openapi: 3.2.0
info:
title: FlowPay Checkout API
version: 2.0.0-alpha.4
description:
$ref: docs/general.md
termsOfService: https://developer.flowpay.it/tos
license:
name: FlowPay SRL
url: https://developer.flowpay.it/tos
x-logo:
url: https://images.flowpay.it/logo
altText: FlowPay
contact:
name: API Support
url: https://developer.flowpay.it
email: api-support@flowpay.it
x-json-schema-faker:
locale: it-IT
omitNulls: true
fillProperties: true
reuseProperties: true
servers:
- url: https://api.flowpay.it/v2
description: Production server (Not implementend)
- url: https://mock.flowpay.it/v2
description: Mock server
- url: https://sandbox.{customerID}.flowpay.it/v2
description: Customer-assigned sandbox server
variables:
customerID:
default: 00000000-00000000-00000000-00000000
description: Unique customer identifier assigned after contract signature
- url: http://localhost:5002
description: Debug
tags:
- name: Checkout
description: This endpoint allows managing checkout sessions any document client has access to
paths:
/checkout:
post:
summary: Create checkout
description: 'This endpoint allows to create a new checkout specifying the document to be paid.
If the payment needs to be authorized by the user, the response will contain a link to be used to redirect the user to FlowPay payment page.'
operationId: createCheckout
security:
- oAuth2: []
requestBody:
description: Checkout details
content:
application/json:
schema:
type: object
properties:
kind:
$ref: '#/components/schemas/DocumentKindEnum'
fingerprint:
$ref: '#/components/schemas/Fingerprint'
locked:
type: boolean
default: false
description: If true funds will be directed to FlowPay technical account and will not be available to the beneficiary until the payment is confirmed or revoked via API. See locked payments paragraph for more details.
scaExempt:
type: boolean
default: false
description: If true, the payment will be exempted from SCA. Only some use cases are eligible for SCA exemption, see SCA exemption paragraph for more details. In case of SCA exemption, if a supported payment method is specified, the payment will be instantly processed.
okRedirectUrl:
type: string
format: uri
description: URL to be used to redirect the user to the client application after the payment has been successfully processed. If not specified, the user will be redirected to the default FlowPay payment page.
koRedirectUrl:
type: string
format: uri
description: URL to be used to redirect the user to the client application in case of payment failure. If not specified, the user will be redirected to the default FlowPay payment page.
preferences:
type: object
description: Useful to customize payer user experience on payment page
properties:
paymentMethod:
type: string
format: uuid
description: Payer payment method to be used to pay the document. If not specified, the user will be able to choose the payment method from a list of supported payment methods.
canEditRemittance:
type: boolean
default: true
description: If true, the user will be able to edit the remittance information from the payment page.
allowedMethods:
type: array
items:
type: string
enum:
- sct
- sctInst
- card
- sdd
- wallet
description: List of allowed payment methods. If not specified, all supported payment methods will be allowed.
required:
- kind
- fingerprint
required: true
responses:
'200':
description: Payment processed. This response is returned only if the payment has been processed without requiring user authorization, i.e. in the case of a checkout created with SCA exemption (`scaExempt`) and consistent payment method (`preferences.paymentMethod`)
content:
application/json:
schema:
type: object
properties: {}
'201':
description: Checkout created
content:
application/json:
schema:
$ref: '#/components/schemas/Checkout'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'500':
$ref: '#/components/responses/InternalServerError'
tags:
- Checkout
/checkout/{code}:
get:
summary: Get checkout details
description: Retrieve details of a specific checkout
operationId: getCheckout
security:
- oAuth2:
- checkout:read
parameters:
- name: code
in: path
description: Checkout code
required: true
schema:
type: string
responses:
'200':
description: Checkout details
content:
application/json:
schema:
$ref: '#/components/schemas/Checkout'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
'500':
$ref: '#/components/responses/InternalServerError'
tags:
- Checkout
delete:
summary: Delete checkout
description: 'Allows to delete a checkout.
This endpoint can be used to delete a checkout that has not been paid yet.
If the checkout has been paid, it cannot be deleted and this endpoint will return an error.'
operationId: deleteCheckout
security:
- oAuth2: []
tags:
- Checkout
parameters:
- name: code
in: path
description: Checkout code
required: true
schema:
type: string
responses:
'204':
description: Checkout deleted
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
'500':
$ref: '#/components/responses/InternalServerError'
components:
responses:
InternalServerError:
description: Server encountered an unexpected condition that prevented it from fulfilling the request
content:
application/json:
schema:
type: object
properties:
statusCode:
$ref: '#/components/schemas/StatusCode'
requestID:
$ref: '#/components/schemas/RequestID'
required:
- statusCode
- requestID
NotFound:
description: The requested resource was not found
content:
application/json:
schema:
type: object
properties:
statusCode:
$ref: '#/components/schemas/StatusCode'
requestID:
$ref: '#/components/schemas/RequestID'
message:
type: string
description: Error message
example: Invoice not found
required:
- statusCode
- requestID
- message
Unauthorized:
description: Client has not provided valid credentials to access the requested resource
content:
application/json:
schema:
type: object
properties:
statusCode:
$ref: '#/components/schemas/StatusCode'
requestID:
$ref: '#/components/schemas/RequestID'
message:
type: string
description: Error message
example: You must provide a valid access token
required:
- statusCode
- requestID
- message
BadRequest:
description: Client has provided invalid data
content:
application/json:
schema:
type: object
properties:
statusCode:
$ref: '#/components/schemas/StatusCode'
requestID:
$ref: '#/components/schemas/RequestID'
message:
type: string
description: Error message
example: Proforma invoice can not have a due date later than the invoice date
additionalInfo:
type: object
description: Additional information about the error
properties:
path:
type: string
description: JSON path of the field that caused the error
example: .dueDate
key:
type: string
description: JSON key of the field that caused the error
example: dueDate
type:
type: string
description: Expected type of the field that caused the error
example: string
required:
- path
required:
- statusCode
- requestID
- message
- additionalInfo
Forbidden:
description: Client is not authorized to access the requested resource
content:
application/json:
schema:
type: object
properties:
statusCode:
$ref: '#/components/schemas/StatusCode'
requestID:
$ref: '#/components/schemas/RequestID'
message:
type: string
description: Error message
example: You can't create a new invoice for this tenant
required:
- statusCode
- requestID
- message
schemas:
CollectionMethodEnum:
type: string
enum:
- sct
- sct-inst
- sdd
- card
- custom/