Skip to main content
The production API base URL is https://payments.boxpressd.com/api/v1. Approved backends authenticate with both Authorization: Bearer <service-client-secret> and X-Boxpressd-Client-Id.

Trusted service endpoints

Merchant routes require merchant_accounts:read or merchant_accounts:write. Responses expose configuration status but never return a gateway secret, encrypted credential, or vault reference.

Hosted-browser endpoints

These routes require the signed, HttpOnly action cookie created when the browser redeems a one-time session: Raw card data is accepted only by POST /api/pci/v1/payment-methods on the Payments origin. Caller backends and parent applications must not proxy or log that payload.

Idempotency

POST /payment-sessions requires Idempotency-Key. The purchase confirmation and server-managed offer creation routes also require it. Use a stable key for one logical attempt, and generate a new key only for new work.

Common errors

Errors use a JSON object with error and message fields.

Verify fulfillment callbacks

Payments signs the exact raw request body with HMAC-SHA256. The signature header uses v1=<hex-digest>.
Read X-Boxpressd-Timestamp and X-Boxpressd-Signature before parsing the body. Reject stale timestamps, verify the signature against the raw bytes, and deduplicate the event id before applying fulfillment. Return a successful status only after the event has been recorded durably.