Payments API

Verify TrxID

Matching is always provider + TrxID + amount. Amount-only matching is never used (two ৳500 payments would collide).

Two ways to verify — API key (from your server) or the public endpoint (submitted by the buyer on the checkout page).

Via API key (server-side)

POST/api/v1/payments/:id/verify

Auth: X-Api-Key: YOUR_STORE_API_KEY

Via buyer (checkout page)

POST/api/payments/public/:id/verify

No auth needed — used by the hosted checkout.

request
{
  "trxId": "BKH8X2K1M",
  "provider": "bkash"
}

What happens

  • SMS already in inbox with same TrxID, provider, amount → verified
  • SMS not in yet → verifying until the webhook arrives, then auto-match
  • SMS amount differs → failed + 400
  • TrxID already on another invoice → 400