# Kueski > Kueski is a Mexican fintech (founded 2012, Guadalajara) offering online consumer credit. Its > flagship product, Kueski Pay, is a buy-now-pay-later payment method that lets shoppers buy without > a credit card and repay in biweekly installments at thousands of Mexican merchants. Kueski operates > as a SOFOM E.N.R. registered with CONDUSEF. Generated by API Evangelist. Kueski publishes no llms.txt of its own — /llms.txt returns 404 on every Kueski host (verified 2026-08-04). This file is an independent, third-party summary assembled from Kueski's public surface; it is not served by Kueski. ## What Kueski Pay is, for an integrator Kueski Pay is a redirect-model BNPL payment method, not a card gateway. A merchant displays an installment-messaging widget on product and cart pages, creates a Kueski Pay order server-side, then redirects the shopper to a Kueski-hosted checkout where the shopper authenticates, is underwritten in real time, and selects a repayment plan. The merchant never handles shopper credit data. Distribution is by storefront-platform plugin (WooCommerce, Shopify, VTEX IO, Magento, PrestaShop, Tiendanube, T1 Paginas) plus a browser widget bundle. There is no server-side SDK in any language and no published API specification. ## APIs - [Kueski Pay Widget Configuration API](https://www.kueskipay.com/guias-de-integracion): Serves merchant configuration and installment-messaging data to the browser widgets. Base URL `https://api.kueskipay.com` (sandbox `https://testing.kueskipay.com`). Observed operation: `GET /v1/configurations?widget_type=product_widget`. - [Kueski Pay Merchant Orders API](https://github.com/kueski-dev/Dev-Center/wiki/WooCommerce): Merchant-facing order lifecycle. Base URL `https://woocommerce-middleware-go.production-pay.kueski.com/api/v1` (sandbox `https://woocommerce-middleware-go.staging-pay.kueski.codes/api/v1`). Operations observed in Kueski's own first-party plugin: `GET /api/v1/merchant/validate-keys`, `POST /api/v1/order/create`, `POST /api/v1/orders-sync`, `POST /api/v1/order/refund`. ## Authentication Opaque merchant API keys presented as HTTP bearer tokens: `Authorization: Bearer {key}`. Merchants receive a public key (browser-safe, drives the widgets) and a secret key (server-side, drives orders and refunds). Keys are issued by Kueski after merchant onboarding — there is no self-service key generation and no OAuth, OIDC or scope surface. Exception: `merchant/validate-keys` takes the key as an `?api_key=` query parameter rather than a header. ## Conventions an agent needs to know - Errors use a proprietary envelope, not RFC 9457: `{"status":"fail","code":"...","message":"..."}`. - Authentication failures return **HTTP 400**, not 401, and send no `WWW-Authenticate` header. Do not branch on status code alone — read `code`. - **No idempotency key.** `order/create` and `order/refund` are money-moving POSTs with no replay protection. A retry after a timeout can duplicate an order or a refund. - **No webhooks.** Order state is retrieved by polling `POST /api/v1/orders-sync` with a batch of payment ids. - **No rate-limit headers** are returned and no rate-limit policy is published. - A `request-id` response header is emitted by the Istio/Envoy edge on every response, including errors — use it for correlation. - Version is `v1` in the URI path. No versioning or deprecation policy is published. ## Docs - [Integration guides](https://www.kueskipay.com/guias-de-integracion) - [Dev Center wiki](https://github.com/kueski-dev/Dev-Center/wiki) - [For merchants](https://www.kueskipay.com/para-comercios) - [Merchant registration](https://www.kueskipay.com/registro-comercios) - [Merchant portal](https://negocios.kueski.com/login) - [Status page](https://status.kueski.com/) - [Help center](https://preguntas.frecuentes.kueski.com/hc/es/categories/14632860970907-Kueski-Pay) - [Terms of service](https://www.kueskipay.com/tyc) ## Packages - [KueskiPay Gateway for WooCommerce](https://wordpress.org/plugins/kueskipay-gateway/) — first-party, GPL-2.0, v2.4.1. The most complete public expression of the merchant API contract. - [Kueski Pay widgets](https://cdn.kueskipay.com/widgets.js) — browser bundle registering the `` and `` custom elements. Unversioned, no SRI hash. - [Kueski Pay for VTEX IO](https://apps.vtex.com/kueskiio-script-pixel/p) ## API Evangelist artifacts in this repository - authentication/kueski-authentication.yml — the bearer-key auth profile - conventions/kueski-conventions.yml — versioning, tracing, error envelope, polling model - errors/kueski-problem-types.yml — observed error catalog - sandbox/kueski-sandbox.yml — test vs live environments - lifecycle/kueski-lifecycle.yml — status page, versioning and deprecation posture - changelog/kueski-changelog.yml — first-party plugin release stream - packages/kueski-packages.yml — distributable first-party artifacts - components/kueski-components.yml — widgets, modal and hosted checkout - conformance/kueski-conformance.yml — standards and regulatory posture - security/kueski-domain-security.yml — TLS/HSTS/DNSSEC/CAA/SPF/DMARC probe - well-known/kueski-well-known.yml — /.well-known/ probe results (all 404) ## What Kueski does not publish No OpenAPI, AsyncAPI, JSON Schema or GraphQL contract. No `/.well-known/` documents of any kind — no security.txt, no api-catalog, no OAuth/OIDC metadata, no A2A agent card. No MCP server. No llms.txt. No API changelog, versioning policy, deprecation policy, SLA or rate-limit documentation. No error or decline-code reference. No vulnerability disclosure programme or trust center. No self-service sandbox — test credentials require a commercial merchant relationship.