Payments API
Verify TrxID
Matching is always provider + TrxID + amount. Amount-only matching is never used (two ৳500 payments would collide).
Two ways to verify — API key (from your server) or the public endpoint (submitted by the buyer on the checkout page).
Via API key (server-side)
POST/api/v1/payments/:id/verify
Auth: X-Api-Key: YOUR_STORE_API_KEY
Via buyer (checkout page)
POST/api/payments/public/:id/verify
No auth needed — used by the hosted checkout.
request
{
"trxId": "BKH8X2K1M",
"provider": "bkash"
}What happens
- SMS already in inbox with same TrxID, provider, amount →
verified - SMS not in yet →
verifyinguntil the webhook arrives, then auto-match - SMS amount differs →
failed+ 400 - TrxID already on another invoice → 400