> ## Documentation Index
> Fetch the complete documentation index at: https://docs.boxpressd.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Boxpressd Payments

> Add hosted checkout, saved-card management, merchant-routed charges, and AI credit purchases.

Boxpressd Payments is the hosted checkout and payment orchestration service for Boxpressd products and marketplace venues. A trusted backend creates a short-lived session, and the browser opens the returned hosted URL as a page, modal, or mobile sheet.

| Environment | Origin |
| - | - |
| Production | `https://payments.boxpressd.com` |
| Development | `https://payments-dev.boxpressd.com` |

<CardGroup cols={2}>
  <Card title="Create a session" icon="play" href="/payments/quickstart">
    Start a hosted checkout from a trusted backend.
  </Card>

  <Card title="Hosted checkout" icon="credit-card" href="/payments/hosted-checkout">
    Choose purchase, card management, credit, or subscription actions.
  </Card>

  <Card title="Embed the flow" icon="window" href="/payments/embed-sdk">
    Open the server-created URL in the browser SDK.
  </Card>

  <Card title="AI credits" icon="coins" href="/payments/ai-credits">
    Discover offers and purchase credits for a billing account.
  </Card>
</CardGroup>

## Who can integrate

Payments APIs use service-client credentials provisioned for approved Boxpressd backends. A Boxpressd developer API key does not authenticate directly to Payments.

Each service client has exact allowlists for actions, permissions, billing resource types, origins, and return URLs. Keep its secret in the calling backend’s secret store.

## Funds flow

Marketplace charges use direct merchant orchestration:

1. A trusted backend creates a hosted session.
2. The card is submitted only to the Payments origin and tokenized in the card-data environment.
3. Payments selects the merchant account and gateway on the server.
4. NMI or Authorize.Net processes the charge under the merchant’s account.
5. The gateway and acquirer settle directly to the merchant.
6. A durable outbox delivers the signed result or grants the purchased Boxpressd entitlement and credits exactly once.

Boxpressd Payments does not hold a marketplace balance or run merchant payouts in this flow.

## Browser boundary

The caller’s browser receives only a one-time hosted URL and masked payment-method data. The browser never receives the service-client secret, gateway credentials, a vault reference, or server-owned prices.
