Payments API

Authentication

TakaPay REST API uses API Key for authentication — no login required. Each store has its own API key that you send with every request.

API Key

Go to Admin → Stores & API, find your store, and copy the API Key. Send it on every request via the X-Api-Key header.

header
X-Api-Key: YOUR_STORE_API_KEY
curl example
curl http://localhost:4000/api/v1/payments \
  -H "X-Api-Key: YOUR_STORE_API_KEY"

Security tips

  • Never expose the API key in frontend JS or mobile apps.
  • Always call from your server backend.
  • Rotate the key anytime from Admin → Stores & API.

Base URL

production
http://localhost:4000/api/v1

All REST endpoints below are relative to this base.

Public endpoints (no key needed)

These are used by the hosted checkout page — your customers open them in the browser.

  • GET /payments/public/:id — load checkout page data
  • POST /payments/public/:id/verify — customer submits TrxID

Inbound SMS webhook (TakaPay Android app)

The TakaPay Android app reads bKash / Nagad / Rocket receipts and forwards them here. Auth uses a separate X-Webhook-Secret header (set in Admin → Settings).

POST/api/webhooks/takapay

payload from app
{
  "app": "TakaPay",
  "provider": "bkash",
  "kind": "received",
  "trxId": "BKH8X2K1M",
  "amount": 1490,
  "counterparty": "01711111111",
  "receivedAt": "2026-08-19T15:00:00.000Z"
}