PayU Authorize API

Authentication involves generating an OAuth token, which is used for further communication with PayU servers. To create a standard OAuth token, you will need client_id and client_secret keys, which can be found in your merchant panel, in the POS.

Operations 1

POST /pl/standard/user/oauth/authorize Create OAuth Token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/payu-authorize-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

payu-authorize-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: 2.1.0
  title: PayU GPO Europe REST Authorize API
  license:
    name: Apache 2.0
    url: http://www.apache.org/licenses/LICENSE-2.0.html
  x-logo:
    url: https://poland.payu.com/wp-content/themes/global-website/assets/src/images/payu-logo.svg
  description: '# Overview


    This reference is designed to assist you in effectively utilizing the PayU REST API to enhance your online payment capabilities.'
servers:
- url: https://secure.payu.com
  description: Production Server
- url: https://secure.snd.payu.com
  description: Sandbox Test Server
security:
- Bearer:
  - client_credentials
tags:
- name: Authorize
  description: Authentication involves generating an OAuth token, which is used for further communication with PayU servers. To create a standard OAuth token, you will need client_id and client_secret keys, which can be found in your merchant panel, in the POS.
paths:
  /pl/standard/user/oauth/authorize:
    post:
      tags:
      - Authorize
      summary: Create OAuth Token
      security: []
      description: 'Each payment should be authorized in one of three available modes:

        - client_credentials - used for standard integration,

        - trusted_merchant - used for authentication of requests made for logged-in shop/application users with fixed extCustomerId,

        - partner - special type of a token meant for creating entities (e.g. Shop, POS, URL) within partner firm.


        Generated access token is valid for 43199 seconds.'
      operationId: oauth
      requestBody:
        content:
          application/x-www-form-urlencoded:
            schema:
              discriminator:
                propertyName: grant_type
                mapping:
                  client_credentials: '#/components/schemas/ClientCredentials'
                  trusted_merchant: '#/components/schemas/TrustedMerchant'
                  partner: '#/components/schemas/Partner'
              anyOf:
              - $ref: '#/components/schemas/ClientCredentials'
              - $ref: '#/components/schemas/TrustedMerchant'
              - $ref: '#/components/schemas/Partner'
      responses:
        '200':
          x-summary: OK
          description: ''
          content:
            application/json:
              schema:
                type: object
                properties:
                  access_token:
                    type: string
                    description: Token used for authentication of API calls.
                    format: uuid
                  token_type:
                    type: string
                    enum:
                    - bearer
                  refresh_token:
                    type: string
                    format: uuid
                  expires_in:
                    type: integer
                    description: Token expiration time (in seconds).
                    enum:
                    - 43199
                  grant_type:
                    type: string
                    description: Token authentication mode.
                    enum:
                    - client_credentials
                    - trusted_merchant
        '400':
          x-summary: Bad Request
          description: ''
          content:
            application/json:
              schema:
                type: object
                required:
                - error
                - error_description
                properties:
                  error:
                    type: string
                    description: Cause of the error.
                  error_description:
                    type: string
                    description: Error description.
        '401':
          x-summary: Unauthorized
          description: ''
          content:
            application/json:
              schema:
                type: object
                required:
                - error
                - error_description
                properties:
                  error:
                    type: string
                    description: Cause of the error.
                  error_description:
                    type: string
                    description: Error description.
components:
  schemas:
    Partner:
      type: object
      required:
      - grant_type
      - client_id
      - client_secret
      - firm_id
      description: only usable with special Technical Partner priviliges that allow management of Firms, URLs, Shops and POSes created and managed by Partner
      properties:
        grant_type:
          type: string
          example: partner
          enum:
          - partner
          description: Authorization mode
        client_id:
          type: string
          example: '145227'
          description: Partners client_id
        client_secret:
          type: string
          example: 12f071174cb7eb79d4aac5bc2f07563f
          description: Partners client_secret
        firm_id:
          type: string
          example: p3BiPgVO
          description: publicFirmId created by Partner that will be managed
    ClientCredentials:
      type: object
      required:
      - grant_type
      - client_id
      - client_secret
      properties:
        grant_type:
          type: string
          example: client_credentials
          enum:
          - client_credenitals
          description: Authorization mode
        client_id:
          type: string
          example: '145227'
          description: Merchant's POS identifier in PayU's system. Can be found in PayU's merchant panel
        client_secret:
          type: string
          example: 12f071174cb7eb79d4aac5bc2f07563f
          description: Merchant's secret key. Can be found in PayU's merchant panel
    TrustedMerchant:
      type: object
      required:
      - grant_type
      - client_id
      - client_secret
      - email
      - ext_customer_id
      properties:
        grant_type:
          type: string
          example: trusted_merchant
          enum:
          - trusted_merchant
          description: Authorization mode
        client_id:
          type: string
          example: '145227'
          description: Merchant's POS identifier in PayU's system. Can be found in PayU's merchant panel
        client_secret:
          type: string
          example: 12f071174cb7eb79d4aac5bc2f07563f
          description: Merchant's secret key. Can be found in PayU's merchant panel
        email:
          type: string
          description: Customer's email address in merchant's system
        ext_customer_id:
          type: string
          description: Customer's identifier in the merchant's system
  securitySchemes:
    Bearer:
      type: http
      scheme: bearer
    Basic:
      type: http
      scheme: basic