Prerequisites
- An approved Payments service client ID and secret
- A billing account your client is allowed to access
- A ready merchant account for the current environment
- Registered return and cancel URLs
1
Store the service credential
Keep both values in your backend environment:Never expose the secret through browser or native application code.
2
Create a hosted session
Call Payments from your backend. Supply a stable idempotency key for the checkout attempt.
3
Use the first returned URL
Redirect the browser to
data.url or open it with the embed SDK.Persist the session ID before redirecting. An idempotency replay returns the existing session with url: null because Payments cannot reproduce the raw one-time token.4
Verify authoritative status
After the user returns, query the session from your backend: