AKQR PayDeveloper Center
API DOCUMENTATION • TEST MODE

Build with AKQR Pay securely.

Create PENDING payment requests, inspect order status and display hosted checkout previews. Live money movement, refunds and SUCCESS callbacks are not activated until an authorized provider completes verification.

🔒 HTTPS-only🧪 Test API keys🧾 Database-backed PENDING orders🔌 8 code kits
Checking API documentation status…
01

5-minute quickstart

1. Register

Make an AKQR merchant account. Registration opens your dashboard, but does not enable payment acceptance.

Merchant registration ↗
2. Create test key

Dashboard → API credentials. Copy the skp_test_… key once. Store it on your trusted backend.

API credentials ↗
3. Make a request

POST a unique order ID and an INR amount as a string, then GET order status. Repeating the same order ID/amount is idempotent.

Read endpoints ↓
02

GET / POST API Reference

Base URL: https://akqr.in/api/v1. All protected API calls require x-smilepay-key. Cross-origin browser keys are not supported. Use HTTPS from your own backend.

POST/api/v1/ordersCreate or reuse a test order
Example request
curl --fail-with-body -X POST 'https://akqr.in/api/v1/orders' \
  -H 'Content-Type: application/json' \
  -H 'x-smilepay-key: YOUR_TEST_KEY' \
  --data '{"order_id":"SHOP-10001","amount":"199.00"}'
Order response is NOT money received. The API returns status: PENDING, provider_ready: false, and an HTTPS checkout preview URL. Do not deliver goods or increase a wallet balance from this response.
GET/api/v1/orders/:orderIdRead your authenticated order
Status lookup request
curl --fail-with-body 'https://akqr.in/api/v1/orders/SHOP-10001' \
  -H 'x-smilepay-key: YOUR_TEST_KEY'
GEThttps://pay.akqr.in/<public_id>Hosted checkout preview, no authentication required

Public preview displays amount, merchant branding and current status. It never collects funds without verified provider activation. GET /api/public/checkout/<public_id> is only available on the approved payment host.

POST/api/checkout/startCurrently disabled (HTTP 503)

GET requests cannot transfer funds, change transaction status or trigger refunds. There is no browser-accessible unencrypted transaction endpoint.

EndpointMethodAuthFunction
/healthGETPublicGateway health
/api/loginPOSTPublic + rate limitMerchant session
/api/console/bootstrapGETSecure cookieAccount metrics
/api/console/itemsGET / POSTSecure cookieDraft payment links/pages
/api/console/receiversGET / POSTSecure cookieReceiving account configuration
/api/console/keysGET / POSTSecure cookieTest API key management
/api/console/callback-reportsGETSecure cookieWebhook delivery reports
/api/v1/ordersPOSTTest API keyCreate PENDING order
/api/v1/orders/:orderIdGETTest API keyLook up order status
/api/public/checkout/:tokenGETPublic payment hostRead preview only
03

Webhooks & real-time status

Current capabilities

A merchant can save an HTTPS callback URL, generate a private signing secret, and explicitly send a signed webhook.test event from Dashboard → Integrations. Official Paytm PG initiation and signed transaction-status verification are available to merchants with approved individual MID/Key configuration. Merchant-to-merchant settlement and payouts are not provided. A saved URL alone does not indicate delivery.

When an opted-in merchant creates a test order, the system queues a signed order.pending event and retries failed deliveries up to five attempts. Dashboard → Integrations shows the outbox state. Dashboard → Webhook reports lists actual test delivery attempts. Receiver signature input: X-AKQR-Timestamp + . + raw JSON body, HMAC-SHA256 with your secret; compare against X-AKQR-Signature: sha256=... in constant time. Reject stale timestamps and duplicated event IDs.

Required live webhook design

Before money events can be sent: verify PSP signatures, order ownership, payment reference, amount/currency and replay protection; create durable event records, sign outbound requests, retry safely and reconcile settlements.

Verify signed test webhooks (Node.js example)
// Node.js Express webhook receiver: use RAW body and your stored signing secret.
const crypto = require('node:crypto');
app.post('/webhook/akqr', express.raw({type:'application/json', limit:'8kb'}), (req,res)=>{
  const timestamp=String(req.get('X-AKQR-Timestamp')||'');
  if(!/^[0-9]{10}$/.test(timestamp)||Math.abs(Date.now()/1000-Number(timestamp))>300)return res.sendStatus(401);
  const provided=String(req.get('X-AKQR-Signature')||'').replace(/^sha256=/,'');
  if(!/^[a-f0-9]{64}$/.test(provided))return res.sendStatus(401);
  const expected=crypto.createHmac('sha256',process.env.AKQR_WEBHOOK_SECRET)
    .update(timestamp+'.').update(req.body).digest('hex');
  if(!crypto.timingSafeEqual(Buffer.from(provided,'hex'),Buffer.from(expected,'hex')))return res.sendStatus(401);
  const event=JSON.parse(req.body.toString('utf8'));
  // Persist event.id and reject duplicates before responding 200.
  // Do NOT fulfill webhook.test, order.pending or other unverified payment events.
  res.sendStatus(200);
});
Never mark an order paid because a browser redirected, a notification was read, or an unsigned webhook claimed SUCCESS. Until provider activation, no payment-success payload is authentic.
04

Demo mode & subscriptions

Demo API

Test credentials are available inside merchant dashboard. Orders and hosted pages are real test records. They do not charge a bank or wallet.

Merchant subscription plans

Starter, Growth and Business account tiers exist in the catalog; billing amounts and activation are not yet configured. ₹199 pricing below is only per integration kit, not the gateway subscription fee.

05

Ready-made language integration kits

Each programming-language starter contains source code to create a PENDING test order and check its status. The listed price is ₹199 per kit. Source files are prepared privately; purchasing/licensed delivery stays disabled until verified billing is integrated. These are API starter kits, not provider-certified checkout plugins.

JavaScript₹199

Node.js

Ready-made test API integration source for Node.js. Server-side order creation and status lookup.

POST ordersGET statusTest mode
Source prepared • delivery after verified billing
PHP₹199

PHP 8+

Ready-made test API integration source for PHP 8+. Server-side order creation and status lookup.

POST ordersGET statusTest mode
Source prepared • delivery after verified billing
Python₹199

Python 3

Ready-made test API integration source for Python 3. Server-side order creation and status lookup.

POST ordersGET statusTest mode
Source prepared • delivery after verified billing
Go₹199

Go

Ready-made test API integration source for Go. Server-side order creation and status lookup.

POST ordersGET statusTest mode
Source prepared • delivery after verified billing
Java₹199

Java 11+

Ready-made test API integration source for Java 11+. Server-side order creation and status lookup.

POST ordersGET statusTest mode
Source prepared • delivery after verified billing
C#₹199

C# / .NET

Ready-made test API integration source for C# / .NET. Server-side order creation and status lookup.

POST ordersGET statusTest mode
Source prepared • delivery after verified billing
Ruby₹199

Ruby

Ready-made test API integration source for Ruby. Server-side order creation and status lookup.

POST ordersGET statusTest mode
Source prepared • delivery after verified billing
Shell₹199

Bash / cURL

Ready-made test API integration source for Bash / cURL. Server-side order creation and status lookup.

POST ordersGET statusTest mode
Source prepared • delivery after verified billing

Need WooCommerce, Laravel or other platform-specific commercial payment plugins? Those are separate projects and are not yet built. Do not buy from unofficial links claiming AKQR live payment support.

06

Security and encryption

🔐 HTTPS transport

Only TLS connections; never transmit API keys, logins or payment details over HTTP.

🗝 Key storage

Test keys are hashed at rest. Keep raw API keys out of frontend JS, mobile APKs, screenshots and source-control.

🧰 Sensitive records

New customer contact values, merchant receiver identifiers, receipt alerts, signing secrets and test-webhook event bodies use application-layer encryption. Login identifiers and some legacy data remain plaintext; full-database encryption is not claimed.

💳 Safe status rules

PENDING, REVIEW or an alert is not SUCCESS. Only independently verified provider callbacks can authorize financial completion.