Store Payment Option
POST/accounts/:customerAccountId/paymentOptions
This methods allows the storing of card details that have already been authenticated. The returned storedPaymentOptionReference can be used, for example, in /payment/mit endpoint to authorize a merchant initiated payment without the need of additional 3DS challenges or submission of card details.
This endpoint contains PCI data and requires forwarding through /forwarding/tokenize.
Request
Path Parameters
Possible values: <= 255 characters
Customer identifier
john_doe_12345Header Parameters
Must be application/json
Must be be en-US
The origin of the request
The client making the request
- application/json
- Body
- Example (auto)
Bodyrequired
- Array [
- ]
paymentOption objectrequired
Details of the payment option to be stored.
card objectrequired
Card details including 3DS data and card metadata.
3DS object
3D Secure data for the card.
3DS2 object
3DS version 2 specific authentication data.
Electronic Commerce Indicator from ACS (e.g., '02').
Possible values: <= 2 characters
Transaction ID assigned by ACS.
Token issued after successful 3DS authentication.
Possible values: <= 64 characters
Transaction ID from the Directory Server.
3DS protocol version used during authentication.
Possible values: <= 10 characters
2.1.0Possible statuses:
Y = Authenticated,
N = Not Authenticated,
U = Unavailable,
A = Attempted,
R = Rejected.
Possible values: <= 1 characters, [Y, N, U, A, R]
cardDetails objectrequired
Masked card data for the payment method.
Brand of the card (e.g., VISA, MASTERCARD).
Possible values: <= 16 characters
VISAExpiration month of the card in MM format.
Possible values: Value must match regular expression ^(0[1-9]|1[0-2])$
09Expiration year of the card in YYYY format.
Possible values: Value must match regular expression ^20\d{2}$
2029Full name of the cardholder.
Possible values: <= 64 characters
JOHN DOETokenized identifier of the card.
Possible values: <= 32 characters
LLVOXVAJINJWPDDPZAbillingAddress objectrequired
Street name.
Possible values: <= 60 characters
Max-Planck-StraßeApartment, suite, unit, building, floor or other secondary address information.
Possible values: <= 60 characters
Specific delivery instructions, department names, or additional floor information.
Possible values: <= 60 characters
The city or localitly of the address.
Possible values: <= 50 characters
BerlinISO-3 code of the address country (e.g., DEU for Germany).
Possible values: >= 3 characters and <= 3 characters
DEUThe house or building number corresponding to the street address.
Possible values: <= 10 characters
30The postal or ZIP code of the address.
Possible values: <= 10 characters
144733-letter code of the address state. Mandatory when countryCode corresponds to Canada or USA.
Possible values: <= 3 characters
businessConsumer objectnullable
Company data, in case the consumer is a business or a legal entity.
Mandatory, unless consumer is provided.
consumer and businessConsumer objects may not be submitted together.
Name of the legal entity
Possible values: <= 100 characters
Company registration country ISO2 or ISO3 code
Possible values: >= 2 characters and <= 3 characters
Company registration number
Possible values: <= 50 characters
Possible values: <= 100 characters
Consists of ISO 639-1 language code and ISO 3166-1 alpha-2 country code separated by dash. If this value is not provided the browser culture is used. Default culture is English (e.g., en-de). This field is not case sensitive.
Possible values: <= 5 characters
en-ENCustomer email address for any notification
Possible values: <= 255 characters
Person's tax identification number
Possible values: <= 30 characters
consumer objectnullable
Consumer's personal data, in case the consumer is a physical person.
Mandatory, unless businessConsumer is provided.
consumer and businessConsumer objects may not be submitted together.
Consists of ISO 639-1 language code and ISO 3166-1 alpha-2 country code separated by dash. If this value is not provided the browser culture is used. Default culture is English (e.g., en-de). This field is not case sensitive.
Possible values: <= 5 characters
en-ENDate of birth. Format - YYYY-MM-DD. Mandatory for payment option registration flow. Minimum date allowed is 1900-01-01
Possible values: <= 10 characters, Value must match regular expression ^\d{4}-\d{2}-\d{2}$
1989-11-08Customer email address for any notification
Possible values: <= 255 characters
john.doe@gmail.comPerson first name
Possible values: <= 60 characters
JohnPerson gender
Possible values: <= 6 characters
MrPerson's home phone number (including the country code)
Possible values: <= 30 characters
496912345678Person last name
Possible values: <= 60 characters
DoeConsumer/Customer Account Id in the merchant system. When provided into the Create Checkout API, SmartPay will request e-wallet account creation which will have external account reference equals to the given merchantCustomerId value.
Possible values: <= 255 characters
abcd123The customer's middle name
Possible values: <= 60 characters
RobertPerson's mobile phone number (including the country code)
Possible values: <= 30 characters
496912345678Person's tax identification number
Possible values: <= 30 characters
123456789Person title
Possible values: <= 3 characters
MrPerson's work phone number (including the country code)
Possible values: <= 30 characters
496912345678criteria object[]
List of name/value pair custom parameters.
Name of the custom parameter.
Possible values: <= 64 characters
Value of the custom parameter.
Possible values: <= 256 characters
customReferences object
Optional custom reference fields used for merchant tracking.
Possible values: <= 255 characters
Possible values: <= 255 characters
Possible values: <= 255 characters
Unique external identifier of the customer account.
Possible values: <= 255 characters
extraInfo object
Additional grouping metadata.
Possible values: <= 64 characters
Possible values: <= 64 characters
payment objectrequired
Transactional metadata for the registration payment.
Amount for the registration payment (minimum 0.01).
Possible values: >= 0.01
49.99ISO 4217 currency code.
Possible values: Value must match regular expression ^[A-Z]{3}$
EURShort description of the transaction.
Possible values: <= 127 characters
windscreen wipers 4 pcsISO 3166-1 alpha-2 country code of the shop.
Possible values: Value must match regular expression ^[A-Z]{2}$
FR{
"paymentOption": {
"card": {
"3DS": {
"3DS2": {
"acsEci": "string",
"acsTransactionId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"authenticationToken": "string",
"dsTransactionId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"protocolVersion": "2.1.0",
"transactionStatus": "Y"
}
},
"cardDetails": {
"cardBrand": "VISA",
"cardExpiryMonth": "09",
"cardExpiryYear": "2029",
"cardHolder": "JOHN DOE",
"cardToken": "LLVOXVAJINJWPDDPZA"
}
}
},
"billingAddress": {
"addressLine1": "Max-Planck-Straße",
"addressLine2": "string",
"addressLine3": "string",
"city": "Berlin",
"countryCode": "DEU",
"number": 30,
"postCode": 14473,
"state": "string"
},
"businessConsumer": {
"companyName": "string",
"companyRegistrationCountryCode": "string",
"companyRegistrationNumber": "string",
"companyType": "string",
"culture": "en-EN",
"emailAddress": "string",
"taxId": "string"
},
"consumer": {
"culture": "en-EN",
"dateOfBirth": "1989-11-08",
"emailAddress": "john.doe@gmail.com",
"firstName": "John",
"gender": "Mr",
"homePhone": 496912345678,
"lastName": "Doe",
"merchantCustomerId": "abcd123",
"middleName": "Robert",
"mobilePhone": 496912345678,
"taxId": 123456789,
"timezone": "CET",
"title": "Mr",
"workPhone": 496912345678
},
"criteria": [
{
"name": "string",
"value": "string"
}
],
"customReferences": {
"custom1": "string",
"custom2": "string",
"custom3": "string"
},
"customerAccountId": "string",
"extraInfo": {
"customerGroup": "string",
"productGroup": "string"
},
"payment": {
"amount": 49.99,
"currencyCode": "EUR",
"description": "windscreen wipers 4 pcs"
},
"shopCountry": "FR"
}
Responses
- 201
- 400
- 401
- 403
- 404
- 500
Payment option successfully stored
- application/json
- Schema
- Example (auto)
Schema
Unique identifier of the stored payment option.
Possible values: <= 64 characters
Ky28Mgp5GLauHPmYxUnZOcardDetails object
Metadata about the stored card.
Brand of the card.
Possible values: <= 16 characters, [AMEX, BNKACCT, CRTBANCAIR, DISCOVER, GIROPAY, IDEAL, JCB, MSTRCRD, MSTRO, PAYPAL, PAYU, PAYUBLK, PAYUTWST, PAYUINST, PREPMNT, SEPADDB2B, SEPADDCORE, VISA, VISADBIT]
MSTRCRDName of the cardholder.
Possible values: <= 64 characters
JOHN DOETokenized card identifier used for MIT.
Possible values: <= 64 characters
512345PFITLJFS0008Optional CVV token if stored securely.
Possible values: <= 32 characters
WNZSWCUMAAHIDDVUDCExpiration month of the stored card.
Possible values: Value must match regular expression ^(0[1-9]|1[0-2])$
09Expiration year of the stored card.
Possible values: Value must match regular expression ^20\d{2}$
2029{
"storedPaymentOptionReference": "Ky28Mgp5GLauHPmYxUnZO",
"cardDetails": {
"cardBrand": "MSTRCRD",
"cardHolder": "JOHN DOE",
"cardToken": "512345PFITLJFS0008",
"cvvToken": "WNZSWCUMAAHIDDVUDC",
"cardExpiryMonth": "09",
"cardExpiryYear": "2029"
}
}
Bad Request
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "Value out of bounds. Value must be between 1 and 100",
"code": "value_out_of_bounds",
"property": "someField",
"context": {
"minimum": 1,
"maximum": 100
}
}
]
}
Unauthenticated
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "You are not authenticated to perform this request.",
"code": "unauthorized"
}
]
}
Forbidden
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "You do not have permissions to perform this request.",
"code": "forbidden"
}
]
}
Not Found
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "Resource not found.",
"code": "not_found"
}
]
}
Internal Server Error
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "Internal server error."
}
]
}