HTTP and curl
Call the API from any language with plain HTTPS and JSON.
The API needs no SDK. Every request is HTTPS with a bearer key; every body is JSON.
export ZYLOPAY_SECRET_KEY="zp_test_sk_…"
export ZYLOPAY_API="https://zylopay-api.fly.dev/api/v1"Read
curl "$ZYLOPAY_API/payments?limit=5" \
-H "Authorization: Bearer $ZYLOPAY_SECRET_KEY"Write
POST and PATCH bodies are JSON. Send an Idempotency-Key with every write (required for payment intents and refunds).
curl "$ZYLOPAY_API/refunds" \
-H "Authorization: Bearer $ZYLOPAY_SECRET_KEY" \
-H "Idempotency-Key: refund-R-2211" \
-H "Content-Type: application/json" \
-d '{"payment": "pay_1042", "amount": 1000000}'See the headers
Add -i to see Request-Id, RateLimit-*, ZyloPay-Version and Idempotent-Replayed:
curl -i "$ZYLOPAY_API/balance" -H "Authorization: Bearer $ZYLOPAY_SECRET_KEY"From other languages
Any HTTP client works. The rules that matter:
- Send
Authorization: Bearer <secret key>and, for bodies,Content-Type: application/json. - Parse amounts as integers (they can exceed 32 bits).
- Handle errors by
error.typeanderror.code(Errors). - Page with
next_cursor(Pagination). - Retry
429and5xxwith backoff and the sameIdempotency-Key.
import os, uuid, requests
resp = requests.post(
"https://zylopay-api.fly.dev/api/v1/payment_intents",
headers={
"Authorization": f"Bearer {os.environ['ZYLOPAY_SECRET_KEY']}",
"Idempotency-Key": str(uuid.uuid4()),
},
json={"amount": 2500000, "terminal": "tml_ZP-4821-K"},
timeout=30,
)
if resp.status_code >= 400:
err = resp.json()["error"]
raise RuntimeError(f"{err['type']}/{err['code']}: {err['message']} (request {err['request_id']})")
intent = resp.json()