1. 3D Secure Payment
Sipay API Documentation
EN
  • EN
  • TR
  • Overview
    • Getting Started
    • Test Cards
  • Authentication
    • Token Generation
      POST
  • Installments & Commission
    • Installment Details
      POST
    • Merchant Installments
      POST
    • Commission
      POST
  • HASH
    • Hash Creation
    • Hash Validation
  • Non-Secure Payment
    • Non-Secure Payment Flow
    • Non-Secure Card Payment
      POST
    • Non-Secure Recurring Payment
      POST
    • Non-Secure Insurance Payment
      POST
    • Non-Secure Pre-Authorization Payment
      POST
    • Confirm Payment
      POST
  • 3D Secure Payment
    • 3D Secure Payment Flow
    • 3D Secure Card Payment
      POST
    • 3D Secure Recurring Payment
      POST
    • 3D Secure Pre-Authorization Payment
      POST
    • Complete Payment
      POST
    • Confirm Payment
      POST
    • 3D Secure Agriculture Payment
      POST
  • Non-Secure and 3D Payment with Sipay
    • Purchase Link Example
    • Non-Secure and 3D Secure Payment with Sipay
      POST
  • Check Status
    • Check Status
  • Payment with Saved Card
    • Card Registration
    • 3D Secure Pay by Card Token
    • Non-Secure Pay by Card Token
    • Retrieving Saved Card
    • Edit Saved Card
    • Delete Saved Card
  • Recurring
    • Recurring Query Search
    • Recurring Plan Process
    • Recurring Plan Update
  • Refund
    • Refund
  • Cashout
    • Cashout to Bank
  • Webhook
    • Webhook
  • Status Codes
    • Status Codes
  1. 3D Secure Payment

3D Secure Card Payment

Testing
Testing Env
https://provisioning.sipay.com.tr
Testing Env
https://provisioning.sipay.com.tr
POST
/ccpayment/api/paySmart3D
The paySmart3D API is used to send order and credit card details to the Sipay payment integration system.
After submitting the payment form (HTML) on the merchant website, the user is redirected to the bank's 3D Secure page, where the payment is verified using an SMS code. Upon successful payment, the user is redirected to the success URL specified by the merchant. If the payment is unsuccessful or cancelled, the user is redirected to the cancellation URL specified by the merchant.
Unlike other payment APIs, the paySmart3D API does not require a getpos API call.

Please do not send an AJAX request to the paySmart3D API.
The /api/paySmart3D endpoint must be accessed via an HTML form submission.

Response Details:#

payment_status == 0 means that operation failed.
payment_status == 1 and transaction_type == “Pre-Authorization” means that the transaction is successful and the transaction amount is blocked from the credit card.
In order to withdraw the blocked amount from the card,
Complete Payment Endpoint and Confirm Payment Endpoint must be called.
payment_status == 1 and transaction_type == “Auth” means that the transaction is successful and the transaction amount is immediately deducted from the card.

The hash key must be sent in the request.
Sample hash keys can be found in the request form panel on the side, corresponding to the selected programming language.

Request

Authorization
Provide your bearer token in the
Authorization
header when making requests to protected resources.
Example:
Authorization: Bearer ********************
Body Params application/jsonRequired

Examples

Responses

🟢200Success
application/json
Bodyapplication/json

🟠404Failed
🟢200HTML Form
Request Request Example
Shell
JavaScript
Java
Swift
HASH
generate_hash_key() {
  local total="$1"
  local installment="$2"
  local currency_code="$3"
  local merchant_key="$4"
  local invoice_id="$5"
  local app_secret="$6"

  local data="${total}|${installment}|${currency_code}|${merchant_key}|${invoice_id}"

  local rand1
  rand1=$(openssl rand -hex 16)
  local iv
  iv=$(printf "%s" "$rand1" | openssl sha1 | awk '{print $2}' | cut -c1-16)

  local password
  password=$(printf "%s" "$app_secret" | openssl sha1 | awk '{print $2}')

  local rand2
  rand2=$(openssl rand -hex 16)
  local salt
  salt=$(printf "%s" "$rand2" | openssl sha1 | awk '{print $2}' | cut -c1-4)

  local salt_with_password
  salt_with_password=$(printf "%s" "${password}${salt}" | openssl sha256 | awk '{print $2}' | cut -c1-32)

  local key_hex
  key_hex=$(printf "%s" "$salt_with_password" | xxd -p -c 256)

  local iv_hex
  iv_hex=$(printf "%s" "$iv" | xxd -p -c 256)

  local encrypted_base64
  encrypted_base64=$(printf "%s" "$data" | openssl enc -aes-256-cbc -K "$key_hex" -iv "$iv_hex" -base64)

  local msg_encrypted_bundle="${iv}:${salt}:${encrypted_base64}"
  msg_encrypted_bundle="${msg_encrypted_bundle//\//__}"

  echo "$msg_encrypted_bundle"
}

total="100"
installment="1"
currency_code="TRY"
merchant_key="merchant_key"
invoice_id="invoice_id"
app_secret="app_secret"

result=$(generate_hash_key "$total" "$installment" "$currency_code" "$merchant_key" "$invoice_id" "$app_secret")
echo "$result"
Response Response Example
200 - Success
{
	"sipay_status": "1",
	"order_no": "VP17749690188158024",
	"order_id": "VP17749690188158024",
	"invoice_id": "7PAXU5D2IMBQ3KD-1774969017",
	"status_code": "100",
	"status_description": "Payment Successfully Completed",
	"sipay_payment_method": "1",
	"credit_card_no": "450803****4509",
	"transaction_type": "Auth",
	"payment_status": "1",
	"payment_method": "1",
	"error_code": "100",
	"error": "Payment Successfully Completed",
	"auth_code": "P54802",
	"merchant_commission": "0.1",
	"user_commission": "0",
	"merchant_commission_percentage": "1",
	"merchant_commission_fixed": "0",
	"installment": "1",
	"amount": "5",
	"payment_reason_code": null,
	"payment_reason_code_detail": null,
	"hash_key": "7fa34583e3b2dd60:32f6:6sEV__qFOEiSvNHEVXCW4EJaJvD+dzeQzqoKiQG0kEDADdcGcrniJFJh5jdM+r2aBAMkOn71VUffdxEZ9BaEpUg==",
	"md_status": "1",
	"original_bank_error_code": null,
	"original_bank_error_description": null,
	"host_reference_id": "609000105269"
}
Previous
3D Secure Payment Flow
Next
3D Secure Recurring Payment
Built with