2C2P Do Payment API

Execute a payment against a paymentToken.

Documentation

Specifications

Other Resources

OpenAPI Specification

2c2p-do-payment-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: 2C2P Payment Gateway API (PGW v4.3) Do Payment API
  description: 'Server-to-server REST interface for the 2C2P Payment Gateway. Every operation is an HTTPS POST under /payment/4.3/. IMPORTANT: on the wire, each request and response body is a single JSON Web Token (JWS) signed with the merchant''s Secret Key using HMAC SHA-256 - the merchant is identified by the merchantID inside the signed payload, and there is no HTTP Authorization header. For readability this document models the DECODED JSON payloads (request `payload` and response `payload`) rather than the raw JWT string. The field schemas here are MODELED from the documented parameters and are a representative subset, not a byte-for-byte copy of 2C2P''s contract; verify exact fields against developer.2c2p.com. Endpoint paths are confirmed from the 2C2P developer reference index.'
  version: '4.3'
  contact:
    name: 2C2P Developer
    url: https://developer.2c2p.com
  x-transport-notes: All traffic is HTTPS request/response. Asynchronous results are delivered as a backend notification webhook (2C2P POSTs a signed JWT to the merchant's backendReturnUrl). There is no WebSocket or SSE transport.
servers:
- url: https://pgw.2c2p.com/payment/4.3
  description: Production
- url: https://sandbox-pgw.2c2p.com/payment/4.3
  description: Sandbox
tags:
- name: Do Payment
  description: Execute a payment against a paymentToken.
paths:
  /payment:
    post:
      operationId: doPayment
      tags:
      - Do Payment
      summary: Do payment
      description: Executes a payment against a paymentToken, selecting the channel via the payment code (card, e-wallet, QR, installment, pay-later, loyalty) and supplying card / customer / browser / return-URL data.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DoPaymentRequest'
      responses:
        '200':
          description: Decoded do-payment response payload.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DoPaymentResponse'
components:
  schemas:
    DoPaymentRequest:
      type: object
      required:
      - paymentToken
      properties:
        paymentToken:
          type: string
        payment:
          type: object
          description: The selected payment channel and its data.
          properties:
            code:
              type: object
              description: Channel / agent routing codes (channelCode, agentCode, etc.).
              additionalProperties: true
            data:
              type: object
              description: Channel-specific data - for cards, an encryptedCardInfo / securePayToken from Secure Fields plus cardholder details; for other methods, the corresponding fields.
              additionalProperties: true
        clientIP:
          type: string
        clientID:
          type: string
        locale:
          type: string
        responseReturnUrl:
          type: string
          format: uri
        browserDetails:
          type: object
          additionalProperties: true
    DoPaymentResponse:
      type: object
      properties:
        respCode:
          type: string
        respDesc:
          type: string
        data:
          type: string
          description: Redirect / 3DS / channel action data where applicable.
        channelCode:
          type: string
        invoiceNo:
          type: string
Where this information came from

This is an independent, third-party profile of 2C2P Do Payment API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.