Xendit Payment Tokens API

Save reusable payment methods for future and recurring charges.

OpenAPI Specification

xendit-payment-tokens-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Xendit Balance Payment Tokens API
  description: 'Xendit is a payments infrastructure provider for Southeast Asia. This OpenAPI document describes a representative, high-fidelity subset of the public Xendit REST API grounded in the developer documentation at https://docs.xendit.co - the unified Payments API (Payment Requests and Payment Tokens), hosted Invoices, Payouts / disbursements, Balance, Transactions, Customers, and Refunds. All requests are authenticated with a secret API key passed over HTTP Basic (the API key is the username, the password is left empty) against the base host https://api.xendit.co.

    Scope note: The newer Payments API resources (payment_requests, payment_tokens, payouts v3, refunds) require an `api-version` header. Some read/update operations here (get transaction by ID, get/update customer, get refund by ID, cancel payout, expire invoice) follow Xendit''s documented resource conventions but were not each individually confirmed against a published reference page at authoring time; they are modeled as representative and flagged in review.yml. Xendit does not publish a machine -readable OpenAPI file at a single canonical public URL; this document was authored by API Evangelist from the human documentation.'
  version: '1.0'
  contact:
    name: Xendit
    url: https://www.xendit.co
servers:
- url: https://api.xendit.co
  description: Xendit production API (test and live keys select the environment)
security:
- basicAuth: []
tags:
- name: Payment Tokens
  description: Save reusable payment methods for future and recurring charges.
paths:
  /v3/payment_tokens:
    post:
      operationId: createPaymentToken
      tags:
      - Payment Tokens
      summary: Create a payment token
      description: Saves an end user's payment method as a reusable payment token for future transactions. Requires the api-version header set to 2024-11-11.
      parameters:
      - $ref: '#/components/parameters/ApiVersion'
      - $ref: '#/components/parameters/ForUserId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PaymentTokenInput'
      responses:
        '201':
          description: The created payment token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaymentToken'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  parameters:
    ForUserId:
      name: for-user-id
      in: header
      required: false
      description: xenPlatform sub-account (Business ID) to act on behalf of.
      schema:
        type: string
    ApiVersion:
      name: api-version
      in: header
      required: false
      description: Xendit API version date. The v3 Payments API (payment_requests, payment_tokens) expects 2024-11-11; the Customers API accepts dates such as 2020-10-31.
      schema:
        type: string
  responses:
    Unauthorized:
      description: Missing or invalid API key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    BadRequest:
      description: The request was invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  schemas:
    PaymentToken:
      type: object
      properties:
        payment_token_id:
          type: string
        reference_id:
          type: string
        channel_code:
          type: string
        status:
          type: string
          enum:
          - REQUIRES_ACTION
          - PENDING
          - ACTIVE
          - FAILED
          - EXPIRED
          - CANCELED
        created:
          type: string
          format: date-time
    Error:
      type: object
      properties:
        error_code:
          type: string
          description: Machine-readable Xendit error code, e.g. DATA_NOT_FOUND.
        message:
          type: string
    PaymentTokenInput:
      type: object
      required:
      - reference_id
      - country
      - currency
      - channel_code
      properties:
        reference_id:
          type: string
        country:
          type: string
        currency:
          type: string
        channel_code:
          type: string
          description: Payment channel provider code, e.g. DANA, OVO, GCASH.
        channel_properties:
          type: object
          additionalProperties: true
        customer_id:
          type: string
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
      description: HTTP Basic authentication. Use your Xendit secret API key as the username and leave the password empty. The key is Base64-encoded into the Authorization header. Test keys and live keys select the environment.