
"gatewayResultDescription": "Gateway says: Successful operation",
"gatewayResultSubCode": null,
"gatewayResultSubDescription": null,
"gatewayToken": null,
"rejectReasonCode": null
},
"directChargeResults": null,
"tokenAndMaskedCardModel": {
"bankCard": {
"type": "Visa",
"nameOnCard": "Jane Smith",
"issueNumber": "",
"ownerId": "",
"securityCode": "***",
"number": "417666******0027",
"expirationMonth": 12,
"expirationYear": 2028
},
"threeDS": {
"eWallet": null,
"deviceManufacturerId": null,
"authenticationValue": "MDAwMDAwMDAwMDAxMTA2Njk5NFg=",
"eci": "06",
"xid": "c5c20f45-e814-4bc5-94e1-cb35bcb8e0d9",
"version": "2.2.0",
"sli": null,
"acsTransactionId": "d519b384-af79-4fcb-8223-cc74187b2d0e",
"universal_TransactionId": "301d5d26-2a60-465b-a8aa-898aaaffb281"
},
"errorMessage": null,
"cardBrand": "Visa",
"token": "https://service.pcibooking.net/api/payments/paycard/6d895c3025184ae89b5f565374dfb7cc",
"tokenLocation": null
},
"selectedPaymentMethod": "CardPay",
"transactionAmount": 55.01,
"transactionCurrency": "EUR",
"transactionTimestamp": "2026-10-05T17:21:58.2096507Z",
"providerTransactionId": "65151a",
"providerAuthorizationCode": "0a108f",
"providerAccountId": "NULLsuccess",
"attempts": [
{
"seq": 1,
"prv": "CardPay",
"ts": "2026-10-05T17:21:58.2094965Z",
"suc": true,
"fail": null,
"err": null,
"dur": 0,
"fb": false,
"req": null,
"res": null,
"tid": "65151a",
"auth": "0a108f"
}
]
}
{
"code": -125,
"message": "Bad input data",
"moreInfo": "...",
"errorList": null
}
Payments Library Reference
Complete reference for Payments Library operations
Error Responses
| Code | HTTP Status | Condition |
|---|---|---|
| none | 401 | API key is missing or invalid. The response body is empty. |
-125 | 400 | The results token is invalid or could not be verified. |
Parameters
Authentication
API key only. This endpoint does not accept access tokens or session tokens.string
required
Your API key prefixed with
APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.Request Body
string
required
The payment token string received in the client-side callback function. Pass it as the raw request body.
async function validatePaymentResult(resultToken) {
const response = await fetch('https://service.pcibooking.net/api/eWalletOperation/validateResults', {
method: 'POST',
headers: {
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'text/plain'
},
body: resultToken
});
const data = await response.json();
return data.valid; // true if the token is authentic
}
import requests
def validate_payment_result(result_token):
response = requests.post(
'https://service.pcibooking.net/api/eWalletOperation/validateResults',
headers={
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'text/plain'
},
data=result_token
)
data = response.json()
return data['valid'] # True if the token is authentic
Response
A successful validation returns the decoded operation results. Which fields are populated depends on the operation and payment method:upgChargeResults- PSP transaction details for card, Apple Pay, and Google Pay charges. Always a single object holding the final gateway attempt.failedUpgChargeResults- Array of earlier failed attempts when a payment gateway fallback chain ran. Absent from the response when the first attempt was the only one.directChargeResults- Results for redirect-based methods (PayPal, bank payments, UPI).tokenAndMaskedCardModel- Token and masked card details forTOKENIZE,CHARGE_AND_TOKENIZE, andPREAUTH_AND_TOKENIZEoperations.
selectedPaymentMethod- The payment method the customer used:CardPay,ApplePay,GooglePay,PayPal,BankPayorUPI.transactionAmount- Amount in the currency’s standard unit.transactionCurrency- ISO 4217 currency code.transactionTimestamp- UTC time the transaction was processed, ISO 8601.providerTransactionId- The PSP’s transaction reference for the final attempt.providerAuthorizationCode- Authorization code returned by the PSP, when there is one.providerAccountId- The name of the payment gateway or eWallet account in PCI Booking that processed the final attempt.attempts- One entry per processing attempt, in order. The first entry is the primary attempt and later entries are fallback attempts. Field names are abbreviated:
| Field | Meaning |
|---|---|
seq | Sequence number, 1 for the first attempt |
prv | Provider used for this attempt, for example CardPay or PayPal |
ts | UTC time the attempt started |
suc | true if this attempt succeeded |
fail | Failure reason, null on success |
err | Provider error code, null on success |
dur | Processing time in milliseconds |
fb | true if this failure triggered a fallback to the next provider |
req | Sanitized request snapshot as a JSON string, may be null |
res | Sanitized response snapshot as a JSON string, may be null |
tid | PSP transaction ID for this attempt |
auth | Authorization code for this attempt |
-125 with HTTP 400.
{
"upgChargeResults": {
"authorizationCode": "0a108f",
"currency": "EUR",
"amount": 55.01,
"operationType": "Charge",
"operationResultCode": "Success",
"operationResultDescription": "Successful operation",
"customGatewayResponse": null,
"gatewayName": "NULLSuccess",
"gatewayReference": "65151a",
"gatewayResultCode": "OK",
"gatewayResultDescription": "Gateway says: Successful operation",
"gatewayResultSubCode": null,
"gatewayResultSubDescription": null,
"gatewayToken": null,
"rejectReasonCode": null
},
"directChargeResults": null,
"tokenAndMaskedCardModel": {
"bankCard": {
"type": "Visa",
"nameOnCard": "Jane Smith",
"issueNumber": "",
"ownerId": "",
"securityCode": "***",
"number": "417666******0027",
"expirationMonth": 12,
"expirationYear": 2028
},
"threeDS": {
"eWallet": null,
"deviceManufacturerId": null,
"authenticationValue": "MDAwMDAwMDAwMDAxMTA2Njk5NFg=",
"eci": "06",
"xid": "c5c20f45-e814-4bc5-94e1-cb35bcb8e0d9",
"version": "2.2.0",
"sli": null,
"acsTransactionId": "d519b384-af79-4fcb-8223-cc74187b2d0e",
"universal_TransactionId": "301d5d26-2a60-465b-a8aa-898aaaffb281"
},
"errorMessage": null,
"cardBrand": "Visa",
"token": "https://service.pcibooking.net/api/payments/paycard/6d895c3025184ae89b5f565374dfb7cc",
"tokenLocation": null
},
"selectedPaymentMethod": "CardPay",
"transactionAmount": 55.01,
"transactionCurrency": "EUR",
"transactionTimestamp": "2026-10-05T17:21:58.2096507Z",
"providerTransactionId": "65151a",
"providerAuthorizationCode": "0a108f",
"providerAccountId": "NULLsuccess",
"attempts": [
{
"seq": 1,
"prv": "CardPay",
"ts": "2026-10-05T17:21:58.2094965Z",
"suc": true,
"fail": null,
"err": null,
"dur": 0,
"fb": false,
"req": null,
"res": null,
"tid": "65151a",
"auth": "0a108f"
}
]
}
{
"code": -125,
"message": "Bad input data",
"moreInfo": "...",
"errorList": null
}

