https://payments.boxpressd.com/api/v1. Approved backends authenticate with both Authorization: Bearer <service-client-secret> and X-Boxpressd-Client-Id.
Trusted service endpoints
Merchant routes require
merchant_accounts:read or merchant_accounts:write. Responses expose configuration status but never return a gateway secret, encrypted credential, or vault reference.
Hosted-browser endpoints
These routes require the signed, HttpOnly action cookie created when the browser redeems a one-time session:
Raw card data is accepted only by
POST /api/pci/v1/payment-methods on the Payments origin. Caller backends and parent applications must not proxy or log that payload.
Idempotency
POST /payment-sessions requires Idempotency-Key. The purchase confirmation and server-managed offer creation routes also require it. Use a stable key for one logical attempt, and generate a new key only for new work.
Common errors
Errors use a JSON object with
error and message fields.
Verify fulfillment callbacks
Payments signs the exact raw request body with HMAC-SHA256. The signature header usesv1=<hex-digest>.
X-Boxpressd-Timestamp and X-Boxpressd-Signature before parsing the body. Reject stale timestamps, verify the signature against the raw bytes, and deduplicate the event id before applying fulfillment. Return a successful status only after the event has been recorded durably.