ZyloPaydocs

HTTP and curl

Call the API from any language with plain HTTPS and JSON.

The API needs no SDK. Every request is HTTPS with a bearer key; every body is JSON.

export ZYLOPAY_SECRET_KEY="zp_test_sk_…"
export ZYLOPAY_API="https://zylopay-api.fly.dev/api/v1"

Read

curl "$ZYLOPAY_API/payments?limit=5" \
  -H "Authorization: Bearer $ZYLOPAY_SECRET_KEY"

Write

POST and PATCH bodies are JSON. Send an Idempotency-Key with every write (required for payment intents and refunds).

curl "$ZYLOPAY_API/refunds" \
  -H "Authorization: Bearer $ZYLOPAY_SECRET_KEY" \
  -H "Idempotency-Key: refund-R-2211" \
  -H "Content-Type: application/json" \
  -d '{"payment": "pay_1042", "amount": 1000000}'

See the headers

Add -i to see Request-Id, RateLimit-*, ZyloPay-Version and Idempotent-Replayed:

curl -i "$ZYLOPAY_API/balance" -H "Authorization: Bearer $ZYLOPAY_SECRET_KEY"

From other languages

Any HTTP client works. The rules that matter:

  • Send Authorization: Bearer <secret key> and, for bodies, Content-Type: application/json.
  • Parse amounts as integers (they can exceed 32 bits).
  • Handle errors by error.type and error.code (Errors).
  • Page with next_cursor (Pagination).
  • Retry 429 and 5xx with backoff and the same Idempotency-Key.
import os, uuid, requests

resp = requests.post(
    "https://zylopay-api.fly.dev/api/v1/payment_intents",
    headers={
        "Authorization": f"Bearer {os.environ['ZYLOPAY_SECRET_KEY']}",
        "Idempotency-Key": str(uuid.uuid4()),
    },
    json={"amount": 2500000, "terminal": "tml_ZP-4821-K"},
    timeout=30,
)
if resp.status_code >= 400:
    err = resp.json()["error"]
    raise RuntimeError(f"{err['type']}/{err['code']}: {err['message']} (request {err['request_id']})")
intent = resp.json()

On this page