# Uzum > Uzum is an Uzbekistan-based digital ecosystem headquartered in Tashkent, combining Uzum Market > (the country's largest online marketplace), Uzum Tezkor (rapid delivery), Uzum Bank (a licensed > digital bank) and Uzum Nasiya (consumer installment lending). Its developer surface is published > by Uzum Bank at developer.uzumbank.uz: nine OpenAPI contracts and one JSON-RPC 2.0 > Banking-as-a-Service hub covering card acquiring, QR and cash-register payments, tax receipt > fiscalization, cross-border money transfer, installment origination, in-app merchant billing and > FX rate quoting. Generated by API Evangelist on 2026-09-02 from apis.yml and the artifacts in this repository. Uzum does not publish an llms.txt of its own; https://developer.uzumbank.uz/en/llms.txt returns the docs-site SPA shell (HTTP 200, text/html), not a document. ## What an agent needs to know first - There is NO self-service signup. Every credential on every Uzum API is issued by an Uzum account manager after a commercial agreement, and several products require test results to be confirmed in a Telegram chat before production keys are released. - There are six different authentication models across nine contracts. There is no single partner credential and no OAuth surface. - Uzum Fast Pay and Uzum Dynamic QR return HTTP 200 for FAILURES. The real outcome is the `error_code` field in the body. Branching on HTTP status alone will read a declined payment as a success. - There is no rate limit published, no 429 documented, and no rate-limit response header on any Uzum contract. - There is no Idempotency-Key header. Duplicate suppression works by partner-supplied natural key and REJECTS the duplicate rather than replaying the original result. On a 500 or 504, call the product's status method with the original id — never re-register with a fresh id. - There is no status page. Operational updates are published to a Telegram channel. ## APIs - [Uzum Checkout](https://developer.uzumbank.uz/en/checkout): Card acquiring gateway (Visa, Mastercard, Uzcard, Humo). One-step and two-step payments, back-to-back payment without the hosted form, card binding, full and partial refunds, reversal, auto-fiscalization. PCI DSS. Auth: X-Terminal-Id + X-API-Key. 12 operations. No base URL is published. - [Uzum CrossBorder Transfer](https://developer.uzumbank.uz/en/crossborder): Inbound and outbound international transfer, cross-border service payments, FX rates, transfer registry. Auth: HTTP Basic. Base: https://crossborder.transfer.uz. 20 operations. - [Remit Core](https://developer.uzumbank.uz/en/remitcore): Single integration point for cross-border remittances (CREDIT and DEBIT). Auth: X-Api-Key. Test base: https://remit-core.ipt-merch.com; production is IPSec-only. 9 operations. - [Uzum Nasiya Partner API](https://developer.uzumbank.uz/en/nasiya): BNPL/installment contract origination. Buyer status and limit checks, basket calculation, contract create/confirm/cancel, SMS activation. Auth: Bearer. Base: https://merchants-api.uzumnasiya.uz. 8 operations. - [Uzum Fiscalization](https://developer.uzumbank.uz/en/fiscalization): Submits sale and refund receipts to the Uzbekistan State Tax Committee. Mandatory product labels for regulated goods. Auth: API key. Base: https://ofd-key.inplat-tech.com. 5 operations. - [Uzum Fast Pay](https://developer.uzumbank.uz/en/fastpay): Instant QR and POS/cash-register payments where the seller scans the customer's QR. Auth: time-bound signed Authorization header (expires 50s after signing). Base: https://mobile.apelsin.uz. 4 operations. - [Uzum Dynamic QR](https://developer.uzumbank.uz/en/dynamicqr): QR printed on a POS receipt, scanned by the customer in the Uzum Bank app. Base: https://mobile.apelsin.uz. 5 operations. - [Uzum Merchant API](https://developer.uzumbank.uz/en/merchant): Webhook protocol — Uzum Bank calls five handlers the PARTNER implements (check, create, confirm, reverse, status). Auth: HTTP Basic. OpenAPI 3.1.0 with zero paths; the surface is entirely in the `webhooks` object. - [Uzum RateKeeper](https://developer.uzumbank.uz/en/ratekeeper): FX conversion and partner conversion limits. 2 operations. No base URL and no auth section published. - [Uzum BaaS Payment Hub](https://developer.uzumbank.uz/en/paymenthub/): JSON-RPC 2.0 banking API — account balance/history, card binding, merchant directory, and receipts for card-to-card, card-to-account, account-to-card, account-to-account and online card payments. Auth: HTTP Basic over TLS 1.2. No OpenAPI is published for this surface. - [Uzum Market Seller API](https://seller.uzum.uz/): FBO/FBS order, inventory and price sync for Uzum Market sellers. Credential-gated — api-seller.uzum.uz returns 403 "RBAC: access denied" anonymously and the Swagger UI redirects to Keycloak. No public contract. ## Machine-readable artifacts in this repository - openapi/ — nine OpenAPI contracts saved verbatim from developer.uzumbank.uz - overlays/ — one OpenAPI Overlay 1.0.0 per contract carrying API Evangelist enhancements - authentication/uzum-authentication.yml — the six credential models, and which five contracts document auth in prose without declaring a securityScheme - conventions/uzum-conventions.yml — pagination, versioning, error envelopes, and a reversibility map of every money-moving operation and how to take it back - errors/uzum-problem-types.yml — the four error envelopes and the per-product code registries - errors/uzum-decline-codes.yml — the Uzum Checkout 3xxx card-decline registry - errors/uzum-paymenthub-error-codes.yml — the 22 JSON-RPC error codes - asyncapi/uzum-merchant-webhooks.yml — the five Merchant API webhooks and the payment flow - sandbox/uzum-sandbox.yml — test hosts, published test cards, Postman collections, PDF test cases - conformance/uzum-conformance.yml — PCI DSS and 3-D Secure conformance with spec citations; ISO 20022 absence - data-model/uzum-data-model.yml — the nine disjoint entity models and why no id crosses a product - lifecycle/uzum-lifecycle.yml — per-product versioning, and the absence of a deprecation policy - changelog/uzum-changelog.yml — the one dated breaking change Uzum has published - plans/uzum-plans-pricing.yml — no published pricing; every product is manager-enabled - rate-limits/uzum-rate-limits.yml — no published limits; the ceilings that surface as errors - packages/uzum-packages.yml — no first-party SDK exists, and why @uzum-tech on npm is NOT Uzum - well-known/uzum-well-known.yml — no /.well-known/ document on any of nine hosts - mcp/uzum-mcp.yml — no MCP server exists; a candidate tool surface derived from the contracts - skills/ — packaged Agent Skills for the marquee flows ## Optional - [Uzum corporate site](https://uzum.com/en/) - [Press centre](https://uzum.com/en/press-center/news-and-press-releases/) - [Become an Uzum Bank partner](https://merchants.uzumbank.uz/en/) - [Privacy and terms](https://uzum.com/en/privacy-and-terms/)