Skip to main content
POST

Payments Library Reference

Complete reference for Payments Library operations
After a charge or tokenization operation completes, the client-side Payments Library returns a payment token to your callback function. Call this endpoint from your server to verify the token is authentic and has not been tampered with.

Error Responses

Parameters

Authentication

API key only. This endpoint does not accept access tokens or session tokens.
string
required
Your API key prefixed with APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.

Request Body

string
required
The payment token string received in the client-side callback function. Pass it as the raw request body.

Response

A successful validation returns the decoded operation results. Which fields are populated depends on the operation and payment method:
  • upgChargeResults - PSP transaction details for card, Apple Pay, and Google Pay charges. Always a single object holding the final gateway attempt.
  • failedUpgChargeResults - Array of earlier failed attempts when a payment gateway fallback chain ran. Absent from the response when the first attempt was the only one.
  • directChargeResults - Results for redirect-based methods (PayPal, bank payments, UPI).
  • tokenAndMaskedCardModel - Token and masked card details for TOKENIZE, CHARGE_AND_TOKENIZE, and PREAUTH_AND_TOKENIZE operations.
The following summary fields are present on every result, whichever payment method was used:
  • selectedPaymentMethod - The payment method the customer used: CardPay, ApplePay, GooglePay, PayPal, BankPay or UPI.
  • transactionAmount - Amount in the currency’s standard unit.
  • transactionCurrency - ISO 4217 currency code.
  • transactionTimestamp - UTC time the transaction was processed, ISO 8601.
  • providerTransactionId - The PSP’s transaction reference for the final attempt.
  • providerAuthorizationCode - Authorization code returned by the PSP, when there is one.
  • providerAccountId - The name of the payment gateway or eWallet account in PCI Booking that processed the final attempt.
  • attempts - One entry per processing attempt, in order. The first entry is the primary attempt and later entries are fallback attempts. Field names are abbreviated:
An invalid or tampered token returns error -125 with HTTP 400.