Make an AKQR merchant account. Registration opens your dashboard, but does not enable payment acceptance.
Merchant registration ↗Build with AKQR Pay securely.
Create PENDING payment requests, inspect order status and display hosted checkout previews. Live money movement, refunds and SUCCESS callbacks are not activated until an authorized provider completes verification.
5-minute quickstart
Dashboard → API credentials. Copy the skp_test_… key once. Store it on your trusted backend.
POST a unique order ID and an INR amount as a string, then GET order status. Repeating the same order ID/amount is idempotent.
Read endpoints ↓GET / POST API Reference
Base URL: https://akqr.in/api/v1. All protected API calls require x-smilepay-key. Cross-origin browser keys are not supported. Use HTTPS from your own backend.
curl --fail-with-body -X POST 'https://akqr.in/api/v1/orders' \
-H 'Content-Type: application/json' \
-H 'x-smilepay-key: YOUR_TEST_KEY' \
--data '{"order_id":"SHOP-10001","amount":"199.00"}'
status: PENDING, provider_ready: false, and an HTTPS checkout preview URL. Do not deliver goods or increase a wallet balance from this response.curl --fail-with-body 'https://akqr.in/api/v1/orders/SHOP-10001' \ -H 'x-smilepay-key: YOUR_TEST_KEY'
Public preview displays amount, merchant branding and current status. It never collects funds without verified provider activation. GET /api/public/checkout/<public_id> is only available on the approved payment host.
GET requests cannot transfer funds, change transaction status or trigger refunds. There is no browser-accessible unencrypted transaction endpoint.
| Endpoint | Method | Auth | Function |
|---|---|---|---|
/health | GET | Public | Gateway health |
/api/login | POST | Public + rate limit | Merchant session |
/api/console/bootstrap | GET | Secure cookie | Account metrics |
/api/console/items | GET / POST | Secure cookie | Draft payment links/pages |
/api/console/receivers | GET / POST | Secure cookie | Receiving account configuration |
/api/console/keys | GET / POST | Secure cookie | Test API key management |
/api/console/callback-reports | GET | Secure cookie | Webhook delivery reports |
/api/v1/orders | POST | Test API key | Create PENDING order |
/api/v1/orders/:orderId | GET | Test API key | Look up order status |
/api/public/checkout/:token | GET | Public payment host | Read preview only |
Webhooks & real-time status
Current capabilities
A merchant can save an HTTPS callback URL, generate a private signing secret, and explicitly send a signed webhook.test event from Dashboard → Integrations. Official Paytm PG initiation and signed transaction-status verification are available to merchants with approved individual MID/Key configuration. Merchant-to-merchant settlement and payouts are not provided. A saved URL alone does not indicate delivery.
When an opted-in merchant creates a test order, the system queues a signed order.pending event and retries failed deliveries up to five attempts. Dashboard → Integrations shows the outbox state. Dashboard → Webhook reports lists actual test delivery attempts. Receiver signature input: X-AKQR-Timestamp + . + raw JSON body, HMAC-SHA256 with your secret; compare against X-AKQR-Signature: sha256=... in constant time. Reject stale timestamps and duplicated event IDs.
Required live webhook design
Before money events can be sent: verify PSP signatures, order ownership, payment reference, amount/currency and replay protection; create durable event records, sign outbound requests, retry safely and reconcile settlements.
// Node.js Express webhook receiver: use RAW body and your stored signing secret.
const crypto = require('node:crypto');
app.post('/webhook/akqr', express.raw({type:'application/json', limit:'8kb'}), (req,res)=>{
const timestamp=String(req.get('X-AKQR-Timestamp')||'');
if(!/^[0-9]{10}$/.test(timestamp)||Math.abs(Date.now()/1000-Number(timestamp))>300)return res.sendStatus(401);
const provided=String(req.get('X-AKQR-Signature')||'').replace(/^sha256=/,'');
if(!/^[a-f0-9]{64}$/.test(provided))return res.sendStatus(401);
const expected=crypto.createHmac('sha256',process.env.AKQR_WEBHOOK_SECRET)
.update(timestamp+'.').update(req.body).digest('hex');
if(!crypto.timingSafeEqual(Buffer.from(provided,'hex'),Buffer.from(expected,'hex')))return res.sendStatus(401);
const event=JSON.parse(req.body.toString('utf8'));
// Persist event.id and reject duplicates before responding 200.
// Do NOT fulfill webhook.test, order.pending or other unverified payment events.
res.sendStatus(200);
});
Demo mode & subscriptions
Demo API
Test credentials are available inside merchant dashboard. Orders and hosted pages are real test records. They do not charge a bank or wallet.
Merchant subscription plans
Starter, Growth and Business account tiers exist in the catalog; billing amounts and activation are not yet configured. ₹199 pricing below is only per integration kit, not the gateway subscription fee.
Ready-made language integration kits
Each programming-language starter contains source code to create a PENDING test order and check its status. The listed price is ₹199 per kit. Source files are prepared privately; purchasing/licensed delivery stays disabled until verified billing is integrated. These are API starter kits, not provider-certified checkout plugins.
Node.js
Ready-made test API integration source for Node.js. Server-side order creation and status lookup.
Source prepared • delivery after verified billingPHP 8+
Ready-made test API integration source for PHP 8+. Server-side order creation and status lookup.
Source prepared • delivery after verified billingPython 3
Ready-made test API integration source for Python 3. Server-side order creation and status lookup.
Source prepared • delivery after verified billingGo
Ready-made test API integration source for Go. Server-side order creation and status lookup.
Source prepared • delivery after verified billingJava 11+
Ready-made test API integration source for Java 11+. Server-side order creation and status lookup.
Source prepared • delivery after verified billingC# / .NET
Ready-made test API integration source for C# / .NET. Server-side order creation and status lookup.
Source prepared • delivery after verified billingRuby
Ready-made test API integration source for Ruby. Server-side order creation and status lookup.
Source prepared • delivery after verified billingBash / cURL
Ready-made test API integration source for Bash / cURL. Server-side order creation and status lookup.
Source prepared • delivery after verified billingNeed WooCommerce, Laravel or other platform-specific commercial payment plugins? Those are separate projects and are not yet built. Do not buy from unofficial links claiming AKQR live payment support.
Security and encryption
Only TLS connections; never transmit API keys, logins or payment details over HTTP.
Test keys are hashed at rest. Keep raw API keys out of frontend JS, mobile APKs, screenshots and source-control.
New customer contact values, merchant receiver identifiers, receipt alerts, signing secrets and test-webhook event bodies use application-layer encryption. Login identifiers and some legacy data remain plaintext; full-database encryption is not claimed.
PENDING, REVIEW or an alert is not SUCCESS. Only independently verified provider callbacks can authorize financial completion.