POST

Authorizations

Authorization
string
header
required

The caller's access_token from authentication. Management API callers send the id_token. The program and environment come from the token.

Path Parameters

customerId
string
required

The customer id.

Query Parameters

programId
string

Required on the Management API, where the token carries no program: omitting it returns 400. Customer API callers resolve the program from their token and should omit it; a value sent there is ignored.

Body

application/json
action
enum<string>
required

The step to run.

Available options:
verify,
initiate,
passkey-challenge,
submit
payments
object[]

The payment items. Required for verify, initiate, and submit.

scaChallenge
object

The strong-customer-authentication challenge from initiate. Pass it back on submit.

confirmation
Passkey · object

Step-up confirmation (for submit). Set method to passkey, totp, or pin and include that method's fields. pin is a program capability: see Program capabilities.

idempotencyKey
string<uuid>

Optional. Mint a fresh UUID for every batch. Not a replay key: a shared key re-runs the batch rather than returning the first result.

batchId
string<uuid>

Optional. On verify, the draft being re-verified after edits: omit to create a new draft. On submit, the draft to pay; it is checked for expiry and ownership and cannot be paid twice. Absent keeps the pre-draft behaviour.

accessToken
string
deprecated

Legacy step-up credential. Superseded by confirmation.

totp
string
deprecated

Legacy TOTP step-up code. Superseded by confirmation.

passkeySession
string
deprecated

Legacy passkey session id. Superseded by confirmation.

assertion
string
deprecated

Legacy passkey assertion. Superseded by confirmation.

Response

Result for the requested action

success
boolean
required
Example:

true

data
object
required