Payments API
Authentication
TakaPay REST API uses API Key for authentication — no login required. Each store has its own API key that you send with every request.
API Key
Go to Admin → Stores & API, find your store, and copy the API Key. Send it on every request via the X-Api-Key header.
header
X-Api-Key: YOUR_STORE_API_KEYcurl example
curl http://localhost:4000/api/v1/payments \
-H "X-Api-Key: YOUR_STORE_API_KEY"Security tips
- Never expose the API key in frontend JS or mobile apps.
- Always call from your server backend.
- Rotate the key anytime from Admin → Stores & API.
Base URL
production
http://localhost:4000/api/v1All REST endpoints below are relative to this base.
Public endpoints (no key needed)
These are used by the hosted checkout page — your customers open them in the browser.
GET /payments/public/:id— load checkout page dataPOST /payments/public/:id/verify— customer submits TrxID
Inbound SMS webhook (TakaPay Android app)
The TakaPay Android app reads bKash / Nagad / Rocket receipts and forwards them here. Auth uses a separate X-Webhook-Secret header (set in Admin → Settings).
POST/api/webhooks/takapay
payload from app
{
"app": "TakaPay",
"provider": "bkash",
"kind": "received",
"trxId": "BKH8X2K1M",
"amount": 1490,
"counterparty": "01711111111",
"receivedAt": "2026-08-19T15:00:00.000Z"
}