v53

latestOpenAPI 3.1.0raw.githubusercontent.com2026-07-3128260917.5 KB
Payments

Create a payment session

Creates a payment session for Drop-in, Components, and Hosted Checkout integrations.

The response contains encrypted payment session data. The front end then uses the session data to make any required server-side calls for the payment flow.

You get the payment outcome asynchronously, in an AUTHORISATION webhook.

post/sessions

Headers

Idempotency-Keystring

A unique identifier for the message with a maximum of 64 characters (we recommend a UUID).

Request body

additionalDataobject

This field contains additional data, which may be required for a particular payment request.

The additionalData object consists of entries, each of which includes the key and value.

allowedPaymentMethodsstring[]

List of payment methods to be presented to the shopper. To refer to payment methods, use their payment method type.

Example: "allowedPaymentMethods":["ideal","applepay"]

blockedPaymentMethodsstring[]

List of payment methods to be hidden from the shopper. To refer to payment methods, use their payment method type.

Example: "blockedPaymentMethods":["ideal","applepay"]

captureDelayHoursinteger

The delay between the authorisation and scheduled auto-capture, specified in hours.

channel'iOS' | 'Android' | 'Web'

The platform where a payment transaction takes place. This field is optional for filtering out payment methods that are only available on specific platforms. If this value is not set, then we will try to infer it from the sdkVersion or token.

Possible values:

  • iOS
  • Android
  • Web
countryCodestring

The shopper's two-letter country code.

dateOfBirthstring date

The shopper's date of birth.

Format ISO-8601: YYYY-MM-DD

deliverAtstring date-time

The date and time when the purchased goods should be delivered.

ISO 8601 format: YYYY-MM-DDThh:mm:ss+TZD, for example, 2020-12-18T10:15:30+01:00.

enableOneClickboolean

When true and shopperReference is provided, the shopper will be asked if the payment details should be stored for future one-click payments.

enablePayOutboolean

When true and shopperReference is provided, the payment details will be tokenized for payouts.

enableRecurringboolean

When true and shopperReference is provided, the payment details will be stored for recurring payments where the shopper is not present, such as subscription or automatic top-up payments.

expiresAtstring date-time

The date the session expires in ISO8601 format. When not specified, the expiry date is set to 1 hour after session creation. You cannot set the session expiry to more than 24 hours after session creation.

installmentOptionsobject

A set of key-value pairs that specifies the installment options available per payment method. The key must be a payment method name in lowercase. For example, card to specify installment options for all cards, or visa or mc. The value must be an object containing the installment options.

mccstring

The merchant category code (MCC) is a four-digit number, which relates to a particular market segment. This code reflects the predominant activity that is conducted by the merchant.

merchantAccountstring required

The merchant account identifier, with which you want to process the transaction.

merchantOrderReferencestring

This reference allows linking multiple transactions to each other for reporting purposes (i.e. order auth-rate). The reference should be unique per billing cycle. The same merchant order reference should never be reused after the first authorised attempt. If used, this field should be supplied for all incoming authorisations.

We strongly recommend you send the merchantOrderReference value to benefit from linking payment requests when authorisation retries take place. In addition, we recommend you provide retry.orderAttemptNumber, retry.chainAttemptNumber, and retry.skipRetry values in PaymentRequest.additionalData.

metadataobject

Metadata consists of entries, each of which includes a key and a value. Limits:

  • Maximum 20 key-value pairs per request.
  • Maximum 20 characters per key.
  • Maximum 80 characters per value.
mode'embedded' | 'hosted'

Indicates the type of front end integration. Possible values:

  • embedded (default): Drop-in or Components integration
  • hosted: Hosted Checkout integration
recurringExpirystring

Date after which no further authorisations shall be performed. Only for 3D Secure 2.

recurringFrequencystring

Minimum number of days between authorisations. Only for 3D Secure 2.

recurringProcessingModel'CardOnFile' | 'Subscription' | 'UnscheduledCardOnFile'

Defines a recurring payment type. Required when creating a token to store payment details. Allowed values:

  • Subscription – A transaction for a fixed or variable amount, which follows a fixed schedule.
  • CardOnFile – With a card-on-file (CoF) transaction, card details are stored to enable one-click or omnichannel journeys, or simply to streamline the checkout process. Any subscription not following a fixed schedule is also considered a card-on-file transaction.
  • UnscheduledCardOnFile – An unscheduled card-on-file (UCoF) transaction is a transaction that occurs on a non-fixed schedule and/or have variable amounts. For example, automatic top-ups when a cardholder's balance drops below a certain amount.
redirectFromIssuerMethodstring

Specifies the redirect method (GET or POST) when redirecting back from the issuer.

redirectToIssuerMethodstring

Specifies the redirect method (GET or POST) when redirecting to the issuer.

referencestring required

The reference to uniquely identify a payment.

returnUrlstring required

The URL to return to in case of a redirection. The format depends on the channel.

  • For web, include the protocol http:// or https://. You can also include your own additional query parameters, for example, shopper ID or order reference number. Example: https://your-company.example.com/checkout?shopperOrder=12xy
  • For iOS, use the custom URL for your app. To know more about setting custom URL schemes, refer to the Apple Developer documentation. Example: my-app://
  • For Android, use a custom URL handled by an Activity on your app. You can configure it with an intent filter. Example: my-app://your.package.name

If the URL to return to includes non-ASCII characters, like spaces or special letters, URL encode the value.

We strongly recommend that you use a maximum of 1024 characters.

The URL must not include personally identifiable information (PII), for example name or email address.

shopperConversionIdstring

Use this if you made a /paymentMethods request to get the payment methods for the shopper's checkout session.

A unique ID to connect the shopper to a single checkout session that uses multiple API requests. You can use this to get insights into conversion rates.

shopperEmailstring

The shopper's email address.

shopperIPstring

The shopper's IP address. We recommend that you provide this data, as it is used in a number of risk checks (for instance, number of payment attempts or location-based checks).

Required for Visa and JCB transactions that require 3D Secure 2 authentication for all web and mobile integrations, if you did not include the shopperEmail. For native mobile integrations, the field is required to support cases where authentication is routed to the redirect flow. This field is also mandatory for some merchants depending on your business model. For more information, contact Support.

shopperInteraction'Ecommerce' | 'ContAuth' | 'Moto' | 'POS'

Specifies the sales channel, through which the shopper gives their card details, and whether the shopper is a returning customer. For the web service API, Adyen assumes Ecommerce shopper interaction by default.

This field has the following possible values:

  • Ecommerce - Online transactions where the cardholder is present (online). For better authorisation rates, we recommend sending the card security code (CSC) along with the request.
  • ContAuth - Card on file and/or subscription transactions, where the cardholder is known to the merchant (returning customer). If the shopper is present (online), you can supply also the CSC to improve authorisation (one-click payment).
  • Moto - Mail-order and telephone-order transactions where the shopper is in contact with the merchant via email or telephone.
  • POS - Point-of-sale transactions where the shopper is physically present to make a payment using a secure payment terminal.
shopperLocalestring

The language for the payment. The value combines the two-letter ISO 639-1 language code with the ISO 3166-1 alpha-2 country code. For example, nl-NL.

When using Drop-in/Components, the specified language appears if your front-end global configuration does not set the locale.

shopperReferencestring

Your reference to uniquely identify this shopper, for example user ID or account ID. The value is case-sensitive and must be at least three characters.

Your reference must not include personally identifiable information (PII) such as name or email address.

shopperStatementstring

The text to be shown on the shopper's bank statement. We recommend sending a maximum of 22 characters, otherwise banks might truncate the string. Allowed characters: a-z, A-Z, 0-9, spaces, and special characters . , ' _ - ? + * /.

showInstallmentAmountboolean

Set to true to show the payment amount per installment.

showRemovePaymentMethodButtonboolean

Set to true to show a button that lets the shopper remove a stored payment method.

socialSecurityNumberstring

The shopper's social security number.

splitCardFundingSourcesboolean

Boolean value indicating whether the card payment method should be split into separate debit and credit options.

storestring

Required for Adyen for Platforms integrations if you are a platform model. This is your reference (on balance platform) or the storeReference (in the classic integration) for the ecommerce or point-of-sale store that is processing the payment.

storeFiltrationMode'exclusive' | 'inclusive' | 'skipFilter'

Specifies how payment methods should be filtered based on the 'store' parameter:

  • 'exclusive': Only payment methods belonging to the specified 'store' are returned.
  • 'inclusive': Payment methods from the 'store' and those not associated with any other store are returned.
storePaymentMethodboolean

When true and shopperReference is provided, the payment details will be stored for future recurring payments.

storePaymentMethodMode'askForConsent' | 'disabled' | 'enabled'

Indicates if the details of the payment method will be stored for the shopper. Possible values:

  • disabled – No details will be stored (default).
  • askForConsent – If the shopperReference is provided, the Drop-in/Component shows a checkbox where the shopper can select to store their payment details for card payments.
  • enabled – If the shopperReference is provided, the details will be stored without asking the shopper for consent.
telephoneNumberstring

The shopper's telephone number. The phone number must include a plus sign (+) and a country code (1-3 digits), followed by the number (4-15 digits). If the value you provide does not follow the guidelines, we do not submit it for authentication.

Required for Visa and JCB transactions that require 3D Secure 2 authentication, if you did not include the shopperEmail.

themeIdstring

Sets a custom theme for Hosted Checkout. The value can be any of the Theme ID values from your Customer Area.

threeDSAuthenticationOnlyboolean

Required to trigger the authentication-only flow. If set to true, you will only perform the 3D Secure 2 authentication, and will not proceed to the payment authorization.Default: false.

trustedShopperboolean

Set to true if the payment should be routed to a trusted MID.

Response

Created - the request has been fulfilled and has resulted in one or more new resources being created.

additionalDataobject

This field contains additional data, which may be required for a particular payment request.

The additionalData object consists of entries, each of which includes the key and value.

allowedPaymentMethodsstring[]

List of payment methods to be presented to the shopper. To refer to payment methods, use their payment method type.

Example: "allowedPaymentMethods":["ideal","applepay"]

blockedPaymentMethodsstring[]

List of payment methods to be hidden from the shopper. To refer to payment methods, use their payment method type.

Example: "blockedPaymentMethods":["ideal","applepay"]

captureDelayHoursinteger

The delay between the authorisation and scheduled auto-capture, specified in hours.

channel'iOS' | 'Android' | 'Web'

The platform where a payment transaction takes place. This field is optional for filtering out payment methods that are only available on specific platforms. If this value is not set, then we will try to infer it from the sdkVersion or token.

Possible values:

  • iOS
  • Android
  • Web
countryCodestring

The shopper's two-letter country code.

dateOfBirthstring date-time

The shopper's date of birth in ISO8601 format.

deliverAtstring date-time

The date and time when the purchased goods should be delivered.

ISO 8601 format: YYYY-MM-DDThh:mm:ss+TZD, for example, 2020-12-18T10:15:30+01:00.

enableOneClickboolean

When true and shopperReference is provided, the shopper will be asked if the payment details should be stored for future one-click payments.

enablePayOutboolean

When true and shopperReference is provided, the payment details will be tokenized for payouts.

enableRecurringboolean

When true and shopperReference is provided, the payment details will be stored for recurring payments where the shopper is not present, such as subscription or automatic top-up payments.

expiresAtstring date-time required

The date the session expires in ISO8601 format. When not specified, the expiry date is set to 1 hour after session creation. You cannot set the session expiry to more than 24 hours after session creation.

idstring required

A unique identifier of the session.

installmentOptionsobject

A set of key-value pairs that specifies the installment options available per payment method. The key must be a payment method name in lowercase. For example, card to specify installment options for all cards, or visa or mc. The value must be an object containing the installment options.

mccstring

The merchant category code (MCC) is a four-digit number, which relates to a particular market segment. This code reflects the predominant activity that is conducted by the merchant.

merchantAccountstring required

The merchant account identifier, with which you want to process the transaction.

merchantOrderReferencestring

This reference allows linking multiple transactions to each other for reporting purposes (i.e. order auth-rate). The reference should be unique per billing cycle. The same merchant order reference should never be reused after the first authorised attempt. If used, this field should be supplied for all incoming authorisations.

We strongly recommend you send the merchantOrderReference value to benefit from linking payment requests when authorisation retries take place. In addition, we recommend you provide retry.orderAttemptNumber, retry.chainAttemptNumber, and retry.skipRetry values in PaymentRequest.additionalData.

metadataobject

Metadata consists of entries, each of which includes a key and a value. Limits:

  • Maximum 20 key-value pairs per request.
  • Maximum 20 characters per key.
  • Maximum 80 characters per value.
mode'embedded' | 'hosted'

Indicates the type of front end integration. Possible values:

  • embedded (default): Drop-in or Components integration
  • hosted: Hosted Checkout integration
recurringExpirystring

Date after which no further authorisations shall be performed. Only for 3D Secure 2.

recurringFrequencystring

Minimum number of days between authorisations. Only for 3D Secure 2.

recurringProcessingModel'CardOnFile' | 'Subscription' | 'UnscheduledCardOnFile'

Defines a recurring payment type. Required when creating a token to store payment details. Allowed values:

  • Subscription – A transaction for a fixed or variable amount, which follows a fixed schedule.
  • CardOnFile – With a card-on-file (CoF) transaction, card details are stored to enable one-click or omnichannel journeys, or simply to streamline the checkout process. Any subscription not following a fixed schedule is also considered a card-on-file transaction.
  • UnscheduledCardOnFile – An unscheduled card-on-file (UCoF) transaction is a transaction that occurs on a non-fixed schedule and/or have variable amounts. For example, automatic top-ups when a cardholder's balance drops below a certain amount.
redirectFromIssuerMethodstring

Specifies the redirect method (GET or POST) when redirecting back from the issuer.

redirectToIssuerMethodstring

Specifies the redirect method (GET or POST) when redirecting to the issuer.

referencestring required

The reference to uniquely identify a payment.

returnUrlstring required

The URL to return to in case of a redirection. The format depends on the channel.

  • For web, include the protocol http:// or https://. You can also include your own additional query parameters, for example, shopper ID or order reference number. Example: https://your-company.example.com/checkout?shopperOrder=12xy
  • For iOS, use the custom URL for your app. To know more about setting custom URL schemes, refer to the Apple Developer documentation. Example: my-app://
  • For Android, use a custom URL handled by an Activity on your app. You can configure it with an intent filter. Example: my-app://your.package.name

If the URL to return to includes non-ASCII characters, like spaces or special letters, URL encode the value.

We strongly recommend that you use a maximum of 1024 characters.

The URL must not include personally identifiable information (PII), for example name or email address.

sessionDatastring

The payment session data you need to pass to your front end.

shopperEmailstring

The shopper's email address.

shopperIPstring

The shopper's IP address. We recommend that you provide this data, as it is used in a number of risk checks (for instance, number of payment attempts or location-based checks).

Required for Visa and JCB transactions that require 3D Secure 2 authentication for all web and mobile integrations, if you did not include the shopperEmail. For native mobile integrations, the field is required to support cases where authentication is routed to the redirect flow. This field is also mandatory for some merchants depending on your business model. For more information, contact Support.

shopperInteraction'Ecommerce' | 'ContAuth' | 'Moto' | 'POS'

Specifies the sales channel, through which the shopper gives their card details, and whether the shopper is a returning customer. For the web service API, Adyen assumes Ecommerce shopper interaction by default.

This field has the following possible values:

  • Ecommerce - Online transactions where the cardholder is present (online). For better authorisation rates, we recommend sending the card security code (CSC) along with the request.
  • ContAuth - Card on file and/or subscription transactions, where the cardholder is known to the merchant (returning customer). If the shopper is present (online), you can supply also the CSC to improve authorisation (one-click payment).
  • Moto - Mail-order and telephone-order transactions where the shopper is in contact with the merchant via email or telephone.
  • POS - Point-of-sale transactions where the shopper is physically present to make a payment using a secure payment terminal.
shopperLocalestring

The language for the payment. The value combines the two-letter ISO 639-1 language code with the ISO 3166-1 alpha-2 country code. For example, nl-NL.

When using Drop-in/Components, the specified language appears if your front-end global configuration does not set the locale.

shopperReferencestring

Your reference to uniquely identify this shopper, for example user ID or account ID. The value is case-sensitive and must be at least three characters.

Your reference must not include personally identifiable information (PII) such as name or email address.

shopperStatementstring

The text to be shown on the shopper's bank statement. We recommend sending a maximum of 22 characters, otherwise banks might truncate the string. Allowed characters: a-z, A-Z, 0-9, spaces, and special characters . , ' _ - ? + * /.

showInstallmentAmountboolean

Set to true to show the payment amount per installment.

showRemovePaymentMethodButtonboolean

Set to true to show a button that lets the shopper remove a stored payment method.

socialSecurityNumberstring

The shopper's social security number.

splitCardFundingSourcesboolean

Boolean value indicating whether the card payment method should be split into separate debit and credit options.

storestring

Required for Adyen for Platforms integrations if you are a platform model. This is your reference (on balance platform) or the storeReference (in the classic integration) for the ecommerce or point-of-sale store that is processing the payment.

storeFiltrationMode'exclusive' | 'inclusive' | 'skipFilter'

Specifies how payment methods should be filtered based on the 'store' parameter:

  • 'exclusive': Only payment methods belonging to the specified 'store' are returned.
  • 'inclusive': Payment methods from the 'store' and those not associated with any other store are returned.
storePaymentMethodboolean

When true and shopperReference is provided, the payment details will be stored for future recurring payments.

storePaymentMethodMode'askForConsent' | 'disabled' | 'enabled'

Indicates if the details of the payment method will be stored for the shopper. Possible values:

  • disabled – No details will be stored (default).
  • askForConsent – If the shopperReference is provided, the Drop-in/Component shows a checkbox where the shopper can select to store their payment details for card payments.
  • enabled – If the shopperReference is provided, the details will be stored without asking the shopper for consent.
telephoneNumberstring

The shopper's telephone number. The phone number must include a plus sign (+) and a country code (1-3 digits), followed by the number (4-15 digits). If the value you provide does not follow the guidelines, we do not submit it for authentication.

Required for Visa and JCB transactions that require 3D Secure 2 authentication, if you did not include the shopperEmail.

themeIdstring

Sets a custom theme for Hosted Checkout. The value can be any of the Theme ID values from your Customer Area.

threeDSAuthenticationOnlyboolean

Required to trigger the authentication-only flow. If set to true, you will only perform the 3D Secure 2 authentication, and will not proceed to the payment authorization.Default: false.

trustedShopperboolean

Set to true if the payment should be routed to a trusted MID.

urlstring

The URL for the Hosted Checkout page. Redirect the shopper to this URL so they can make the payment.