Get a hosted checkout
Returns a checkout and its payment attempts, with payer numbers masked. Another business’s checkout is 404. Requires the collections.read permission.
/v1/checkouts/{checkoutId}AuthorizationBearer token (JWT) · headerrequiredA token from POST /v1/oauth/token on the iSmartPay identity service, obtained with an API credential's client id and secret.
checkoutIdstringrequiredThe checkout's id.
The checkout.
idstring<uuid>requiredreferencestringrequiredamountstring | nullrequiredcurrencystringrequireddescriptionstringenvironmentstringrequiredtestlivestatusstringrequiredReusable checkouts stay open after settlement and never have paid status.
openpaidexpiredcancelledurlstring<uri>requiredContains the public bearer token for this checkout.
successUrlstring<uri>cancelUrlstring<uri>expiresAtstring<date-time> | nullrequiredpaidAtstring<date-time> | nullrequiredcollectionReferencestring | nullrequiredattemptsCheckoutAttempt[]Present only on the single-checkout read.
Show propertiesHide properties
CheckoutAttemptcollectionReferencestringrequiredproviderstringrequiredpayerstringrequiredMasked phone number.
statusstringrequiredpendingsucceededfailedfailureReasonstringcreatedAtstring<date-time>requiredamountstringrequiredcreatedAtstring<date-time>requiredamountTypestringrequiredfixedopenminAmountstring | nullrequiredmaxAmountstring | nullrequiredsuggestedAmountsstring[]requiredusagestringrequiredsinglereusablepaymentsCountintegerrequiredtotalCollectedstringrequiredSettled payments only.
The request is not valid. message says which field.
errorobjectrequiredShow propertiesHide properties
codestringrequiredA stable, machine-readable code. Branch on this, not on the message. Codes include invalid_input, unauthenticated, forbidden, environment_mismatch, not_found, rate_limited, idempotency_key_reused, request_in_flight, limits_missing, limits_unusable, tier_ineligible, transaction_limit_exceeded, daily_limit_exceeded, monthly_limit_exceeded, business_suspended, business_deactivated, environment_unknown, duplicate_reference, provider_error, provider_timeout, destination_not_verified, destination_verification_unavailable, upstream_timeout and internal.
messagestringrequiredReadable detail for a person. For any 5xx it is always the fixed text internal server error.
The token is missing, expired or not valid. Get a new one from the token endpoint.
errorobjectrequiredShow propertiesHide properties
codestringrequiredA stable, machine-readable code. Branch on this, not on the message. Codes include invalid_input, unauthenticated, forbidden, environment_mismatch, not_found, rate_limited, idempotency_key_reused, request_in_flight, limits_missing, limits_unusable, tier_ineligible, transaction_limit_exceeded, daily_limit_exceeded, monthly_limit_exceeded, business_suspended, business_deactivated, environment_unknown, duplicate_reference, provider_error, provider_timeout, destination_not_verified, destination_verification_unavailable, upstream_timeout and internal.
messagestringrequiredReadable detail for a person. For any 5xx it is always the fixed text internal server error.
The request was understood and refused. Common causes: the token is not an API credential's (forbidden); the credential is for the other environment (environment_mismatch); it does not have the permission this operation needs (forbidden); a limit was reached (limits_missing, limits_unusable, tier_ineligible, transaction_limit_exceeded, daily_limit_exceeded, monthly_limit_exceeded); or iSmartPay has suspended or deactivated the business (business_suspended, business_deactivated). A suspended business's API credentials stop exchanging for tokens, so a request made with a token issued just before the suspension is refused with business_suspended.
errorobjectrequiredShow propertiesHide properties
codestringrequiredA stable, machine-readable code. Branch on this, not on the message. Codes include invalid_input, unauthenticated, forbidden, environment_mismatch, not_found, rate_limited, idempotency_key_reused, request_in_flight, limits_missing, limits_unusable, tier_ineligible, transaction_limit_exceeded, daily_limit_exceeded, monthly_limit_exceeded, business_suspended, business_deactivated, environment_unknown, duplicate_reference, provider_error, provider_timeout, destination_not_verified, destination_verification_unavailable, upstream_timeout and internal.
messagestringrequiredReadable detail for a person. For any 5xx it is always the fixed text internal server error.
Nothing was found with that reference or number. For utilities, product_not_found means no product has that productId.
errorobjectrequiredShow propertiesHide properties
codestringrequiredA stable, machine-readable code. Branch on this, not on the message. Codes include invalid_input, unauthenticated, forbidden, environment_mismatch, not_found, rate_limited, idempotency_key_reused, request_in_flight, limits_missing, limits_unusable, tier_ineligible, transaction_limit_exceeded, daily_limit_exceeded, monthly_limit_exceeded, business_suspended, business_deactivated, environment_unknown, duplicate_reference, provider_error, provider_timeout, destination_not_verified, destination_verification_unavailable, upstream_timeout and internal.
messagestringrequiredReadable detail for a person. For any 5xx it is always the fixed text internal server error.
Too many requests for this credential. Wait the number of seconds in the Retry-After header, then try again.
errorobjectrequiredShow propertiesHide properties
codestringrequiredA stable, machine-readable code. Branch on this, not on the message. Codes include invalid_input, unauthenticated, forbidden, environment_mismatch, not_found, rate_limited, idempotency_key_reused, request_in_flight, limits_missing, limits_unusable, tier_ineligible, transaction_limit_exceeded, daily_limit_exceeded, monthly_limit_exceeded, business_suspended, business_deactivated, environment_unknown, duplicate_reference, provider_error, provider_timeout, destination_not_verified, destination_verification_unavailable, upstream_timeout and internal.
messagestringrequiredReadable detail for a person. For any 5xx it is always the fixed text internal server error.
Something failed on our side. The message is fixed. If the request was a POST, retry with the same Idempotency-Key and body.
errorobjectrequiredShow propertiesHide properties
codestringrequiredA stable, machine-readable code. Branch on this, not on the message. Codes include invalid_input, unauthenticated, forbidden, environment_mismatch, not_found, rate_limited, idempotency_key_reused, request_in_flight, limits_missing, limits_unusable, tier_ineligible, transaction_limit_exceeded, daily_limit_exceeded, monthly_limit_exceeded, business_suspended, business_deactivated, environment_unknown, duplicate_reference, provider_error, provider_timeout, destination_not_verified, destination_verification_unavailable, upstream_timeout and internal.
messagestringrequiredReadable detail for a person. For any 5xx it is always the fixed text internal server error.
A service behind the API did not answer usably. If the request was a POST, retry with the same Idempotency-Key and body. A party lookup the provider rejects is provider_error.
errorobjectrequiredShow propertiesHide properties
codestringrequiredA stable, machine-readable code. Branch on this, not on the message. Codes include invalid_input, unauthenticated, forbidden, environment_mismatch, not_found, rate_limited, idempotency_key_reused, request_in_flight, limits_missing, limits_unusable, tier_ineligible, transaction_limit_exceeded, daily_limit_exceeded, monthly_limit_exceeded, business_suspended, business_deactivated, environment_unknown, duplicate_reference, provider_error, provider_timeout, destination_not_verified, destination_verification_unavailable, upstream_timeout and internal.
messagestringrequiredReadable detail for a person. For any 5xx it is always the fixed text internal server error.
The API is temporarily unable to tell which environment it serves (environment_unknown), utility purchases are not available right now (utilities_unavailable), a settlement destination could not be name-checked just now (destination_verification_unavailable; retry the same request), or hosted checkout is not set up on this deployment (checkout_unavailable). Retry shortly, except for checkout_unavailable, which lasts until the deployment is configured.
errorobjectrequiredShow propertiesHide properties
codestringrequiredA stable, machine-readable code. Branch on this, not on the message. Codes include invalid_input, unauthenticated, forbidden, environment_mismatch, not_found, rate_limited, idempotency_key_reused, request_in_flight, limits_missing, limits_unusable, tier_ineligible, transaction_limit_exceeded, daily_limit_exceeded, monthly_limit_exceeded, business_suspended, business_deactivated, environment_unknown, duplicate_reference, provider_error, provider_timeout, destination_not_verified, destination_verification_unavailable, upstream_timeout and internal.
messagestringrequiredReadable detail for a person. For any 5xx it is always the fixed text internal server error.
The request took too long. If it was a POST, its outcome is unknown: retry with the same Idempotency-Key and body, or read it back by reference. A party lookup the provider does not answer is provider_timeout: check again before relying on it.
errorobjectrequiredShow propertiesHide properties
codestringrequiredA stable, machine-readable code. Branch on this, not on the message. Codes include invalid_input, unauthenticated, forbidden, environment_mismatch, not_found, rate_limited, idempotency_key_reused, request_in_flight, limits_missing, limits_unusable, tier_ineligible, transaction_limit_exceeded, daily_limit_exceeded, monthly_limit_exceeded, business_suspended, business_deactivated, environment_unknown, duplicate_reference, provider_error, provider_timeout, destination_not_verified, destination_verification_unavailable, upstream_timeout and internal.
messagestringrequiredReadable detail for a person. For any 5xx it is always the fixed text internal server error.